Splunk Search

Splunk Search
Community Activity
kiran331
Hi I have a use case to find users' working hours with start time and end time. Which events will show the informat...
by kiran331 Builder in Splunk Search 12-01-2016
0 6
0
6
pavanae
I am trying to construct a search from almost days to display each user's average of a certain max of distinct count ...
by pavanae Builder in Splunk Search 12-01-2016
0 4
0
4
demkic
Hello, I am stuck on my search and was hoping I could get some help. I am trying to calculate the % increase and di...
by demkic Explorer in Splunk Search 12-01-2016
0 11
0
11
byu168168
I generated a line chart and am plotting on two fields: Time and ID, however, I want to see more than just these two ...
by byu168168 Path Finder in Splunk Search 12-01-2016
0 2
0
2
rajgowd1
HI, i am trying to display ERROR count as a single value and using below search index=myindex ERROR co_name=$co_name...
by rajgowd1 Communicator in Splunk Search 12-01-2016
0 5
0
5
basilarockiaedw
I am connecting my hunk application(6.4) to datastax cassandra 3.1 to get the results for monitoring and the results ...
by basilarockiaedw Path Finder in Splunk Search 12-01-2016
0 4
0
4
dbcase
Hi, I have the below query that works just fine. The thing that I want to add is a percentage (Errors/Success*100) ...
by dbcase Motivator in Splunk Search 12-01-2016
0 1
0
1
ppanchal
I have data in my log which looks like, extraData: { [-] MD_independent_new: 2016-11-30T04:35:57Z ...
by ppanchal Path Finder in Splunk Search 12-01-2016
0 1
0
1
smhsplunk
I only have year-month-day in my _time, when I use table to show in search, it only gives me dates. Yet when I use xy...
by smhsplunk Communicator in Splunk Search 12-01-2016
0 3
0
3
splunk_zen
We may be having performance issues as newly saved search time extractions are not working even after being successfu...
by splunk_zen Builder in Splunk Search 12-01-2016
0 2
0
2
neiowe
Hi all, I am trying to determine the RegEx pattern for the Event Break. Below is an example event. A new event start...
by neiowe Path Finder in Splunk Search 12-01-2016
0 2
0
2
email2vamsi
index="Index1" sourcetype="response" | eval running_ok = if(response_status="Running","0","1") |head 1 |join running_...
by email2vamsi Explorer in Splunk Search 12-01-2016
0 4
0
4
andrewtrobec
Hello, I am trying to determine the number of entries that have a field date that is before or equal to _time. My d...
by andrewtrobec Motivator in Splunk Search 12-01-2016
0 3
0
3
email2vamsi
|eval final = if(running_ok==" " OR running_ok==1,1,0) I want to assign final=1 when (running_ok=="No results found...
by email2vamsi Explorer in Splunk Search 12-01-2016
0 4
0
4
vivekb
I have created following Splunk search: host=xyz* index=my_index NOT(bot) earliest=-1d@d latest=-0d@d | eval searchi...
by vivekb New Member in Splunk Search 12-01-2016
0 8
0
8
pembleton
Hey there, Two problems with searching and viewing json sourcetypes: 1) Anybody know what's the deal with the json...
by pembleton Path Finder in Splunk Search 12-01-2016
0 3
0
3
pradeepkumarg
In my below query, I want to load sourcetypeA for last 13 weeks, however I want to restrict sourcetypeB for last 7 d...
by pradeepkumarg Influencer in Splunk Search 12-01-2016
2 9
2
9
praveenvemuri
Hi 1) Index=test event=initiated | dedup ip-address | table ip-address gives me the initiated transactions. 2) In...
by praveenvemuri Explorer in Splunk Search 12-01-2016
1 6
1
6
Tim_1
Hi all, I'm new to Splunk, and been stuck at trying to format a table of results. I currently have the a raw resul...
by Tim_1 Path Finder in Splunk Search 12-01-2016
0 2
0
2
tmaltizo
We're looking to get the average time, given all, devices/laptops that are non-compliant with encryption. In Foresco...
by tmaltizo Path Finder in Splunk Search 11-30-2016
0 12
0
12
ohlafl
I have a search query that begins like this: index=someData earliest=08/06/2015:10:00:00 latest=08/06/2015:21:00:00....
by ohlafl Communicator in Splunk Search 11-30-2016
1 6
1
6
butzowj
Hello, My management (and me as well, of course) loves the way the visualizations for real time searches look. But f...
by butzowj Path Finder in Splunk Search 11-30-2016
0 1
0
1
_jgpm_
I've tried to use the trim, ltrim, and rtrim command on a particular field that contains a "#" field. I'm not a trad...
by _jgpm_ Communicator in Splunk Search 11-30-2016
0 4
0
4
chanukhya
Hi, My log looks like this. I am trying to get the average response time by service. ServiceInvoker (service_A) : e...
by chanukhya Explorer in Splunk Search 11-30-2016
0 11
0
11
andrewtrobec
Hello, I am writing a search to figure out which users haven't loggedtheir hours. For a list of all users I have a l...
by andrewtrobec Motivator in Splunk Search 11-29-2016
0 3
0
3
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...