Splunk Search

Splunk Search
Community Activity
neiowe
Hi all, I am trying to determine the RegEx pattern for the Event Break. Below is an example event. A new event start...
by neiowe Path Finder in Splunk Search 12-01-2016
0 2
0
2
email2vamsi
index="Index1" sourcetype="response" | eval running_ok = if(response_status="Running","0","1") |head 1 |join running_...
by email2vamsi Explorer in Splunk Search 12-01-2016
0 4
0
4
andrewtrobec
Hello, I am trying to determine the number of entries that have a field date that is before or equal to _time. My d...
by andrewtrobec Motivator in Splunk Search 12-01-2016
0 3
0
3
email2vamsi
|eval final = if(running_ok==" " OR running_ok==1,1,0) I want to assign final=1 when (running_ok=="No results found...
by email2vamsi Explorer in Splunk Search 12-01-2016
0 4
0
4
vivekb
I have created following Splunk search: host=xyz* index=my_index NOT(bot) earliest=-1d@d latest=-0d@d | eval searchi...
by vivekb New Member in Splunk Search 12-01-2016
0 8
0
8
pembleton
Hey there, Two problems with searching and viewing json sourcetypes: 1) Anybody know what's the deal with the json...
by pembleton Path Finder in Splunk Search 12-01-2016
0 3
0
3
pradeepkumarg
In my below query, I want to load sourcetypeA for last 13 weeks, however I want to restrict sourcetypeB for last 7 d...
by pradeepkumarg Influencer in Splunk Search 12-01-2016
2 9
2
9
praveenvemuri
Hi 1) Index=test event=initiated | dedup ip-address | table ip-address gives me the initiated transactions. 2) In...
by praveenvemuri Explorer in Splunk Search 12-01-2016
1 6
1
6
Tim_1
Hi all, I'm new to Splunk, and been stuck at trying to format a table of results. I currently have the a raw resul...
by Tim_1 Path Finder in Splunk Search 12-01-2016
0 2
0
2
tmaltizo
We're looking to get the average time, given all, devices/laptops that are non-compliant with encryption. In Foresco...
by tmaltizo Path Finder in Splunk Search 11-30-2016
0 12
0
12
ohlafl
I have a search query that begins like this: index=someData earliest=08/06/2015:10:00:00 latest=08/06/2015:21:00:00....
by ohlafl Communicator in Splunk Search 11-30-2016
1 6
1
6
butzowj
Hello, My management (and me as well, of course) loves the way the visualizations for real time searches look. But f...
by butzowj Path Finder in Splunk Search 11-30-2016
0 1
0
1
_jgpm_
I've tried to use the trim, ltrim, and rtrim command on a particular field that contains a "#" field. I'm not a trad...
by _jgpm_ Communicator in Splunk Search 11-30-2016
0 4
0
4
chanukhya
Hi, My log looks like this. I am trying to get the average response time by service. ServiceInvoker (service_A) : e...
by chanukhya Explorer in Splunk Search 11-30-2016
0 11
0
11
andrewtrobec
Hello, I am writing a search to figure out which users haven't loggedtheir hours. For a list of all users I have a l...
by andrewtrobec Motivator in Splunk Search 11-29-2016
0 3
0
3
newbietosplunk
When we make searches in Splunk, under which log file do these searches get logged? Example: we need the original pl...
by newbietosplunk Engager in Splunk Search 11-29-2016
1 2
1
2
marktechuk
Hi guys I'm new to Splunk  A search I created returns the following in a specific field: /Erginn008/3e2ce24a277ggh...
by marktechuk New Member in Splunk Search 11-29-2016
0 6
0
6
avanishm
Is it possible to do delta groupby some field? I have an application which is processing data from multiple queues. E...
by avanishm Engager in Splunk Search 11-29-2016
1 2
1
2
viggor
If I have a chart of the form timechart span= T max(duration) as MaxLatency and a point (x,y), then over what time...
by viggor Path Finder in Splunk Search 11-29-2016
0 4
0
4
splgeek
hello all i want to run a search with a stats count that will show results based on two separate time slots Stats Co...
by splgeek Explorer in Splunk Search 11-29-2016
0 3
0
3
JSkier
I'm trying to get splunk working with zfs on Linux, which 6.4 supposedly supports, per the release latest release not...
by JSkier Communicator in Splunk Search 11-29-2016
4 7
4
7
pavanae
I have a search which gives the result as follows for one day Query :- base search | stats dc(dCIF) as dUniqueCIFs ...
by pavanae Builder in Splunk Search 11-29-2016
0 4
0
4
kiran331
Hi How to extract the field "user" from the following data? ABCDEFGHI\cw2343@ac.abcdefghi.com ABCDEFGHI\kirann@a...
by kiran331 Builder in Splunk Search 11-29-2016
0 3
0
3
asarran
I have a field [B] that consists of some numbers and strings. 10 gb 20 gb 30 gb I would like to implement a eval...
by asarran Path Finder in Splunk Search 11-29-2016
0 1
0
1
andrewtrobec
Hello, I have a timechart that plots three values: incoming objects, outgoing objects, and the running amount of obje...
by andrewtrobec Motivator in Splunk Search 11-29-2016
0 4
0
4
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors