Splunk Search

Splunk Search
Community Activity
sarfarajsayyad
I have an index with 30+ fields. One of the field is state. I want to find amount of time an event is in a particular...
by sarfarajsayyad New Member in Splunk Search 11-21-2016
0 1
0
1
emoyoun
I need to generate a calculated field in Pivot with no luck. I tried this: | pivot Statistics HTTP sum(eval(count/3...
by emoyoun New Member in Splunk Search 11-21-2016
0 11
0
11
pavanae
I have a string in my search as below which combines the two fields A and B eval big_and_small=A."and".B Now how...
by pavanae Builder in Splunk Search 11-21-2016
0 1
0
1
sravankaripe
I want to display the user details, search query that was run, and url of the user who are running the real time sear...
by sravankaripe Communicator in Splunk Search 11-21-2016
0 1
0
1
splgeek
Can someone please help me extract all different OS types from my logs. is there anyway Single rex query i can write ...
by splgeek Explorer in Splunk Search 11-21-2016
0 6
0
6
markramsay20070
I've a standard time chart, counting up HTTP error codes. It's all fine, however I'd like to separate out the error-t...
by markramsay20070 New Member in Splunk Search 11-21-2016
0 1
0
1
jesperp
I have my nessus data in splunk, and in my example below I would like to search for all critical findings, and for ea...
by jesperp Engager in Splunk Search 11-21-2016
0 1
0
1
dlpco
I am using 6.5.0 of Splunk with the Free license install. When in the Search and Reporting screen, I get no Search A...
by dlpco Path Finder in Splunk Search 11-21-2016
0 5
0
5
pavanae
I have a Splunk search as below: earliest=-1d@d latest=@d index="abc" sourcetype="def" | stats earliest(date_hour) a...
by pavanae Builder in Splunk Search 11-20-2016
0 11
0
11
pmaitra
I have a search from which I extracted field A. In the second search, how do I assign A to be the source of the secon...
by pmaitra Explorer in Splunk Search 11-20-2016
0 5
0
5
loveforsplunk
Query I am using is : index=anyvalue host=anyvalue keyword [search index=anyvalue host=anyvalue source=y/y/y/y| ...
by loveforsplunk Explorer in Splunk Search 11-19-2016
0 1
0
1
premselvans
I have a table as below. I need to calculate the time difference between the below two events. request_pid _time...
by premselvans New Member in Splunk Search 11-19-2016
0 3
0
3
tpirozzi
So if I have over the past 30 days various counts per day I want to display the following in a stats table showing th...
by tpirozzi Explorer in Splunk Search 11-19-2016
0 1
0
1
demkic
Hi all, Is it possible to combine several field variables into one variable but keep it in the same field? Here is an...
by demkic Explorer in Splunk Search 11-18-2016
0 2
0
2
swe
Hi there, i have a multisensor device sending messages via MQTT. i am trying to extract the fields from it. it wor...
by swe Path Finder in Splunk Search 11-18-2016
0 2
0
2
sundarrajan
Reason for this specific question is to understand the performance quotient for each command like rex/xmlkv/spath/mul...
by sundarrajan Path Finder in Splunk Search 11-18-2016
0 1
0
1
gaurav_gg
CF_MSG(field name) : "App instance exited with guid fd4c7738-1dea-449d-a13b-7856d843c5b3 payload: {\"instance\"=\u00...
by gaurav_gg New Member in Splunk Search 11-18-2016
0 2
0
2
sravankaripe
I need a sample code for field extraction during index time in props.conf and transforms.conf for the below use case....
by sravankaripe Communicator in Splunk Search 11-18-2016
0 1
0
1
kiran331
Hi From the search, i get the event_date field. How can I filter the events by using the event_date field? event_...
by kiran331 Builder in Splunk Search 11-18-2016
0 1
0
1
splunkin11
Is there a way to change the time duration calculated to a more readable format? Trying to go from something like th...
by splunkin11 Path Finder in Splunk Search 11-18-2016
0 3
0
3
redlose
Hi everybody I'm going crazy because of a "timeproblem" which sounds not hard to handle, but i don't get it... My h...
by redlose New Member in Splunk Search 11-18-2016
0 3
0
3
kiran_mh
Hi, I have the following expression (?=[^C]*(?:CASE|C.*CASE))^(?:[^:\n]*:){5}\s+\w+(?P.+), which is used to extract ...
by kiran_mh Explorer in Splunk Search 11-18-2016
0 4
0
4
adityapavan18
Hi I have a custom app, it is a simple app which contains a few dashboards and nothing more. When i click app it's s...
by adityapavan18 Contributor in Splunk Search 11-18-2016
0 2
0
2
puneethgowda
source=DAM_DB_SUMMARY_REPORT | eval Date=substr(DATES,1,10) | stats sum(TOTAL_RECORDS) as "Total Records" by Date | ...
by puneethgowda Communicator in Splunk Search 11-18-2016
0 3
0
3
rodneyjerome
Hi, I am trying to extract fields from a JSON input. I don't understand if I am making any mistake in getting the eve...
by rodneyjerome Explorer in Splunk Search 11-18-2016
0 3
0
3
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...