Splunk Search

Splunk Search
Community Activity
pavanae
I'm going crazy of calculating the difference between two fields which has epoch time. The following is my Query Upd...
by pavanae Builder in Splunk Search 11-23-2016
0 6
0
6
stratenh
Hi, I have a query which returns no results: index="itsm" sourcetype=incidents | dedup NUMBER sortby OPEN_TIME | se...
by stratenh Loves-to-Learn in Splunk Search 11-23-2016
0 5
0
5
RICKZHANG
Filter the number of less than 1000 of the data example: index=app sourcetype=EPC*Event* level=ERROR |rex field=req...
by RICKZHANG Engager in Splunk Search 11-23-2016
0 2
0
2
packet_hunter
Scenario: I am sending results inline with sendemail. Unfortunately, the way it displays (and sends results) in co...
by packet_hunter Contributor in Splunk Search 11-22-2016
0 2
0
2
ahogbin
Hello, I am trying to use the stats command with 2 different where clauses with the end result being to use the 2 va...
by ahogbin Communicator in Splunk Search 11-22-2016
0 4
0
4
drinkingjimmy
I have a log output which provides many fields, but the two I'm most concerned with are user and device. I'm tryin...
by drinkingjimmy Explorer in Splunk Search 11-22-2016
0 4
0
4
qtopia7100
This is the search I'm working with: index="*-network" (sourcetype="cisco:asa" OR sourcetype="routers") user="user*"...
by qtopia7100 Explorer in Splunk Search 11-22-2016
0 1
0
1
pavanae
I displayed the list of people and their count by using the below search: foo | stats dc(A) as people by B which d...
by pavanae Builder in Splunk Search 11-22-2016
1 5
1
5
asarran
Good Morning, Fellow Splunkers I'm looking to list all events of an extracted field one time. Example: Extracted ...
by asarran Path Finder in Splunk Search 11-22-2016
3 2
3
2
rajgowd1
Hi, We have events which contain key value pairs separated by a colon :. Here is the sample event: <6>2016-11-22T16...
by rajgowd1 Communicator in Splunk Search 11-22-2016
0 6
0
6
lalire
I am trying to search our WIndows logs and our Fortinet logs for specific info. (index=windows) OR (Index=fortinet) ...
by lalire Explorer in Splunk Search 11-22-2016
0 2
0
2
k_harini
I have to calculate % of SLA missed over time. basesearch|dedup ID|EVAL sla_status = case(Status like "Closed MPT Wa...
by k_harini Communicator in Splunk Search 11-22-2016
0 8
0
8
andrewtrobec
Hello, I'm trying to flip the x and y axis of a chart so that I can change the way my data is visualized. As it sta...
by andrewtrobec Motivator in Splunk Search 11-22-2016
0 3
0
3
nehal_shah
Hi All, I have a Splunk form where I am using 2 time pickers to come up with different times for 3 different joins i...
by nehal_shah Explorer in Splunk Search 11-22-2016
0 2
0
2
kualo
[2016-xx-xx-xx:xx:xx:xxxx] modelName=model1, modelScore=10 [2016-xx-xx-xx:xx:xx:xxxx] modelName=model2, modelScore=10...
by kualo Explorer in Splunk Search 11-22-2016
1 3
1
3
rsathish47
Hi How do we get a dispatch job list in a Splunk search head cluster? Thanks Sathish Rangan
by rsathish47 Contributor in Splunk Search 11-22-2016
0 1
0
1
benazir
I have hosts with multiple sql id and elapsed time. I have to chart, per host, sql ids against elapsed time. Can anyo...
by benazir Explorer in Splunk Search 11-22-2016
0 1
0
1
landen99
I want to count the number of times that the following event is true, bool = ((field1 <> field2) AND (field3 < 8)), f...
by landen99 Motivator in Splunk Search 11-22-2016
2 6
2
6
sanikuriakose12
Hi I have to creat a total_threat_score field which will be the total of all other score fields like if action==a...
by sanikuriakose12 New Member in Splunk Search 11-22-2016
0 1
0
1
ivanlesk
Hi, I have something like this. ID date(month) avgValue1 avgValue2 avgValue3 ... 111 2016-06 ...
by ivanlesk Engager in Splunk Search 11-22-2016
0 3
0
3
Quiad
Hi! How can i find all the violations in the past? I have tried using this search and change time to all time but onl...
by Quiad New Member in Splunk Search 11-22-2016
0 2
0
2
seetharamanPr
how to get domain name, domain user name from active directory logs 11/22/2016 04:15:20 PM LogName=Security SourceN...
by seetharamanPr New Member in Splunk Search 11-22-2016
0 1
0
1
twilishyflutter
my time stamps are in %H:%M format. one of which is a custom time stamp from my json file. is there a way i can calc...
by twilishyflutter New Member in Splunk Search 11-22-2016
0 1
0
1
neiowe
I am trying to build a report that shows how long a user was logged on. To do this, I am trying to match LOGON_IDs f...
by neiowe Path Finder in Splunk Search 11-22-2016
2 8
2
8
mderosa
Hi, first of all thanks for help me. I have this log file: 2016-11-21T16:29:25.690+0100 INFO 2867 com.l7tech.log...
by mderosa New Member in Splunk Search 11-22-2016
0 3
0
3
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors