Splunk Search

Splunk Search
Community Activity
greeshmak
How to extract a string without using rex or erex? Ex: I don't have clear logs for phone numbers, want to extract th...
by greeshmak Explorer in Splunk Search 11-28-2016
0 2
0
2
sbattista09
heyyyy everyone, anyone run into this annoying message before? we keep getting this after moving to a search head c...
by sbattista09 Contributor in Splunk Search 11-28-2016
0 3
0
3
cdo_splunk
Any one know of a search that will look for Splunk apps that have not been used by any user for a week, etc?
by cdo_splunk Splunk Employee Splunk Employee in Splunk Search 11-28-2016
1 3
1
3
saifuddin9122
Hi all i have various number of sourcetypes. i want to create lookup table for all my sourcetypes. i want all my sou...
by saifuddin9122 Path Finder in Splunk Search 11-28-2016
0 2
0
2
koprai
Searched a bit, but could find anything. Does anyone already have a Formatter for Splunk search text or Splunk dashbo...
by koprai Explorer in Splunk Search 11-28-2016
3 2
3
2
demkic
Hi there, I am wondering - is it possible to divide values in field1 by the column total of field1 and create a new f...
by demkic Explorer in Splunk Search 11-28-2016
0 3
0
3
pdevosceazure
Hi I have log files which collect url as: cs_uri_stem="/dsa/api/playercommands/a6ada68b-7a72-4f38-b752-d99f7efd4cb...
by pdevosceazure Path Finder in Splunk Search 11-28-2016
0 1
0
1
nagarjuna280
We use eval command to create new field, and we used this as function ex: |stats count(eval(method="GET")) as get. Ca...
by nagarjuna280 Communicator in Splunk Search 11-28-2016
1 9
1
9
mcbradford
I run the following every morning, but I know it could be accomplished more efficiently using tstats, but I cannot ge...
by mcbradford Contributor in Splunk Search 11-28-2016
1 4
1
4
stefanstolk1987
Hello, I want to know if it is possible to use a join command with inputlookup instead of a lookup to join data bet...
by stefanstolk1987 New Member in Splunk Search 11-28-2016
0 1
0
1
drinkingjimmy
I have a query which returns a field which is occasionally a 13-digit hexadecimal value, and occasionally a string wh...
by drinkingjimmy Explorer in Splunk Search 11-28-2016
0 5
0
5
SplunkLunk
Good morning, I want to search for specific text within the _raw output of my syslog messages. Something along the ...
by SplunkLunk Path Finder in Splunk Search 11-28-2016
0 3
0
3
nehal_shah
What is the best way to join search queries in different time zones? I have tried following and it doesn't work. It ...
by nehal_shah Explorer in Splunk Search 11-28-2016
0 3
0
3
Arnaud1213
Hi all, How to get the first event from a search AND get only 1 event in a timechart by source ? (and not "by source,...
by Arnaud1213 Explorer in Splunk Search 11-28-2016
0 6
0
6
behymejt2012
Hi Everyone, I have an existing table that includes several columns filled with numeric values and one column that c...
by behymejt2012 Path Finder in Splunk Search 11-28-2016
0 4
0
4
rjthibod
I currently use various macros to store default values (thresholds, static filter strings, etc.) in an app. These def...
by rjthibod Champion in Splunk Search 11-27-2016
2 9
2
9
venkateshc
I have Ex: Search query 1: I have one type of log, it contains Roll Number, Date of Joining, Class and etc Search ...
by venkateshc Engager in Splunk Search 11-27-2016
0 2
0
2
andrewtrobec
Hello, I am trying to create a variable sized visualization based on the value of a field grouped by another field. ...
by andrewtrobec Motivator in Splunk Search 11-27-2016
0 6
0
6
andrewtrobec
Hello, I'm busy mapping temperatures for locations around the world and in some cases the value is negative. Unfort...
by andrewtrobec Motivator in Splunk Search 11-27-2016
0 9
0
9
burras
I have a sourcetype that has a tremendous amount of data - we use this data to calculate an overall number of calls p...
by burras Communicator in Splunk Search 11-27-2016
0 6
0
6
prathikpisplunk
Below is my requirement. I have weekly data for 24 weeks ( 6 months) , I want to get data of last month in every we...
by prathikpisplunk Explorer in Splunk Search 11-26-2016
0 2
0
2
andrewtrobec
Hello, I've been reading up on the rex command and using it to split strings, but I cannot for the life of me get it...
by andrewtrobec Motivator in Splunk Search 11-26-2016
0 2
0
2
andrewtrobec
Hello, I have the following event data: City,Date,Temp,Sky New York,2016-11-10,20,Clear New York,2016-11-10-19,Clou...
by andrewtrobec Motivator in Splunk Search 11-26-2016
5 9
5
9
himapate
I am required to build a search which will show the uptime of all my Splunk components over a period of one month. Al...
by himapate Explorer in Splunk Search 11-26-2016
0 1
0
1
peiffer
Is there any way to do stats count over multiple time frames? I am trying to replace something written in perl and o...
by peiffer Path Finder in Splunk Search 11-26-2016
0 5
0
5
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...