Splunk Search

Splunk Search
Community Activity
naty
Hi, i am doing a search with append and i am trying to optimize it. this is my search: index=myind source=mysrc POO...
by naty Path Finder in Splunk Search 12-22-2016
0 1
0
1
sicspunky
Hi All, Cracking my head trying to get this to work. Basically i need to add another column which will be "Count". ...
by sicspunky New Member in Splunk Search 12-22-2016
0 1
0
1
William
I try to add some csv files, which contain data like the followings Time, ACTION,ORDER_NO, ... 2009-11-2 20:00:00.0...
by William Path Finder in Splunk Search 12-22-2016
2 8
2
8
ravisplunksap
Hi All, I want to create an alert for McAfee services stopped for the Windows hosts. Meanwhile every time McAfee ser...
by ravisplunksap New Member in Splunk Search 12-22-2016
0 1
0
1
heewonha
Hello, I have email list distributed by saved searches. I want to use this in saved searches email action using look...
by heewonha Engager in Splunk Search 12-22-2016
0 1
0
1
hegeman1982
I am trying to come up with a regular expression to use with the field extractor that would return the value of a str...
by hegeman1982 Engager in Splunk Search 12-21-2016
0 2
0
2
mistydennis
I'm running a search that combines two data sources: one source captures our download logs and one source holds metad...
by mistydennis Communicator in Splunk Search 12-21-2016
0 2
0
2
acemel
The search below results in a table with 16 columns (along with column for date/time). The first eight columns show ...
by acemel New Member in Splunk Search 12-21-2016
0 1
0
1
jnichols914
Hi Everyone, I've looked over the answers for my problem, but I can't seem to get this working correctly. Here is wh...
by jnichols914 Explorer in Splunk Search 12-21-2016
0 4
0
4
jwalzerpitt
I'm trying to write a search that I can convert into an alert that will trigger when there's an X% increase when comp...
by jwalzerpitt Influencer in Splunk Search 12-21-2016
0 7
0
7
sravankaripe
i want to know sample search to know whether the alert created is triggered or not ? the alert will triggered as se...
by sravankaripe Communicator in Splunk Search 12-21-2016
0 1
0
1
sravankaripe
Out of events, I have to pick extract <SERIAL_NUM>12456789</SERIAL_NUM> Please help me with the REX syntax in a searc...
by sravankaripe Communicator in Splunk Search 12-21-2016
0 6
0
6
naty
Hi, my managers posted a request for data. they want to see weekly comparison over the course of a month. the catch ...
by naty Path Finder in Splunk Search 12-21-2016
2 11
2
11
anantdeshpande
Hi, We have a column where value can be string, alphanumeric, numeric, and with/without spaces before and after it. T...
by anantdeshpande Path Finder in Splunk Search 12-20-2016
0 12
0
12
nevdull
Hi. I have an XML file where, for some reason, some control characters were printed as ascii strings, \x0a being a ...
by nevdull New Member in Splunk Search 12-20-2016
0 3
0
3
jhhernandez
Good day I am currently in the process of creating alerts for the events received. Within the Triggered Alerts, I c...
by jhhernandez New Member in Splunk Search 12-20-2016
0 1
0
1
yyossef
Hi, I have a problem using max function with stats command. I am tryng to find the max utilization value and at the...
by yyossef Explorer in Splunk Search 12-20-2016
0 7
0
7
maximusdm
Hi all, I've just learned how to use the commands below but not sure how to apply it to a bar chart: | where test >=...
by maximusdm Communicator in Splunk Search 12-20-2016
0 2
0
2
acemel
The search below produces a timechart with 8 sets (trends) of values (Efficiency), one trend for each of 8 positions ...
by acemel New Member in Splunk Search 12-20-2016
0 1
0
1
troyward
I have Windows Kerberos logs that I have turned into a summary table by day by user. I am trying find the way to det...
by troyward Explorer in Splunk Search 12-20-2016
0 2
0
2
splunkrocks2014
I wanted to remove the table headers from a statistics table. I tried to add it the following code to my javascript,...
by splunkrocks2014 Communicator in Splunk Search 12-20-2016
0 3
0
3
nirmalya2006
Hi All I have a search as below. index = enterprise_idx1 sourcetype = sft | dedup _time, BatchId | search Batc...
by nirmalya2006 Path Finder in Splunk Search 12-20-2016
0 7
0
7
shaileshmali
How do I find % deviation between 2 values for each platform? I am able to get deviation, but when i want deviation o...
by shaileshmali Path Finder in Splunk Search 12-20-2016
0 1
0
1
rewritex
I'm trying to create a field extraction based on data: Host: www.ditto.dut.com\r\nIf-Modified-Since: Tue where the fi...
by rewritex Contributor in Splunk Search 12-20-2016
0 3
0
3
sharukh619
We are in an implementation of Splunk on top of our EDW. Is it possible to do Complex Event Processing based on some ...
by sharukh619 New Member in Splunk Search 12-20-2016
0 3
0
3
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...