Splunk Search

Splunk Search
Community Activity
alexandermunce
I am working with a field named product which contains an array of values which I would like to replace with more mea...
by alexandermunce Communicator in Splunk Search 12-13-2016
0 11
0
11
colbymahan
SourceName="EBS Check" OR SourceName="EBS Snapshot" | eval hasEBSCheck=1 | append [| metadata type="hosts" | eval has...
by colbymahan Explorer in Splunk Search 12-13-2016
0 5
0
5
tmurray3
I have a search to graph the last 30 minutes in 5 minute intervals: index=web_summary report="volumebyminuteweb" ear...
by tmurray3 Path Finder in Splunk Search 12-13-2016
0 1
0
1
vkumar6
I need an example search to track system time change in a Linux system. Please help me.
by vkumar6 Explorer in Splunk Search 12-13-2016
0 9
0
9
dbcase
Hi, I have this query index=cox UCE-|rex "UCE-(?<UCE_Code>(\d+))"|lookup UCECodes.csv UCE-Code as UCE_Code|eval ud=...
by dbcase Motivator in Splunk Search 12-13-2016
0 3
0
3
HeinzWaescher
Hi, let's say we have a string with various tagged entries: "This {field1} is {delete_this} the example {tagged_el...
by HeinzWaescher Motivator in Splunk Search 12-13-2016
0 8
0
8
mattj81
Hi, I'm struggling with a search string to pull back Active Directory logon times for a specific user and to include ...
by mattj81 New Member in Splunk Search 12-13-2016
0 6
0
6
umsundar2015
Hi, My scenario is to get a time chart with each day's values for a particular period of time (ex: 7 days) and their...
by umsundar2015 Path Finder in Splunk Search 12-13-2016
0 13
0
13
splunkpoornima
hi all i have taskmanager log files which has the events like Mon Jun 25 00:00:30 CDT 2012,DistributedEvaluation,S...
by splunkpoornima Communicator in Splunk Search 12-12-2016
0 2
0
2
medunmeyer
I am running Splunk 6.5 , and I have tried many things for hours, but am still getting: The system is approaching th...
by medunmeyer Explorer in Splunk Search 12-12-2016
0 1
0
1
namrithadeepak
I have 2 jobs running daily (DailyDayJob, DailyNightJob) that logs to a common file. The logs are as given below: 20...
by namrithadeepak Path Finder in Splunk Search 12-12-2016
0 9
0
9
Vicky84
Sorry I am new to Splunk and wondering if can have the report that gives results in a table as below, data as : i...
by Vicky84 Explorer in Splunk Search 12-12-2016
0 4
0
4
johnbernal553
I have a field in my logs that looks like this: Timestamp: 1477292160636560 1217 The first number is time at which...
by johnbernal553 New Member in Splunk Search 12-12-2016
0 2
0
2
Leustad
Imagine there are thousands of JSON entries and I want to correlate object pairs via a key/value pair. Entry #44 { ...
by Leustad Engager in Splunk Search 12-12-2016
0 1
0
1
AnthonyTibaldi
Hello All, I have a lookup called mylookup based on mylookup.csv containing 3 fields FieldA, FieldB and FieldC. I a...
by AnthonyTibaldi Path Finder in Splunk Search 12-12-2016
0 6
0
6
rlincoln
I have this real-time query with a 12 week back fill: host="<some host>" OR host="<some other host>" "<some sear...
by rlincoln New Member in Splunk Search 12-12-2016
0 4
0
4
anthonysomerset
I have a voice CDR being imported into splunk, i have indexed extractions working perfectly as its ultimately a CSV f...
by anthonysomerset Path Finder in Splunk Search 12-12-2016
0 4
0
4
jmallorquin
Hi, When I search for events from the virtual index, I start to receive events but the query only finishes partially...
by jmallorquin Builder in Splunk Search 12-12-2016
0 5
0
5
srikanth1213
Hi Guys, I am unable to search the event data for license_usage.log , whereas I can see the log file getting updated ...
by srikanth1213 Path Finder in Splunk Search 12-12-2016
0 4
0
4
brywilk_umich
Hi All, Does anyone have a search/report that shows all of your indexes with usage by day vs the previous day with a...
by brywilk_umich Path Finder in Splunk Search 12-12-2016
0 2
0
2
shivendra_infy
I have the following query which gives me a Total count of 2 searches but after evaluating, I am not getting the Tota...
by shivendra_infy Path Finder in Splunk Search 12-12-2016
0 1
0
1
erik_paulsen
I have logs including some very long lines. To get overview of activity, I want to write a search that shows just the...
by erik_paulsen Engager in Splunk Search 12-12-2016
1 3
1
3
paulalbert11
Simple question: both of these return null. Any idea why? | eval createDt1 = strftime("2013-03-22 11:22:33","%s") |...
by paulalbert11 Explorer in Splunk Search 12-12-2016
0 9
0
9
ravinallaparedd
Hi, I would like to know how to find value from lookup table dynamically by matching string in field value. For exa...
by ravinallaparedd New Member in Splunk Search 12-12-2016
0 3
0
3
sumanth_isac
Hi all, Is there any possibility to show values inside the chart without bringing mouse over it. It should always be...
by sumanth_isac Path Finder in Splunk Search 12-12-2016
1 10
1
10
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...