Splunk Search

Splunk Search
Community Activity
mvasquez2
We have devices that generate thousands of a particular entry. I created a daily search to summarize. I combined the ...
by mvasquez2 New Member in Splunk Search 01-04-2017
0 7
0
7
_smp_
Hello. I just finished upgrading from 6.3.3 to 6.5.1 last night. This morning, I am able to reproduce a problem where...
by _smp_ Builder in Splunk Search 01-04-2017
0 6
0
6
prashanthberam
I have a lot of details in my table, so I want to search values from some of the fields IN THOSE FIELDS There is one ...
by prashanthberam Explorer in Splunk Search 01-04-2017
0 8
0
8
Freya_X
When the search result is null with the special filter, how to show it with count =0 instead of no record? index=app...
by Freya_X New Member in Splunk Search 01-04-2017
0 4
0
4
HCadmins
eventtype=cv "Source Client"=* "Destination Client"=slc-p-res* OR dab* Duration=* | convert dur2sec(Duration) AS Dura...
by HCadmins Communicator in Splunk Search 01-04-2017
0 4
0
4
gt_dev
I am still not able to get 2 fields in the mvlist list. Here is my transaction line now: | transaction visitID mvlis...
by gt_dev Explorer in Splunk Search 01-04-2017
0 3
0
3
anantdeshpande
We want to optimize below query as it's taking 4 Min to execute. index= idx_prod sourcetype=SRC1 "Sent message:" ...
by anantdeshpande Path Finder in Splunk Search 01-04-2017
0 1
0
1
HeinzWaescher
Hi, I'm calculating the calenderweek with this: | eval calenderweek=strftime(_time,"%Y-%V") For some reason for 2...
by HeinzWaescher Motivator in Splunk Search 01-04-2017
0 1
0
1
tomasmoser
Hi Team, I need to aggregate sequences of all consecutive events with a field Door=''Open" delimited with sequence o...
by tomasmoser Contributor in Splunk Search 01-04-2017
0 3
0
3
umsundar2015
Hi, My problem is "undefined" word is displayed when i opened in search bar. In turn it gives some random values as...
by umsundar2015 Path Finder in Splunk Search 01-04-2017
0 3
0
3
jturner900
I'm trying to swap the roles of two columns. Normally, there is one "key" in the first column for every group of "va...
by jturner900 Explorer in Splunk Search 01-03-2017
0 1
0
1
ynegoro
I'd like to get contents between fields. Here is a sample log. CheckPointCount=N/A,CheckPointRestart=no,CheckPointIn...
by ynegoro New Member in Splunk Search 01-03-2017
0 2
0
2
kbaden
Hi I am currently using transaction to generate a report on length of user session, which is working well. The next ...
by kbaden Explorer in Splunk Search 01-03-2017
0 2
0
2
chvnc
req_event_id field has values like: PL-ADMIN-11004.30A5748A69B1:AEECB6513 PL-ADMIN-11004.30A5748A69B1:AEEC909E6 PL-A...
by chvnc Explorer in Splunk Search 01-03-2017
0 3
0
3
HeinzWaescher
Hi, is it possible to extract key value pairs out of a multivalue field like this: multivaluefield: sales:100 ,refu...
by HeinzWaescher Motivator in Splunk Search 01-03-2017
0 6
0
6
HCadmins
eventtype=cv "Source Client"=* "Destination Client"=slc-p-res* OR dab* Duration=* | convert ctime(_time) | convert du...
by HCadmins Communicator in Splunk Search 01-03-2017
0 1
0
1
rajgowd1
Hi, I have a search which displays content in a table format. Here is the search and I would like to show them in sc...
by rajgowd1 Communicator in Splunk Search 01-03-2017
0 11
0
11
James_wang
Hi Support, Host, Key, Value A, Username, root A, Address, 1.1.1.1 A, Type, AIX B, Username, admin B, Address, 2.2.2...
by James_wang Engager in Splunk Search 01-03-2017
2 2
2
2
asarran
Hey Fellow Splunkers I would like to total multiple values for the same fields. field="Fruits" Within this field...
by asarran Path Finder in Splunk Search 01-03-2017
0 3
0
3
ankithreddy777
I have a xml message with multiple lines. How can we extract entire data into a field?
by ankithreddy777 Contributor in Splunk Search 01-03-2017
0 1
0
1
twinspop
I am an admin. People can share with me. But any time I share a search via the share widget on the search screen, the...
by twinspop Influencer in Splunk Search 01-03-2017
0 2
0
2
leo_wang
Hi, As. title. I know I could use "predict" command to predict the value of my data. But I have some data which are ...
by leo_wang Path Finder in Splunk Search 01-03-2017
0 1
0
1
maryang
Below is the my query: index=app splunk_server_group=CWE sourcetype=ELMTP99 host="CHE-elmAPP0" source="C:\TPles\ELMgF...
by maryang New Member in Splunk Search 01-03-2017
0 2
0
2
robjordan_boa
It's quite easy to report in splunk on what type of events you have but how to report on what types of events you don...
by robjordan_boa Explorer in Splunk Search 01-03-2017
0 10
0
10
AdixitSplunk
HI , I have this query where i want my data in a specific format . Here under each POD there are some 3-4 hosts ,who...
by AdixitSplunk Path Finder in Splunk Search 01-03-2017
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors