Splunk Search

Splunk Search
Community Activity
splunkrocks2014
Assuming I have a lookup file, for instance, users.csv, with different contents and is located in different apps and ...
by splunkrocks2014 Communicator in Splunk Search 12-13-2016
0 3
0
3
irfans
I am trying to write a lookup that will pull a value out from one of three different columns. for example Col_A, ...
by irfans Explorer in Splunk Search 12-13-2016
1 3
1
3
douglas_garland
I created a macro and used the search string below. After submitting the search, I received the following error mess...
by douglas_garland New Member in Splunk Search 12-13-2016
0 6
0
6
iamkilarunaresh
| inputlookup Roster.csv Level 1 Manager Level 2 Manager Level 3 Manager Ganesh Ganesh Ganesh Th...
by iamkilarunaresh Explorer in Splunk Search 12-13-2016
0 1
0
1
king2jd
Here is my search: | set diff [search index=os_nix sourcetype="Unix:UserAccounts" earliest =-90d@d latest=-30d@d ho...
by king2jd Path Finder in Splunk Search 12-13-2016
0 3
0
3
namrithadeepak
Hi, I have batch job logs that look like below, My output needs to look like this, The challenge is that the j...
by namrithadeepak Path Finder in Splunk Search 12-13-2016
0 2
0
2
a212830
Hi, I noticed some processes running on the indexer today with the phrase "SummaryDirector" in the command-line. Ca...
by a212830 Champion in Splunk Search 12-13-2016
0 1
0
1
LCM_BRogerson
I’m looking for a way to run a search on the results of a previous search. Subsearch won't work because I don't know...
by LCM_BRogerson Path Finder in Splunk Search 12-13-2016
0 5
0
5
psteja
Splunk newbie here trying to get a nice line graph showing the session creation pattern over a period of time: ........
by psteja Engager in Splunk Search 12-13-2016
0 5
0
5
yuwtennis
Hi! I would like to know what does "Size" stands for Job Manager in ver 5.0.5. Any help is appreciated! Thanks, Yu
by yuwtennis Communicator in Splunk Search 12-13-2016
1 3
1
3
johnbernal553
I have a log event like this: Timestamp: 1477292160453180 537 The number 1477292160453180 is the number of microse...
by johnbernal553 New Member in Splunk Search 12-13-2016
0 8
0
8
alexandermunce
I am working with a field named product which contains an array of values which I would like to replace with more mea...
by alexandermunce Communicator in Splunk Search 12-13-2016
0 11
0
11
colbymahan
SourceName="EBS Check" OR SourceName="EBS Snapshot" | eval hasEBSCheck=1 | append [| metadata type="hosts" | eval has...
by colbymahan Explorer in Splunk Search 12-13-2016
0 5
0
5
tmurray3
I have a search to graph the last 30 minutes in 5 minute intervals: index=web_summary report="volumebyminuteweb" ear...
by tmurray3 Path Finder in Splunk Search 12-13-2016
0 1
0
1
vkumar6
I need an example search to track system time change in a Linux system. Please help me.
by vkumar6 Explorer in Splunk Search 12-13-2016
0 9
0
9
dbcase
Hi, I have this query index=cox UCE-|rex "UCE-(?<UCE_Code>(\d+))"|lookup UCECodes.csv UCE-Code as UCE_Code|eval ud=...
by dbcase Motivator in Splunk Search 12-13-2016
0 3
0
3
HeinzWaescher
Hi, let's say we have a string with various tagged entries: "This {field1} is {delete_this} the example {tagged_el...
by HeinzWaescher Motivator in Splunk Search 12-13-2016
0 8
0
8
mattj81
Hi, I'm struggling with a search string to pull back Active Directory logon times for a specific user and to include ...
by mattj81 New Member in Splunk Search 12-13-2016
0 6
0
6
umsundar2015
Hi, My scenario is to get a time chart with each day's values for a particular period of time (ex: 7 days) and their...
by umsundar2015 Path Finder in Splunk Search 12-13-2016
0 13
0
13
splunkpoornima
hi all i have taskmanager log files which has the events like Mon Jun 25 00:00:30 CDT 2012,DistributedEvaluation,S...
by splunkpoornima Communicator in Splunk Search 12-12-2016
0 2
0
2
medunmeyer
I am running Splunk 6.5 , and I have tried many things for hours, but am still getting: The system is approaching th...
by medunmeyer Explorer in Splunk Search 12-12-2016
0 1
0
1
namrithadeepak
I have 2 jobs running daily (DailyDayJob, DailyNightJob) that logs to a common file. The logs are as given below: 20...
by namrithadeepak Path Finder in Splunk Search 12-12-2016
0 9
0
9
Vicky84
Sorry I am new to Splunk and wondering if can have the report that gives results in a table as below, data as : i...
by Vicky84 Explorer in Splunk Search 12-12-2016
0 4
0
4
johnbernal553
I have a field in my logs that looks like this: Timestamp: 1477292160636560 1217 The first number is time at which...
by johnbernal553 New Member in Splunk Search 12-12-2016
0 2
0
2
Leustad
Imagine there are thousands of JSON entries and I want to correlate object pairs via a key/value pair. Entry #44 { ...
by Leustad Engager in Splunk Search 12-12-2016
0 1
0
1
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Solution Authors