Splunk Search

Splunk Search
Community Activity
dbcase
Hi, I have this query index=cox UCE-|rex "UCE-(?<UCE_Code>(\d+))"|lookup UCECodes.csv UCE-Code as UCE_Code|eval ud=...
by dbcase Motivator in Splunk Search 12-13-2016
0 3
0
3
HeinzWaescher
Hi, let's say we have a string with various tagged entries: "This {field1} is {delete_this} the example {tagged_el...
by HeinzWaescher Motivator in Splunk Search 12-13-2016
0 8
0
8
mattj81
Hi, I'm struggling with a search string to pull back Active Directory logon times for a specific user and to include ...
by mattj81 New Member in Splunk Search 12-13-2016
0 6
0
6
umsundar2015
Hi, My scenario is to get a time chart with each day's values for a particular period of time (ex: 7 days) and their...
by umsundar2015 Path Finder in Splunk Search 12-13-2016
0 13
0
13
splunkpoornima
hi all i have taskmanager log files which has the events like Mon Jun 25 00:00:30 CDT 2012,DistributedEvaluation,S...
by splunkpoornima Communicator in Splunk Search 12-12-2016
0 2
0
2
medunmeyer
I am running Splunk 6.5 , and I have tried many things for hours, but am still getting: The system is approaching th...
by medunmeyer Explorer in Splunk Search 12-12-2016
0 1
0
1
namrithadeepak
I have 2 jobs running daily (DailyDayJob, DailyNightJob) that logs to a common file. The logs are as given below: 20...
by namrithadeepak Path Finder in Splunk Search 12-12-2016
0 9
0
9
Vicky84
Sorry I am new to Splunk and wondering if can have the report that gives results in a table as below, data as : i...
by Vicky84 Explorer in Splunk Search 12-12-2016
0 4
0
4
johnbernal553
I have a field in my logs that looks like this: Timestamp: 1477292160636560 1217 The first number is time at which...
by johnbernal553 New Member in Splunk Search 12-12-2016
0 2
0
2
Leustad
Imagine there are thousands of JSON entries and I want to correlate object pairs via a key/value pair. Entry #44 { ...
by Leustad Engager in Splunk Search 12-12-2016
0 1
0
1
AnthonyTibaldi
Hello All, I have a lookup called mylookup based on mylookup.csv containing 3 fields FieldA, FieldB and FieldC. I a...
by AnthonyTibaldi Path Finder in Splunk Search 12-12-2016
0 6
0
6
rlincoln
I have this real-time query with a 12 week back fill: host="<some host>" OR host="<some other host>" "<some sear...
by rlincoln New Member in Splunk Search 12-12-2016
0 4
0
4
anthonysomerset
I have a voice CDR being imported into splunk, i have indexed extractions working perfectly as its ultimately a CSV f...
by anthonysomerset Path Finder in Splunk Search 12-12-2016
0 4
0
4
jmallorquin
Hi, When I search for events from the virtual index, I start to receive events but the query only finishes partially...
by jmallorquin Builder in Splunk Search 12-12-2016
0 5
0
5
srikanth1213
Hi Guys, I am unable to search the event data for license_usage.log , whereas I can see the log file getting updated ...
by srikanth1213 Path Finder in Splunk Search 12-12-2016
0 4
0
4
brywilk_umich
Hi All, Does anyone have a search/report that shows all of your indexes with usage by day vs the previous day with a...
by brywilk_umich Path Finder in Splunk Search 12-12-2016
0 2
0
2
shivendra_infy
I have the following query which gives me a Total count of 2 searches but after evaluating, I am not getting the Tota...
by shivendra_infy Path Finder in Splunk Search 12-12-2016
0 1
0
1
erik_paulsen
I have logs including some very long lines. To get overview of activity, I want to write a search that shows just the...
by erik_paulsen Engager in Splunk Search 12-12-2016
1 3
1
3
paulalbert11
Simple question: both of these return null. Any idea why? | eval createDt1 = strftime("2013-03-22 11:22:33","%s") |...
by paulalbert11 Explorer in Splunk Search 12-12-2016
0 9
0
9
ravinallaparedd
Hi, I would like to know how to find value from lookup table dynamically by matching string in field value. For exa...
by ravinallaparedd New Member in Splunk Search 12-12-2016
0 3
0
3
sumanth_isac
Hi all, Is there any possibility to show values inside the chart without bringing mouse over it. It should always be...
by sumanth_isac Path Finder in Splunk Search 12-12-2016
1 10
1
10
rguntupalli8
Trying to evaluate the below: 1min=1;5min=1;60min=1;24hr=1 Below seem to be not working. Anything wrong with this?...
by rguntupalli8 New Member in Splunk Search 12-12-2016
0 3
0
3
dutabhis07
Hi, i am trying to create a pie chart with gives %age up and down time of a system. Splunk mines a log file with the...
by dutabhis07 Explorer in Splunk Search 12-12-2016
0 3
0
3
ravinallaparedd
Hello, I would like to know how to calculate sum of selected values by excluding other values in a multivalue field....
by ravinallaparedd New Member in Splunk Search 12-11-2016
0 5
0
5
demkic
Hi there, I am trying to calculate the percent of failure types by the total number of transactions (including where...
by demkic Explorer in Splunk Search 12-11-2016
0 11
0
11
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...
Top Solution Authors