Splunk Search

Splunk Search
Community Activity
pavanae
I have the Splunk searches as below: search: My Search | stats earliest(date_hour) as FirstHour latest(date_hour) ...
by pavanae Builder in Splunk Search 11-10-2016
1 7
1
7
sravankaripe
i want to extract the fields and values where field name start with dv_ . Please help me with field extraction on thi...
by sravankaripe Communicator in Splunk Search 11-10-2016
0 6
0
6
wcooper003
I want to populate a time picker to display "Last 30 days" through a URL link. Currently I do something like this: ...
by wcooper003 Communicator in Splunk Search 11-10-2016
0 2
0
2
SathyaNarayanan
Hi, I have list of servers, I need to find top Event Codes errors for each host, as each host as different Event cod...
by SathyaNarayanan Path Finder in Splunk Search 11-10-2016
0 12
0
12
pbenner
I have created a csv lookup table and have successfully loaded it into splunk and used it in a search command source...
by pbenner Explorer in Splunk Search 11-10-2016
1 6
1
6
surekhasplunk
I have written below search where i have used appendcols option so that all the result will come under one table view...
by surekhasplunk Communicator in Splunk Search 11-10-2016
0 4
0
4
pavanae
I have 2 Splunk searches as below: search 1: My Search | stats earliest(date_hour) as FirstHour latest(date_hour) a...
by pavanae Builder in Splunk Search 11-10-2016
0 1
0
1
sfatnass
hi i try to perform a subsearch using join type=left between two index. first my indexs are configured like this : ...
by sfatnass Contributor in Splunk Search 11-10-2016
0 2
0
2
bhawkins1
I have a search which produces a stats with 2 columns, and n = 3k, where k is an integer, rows. The second column is ...
by bhawkins1 Communicator in Splunk Search 11-10-2016
1 2
1
2
seetharamanPr
Hi All, We have our Symantec End Point Protection which is sending logs and it is monitoring both servers and user P...
by seetharamanPr New Member in Splunk Search 11-09-2016
0 4
0
4
viggor
I have a query of the form 'stats list(body) AS events BY id Which gives me for example: id body 1 jack 2 foo b...
by viggor Path Finder in Splunk Search 11-09-2016
0 2
0
2
pavanae
search :- My search | stats values(date_hour) as Access_time by user The above search displays the user id with thei...
by pavanae Builder in Splunk Search 11-09-2016
0 2
0
2
tgdvopab
Hello, I want to count the number of different messages and show them in a pie chart. My data looks like the followin...
by tgdvopab Path Finder in Splunk Search 11-09-2016
0 2
0
2
mstark31
Is there a way to use eval to calculate the standard deviation of data in multiple fields (same number of fields each...
by mstark31 Path Finder in Splunk Search 11-09-2016
1 4
1
4
Shark2112
Hey everyone. I want to search updated events via jira rest for adding them in my index after. My search work fine o...
by Shark2112 Communicator in Splunk Search 11-09-2016
0 1
0
1
splunkreal
Hello, is it possible to add clustered search peers (indexers) to standalone search head? Thanks.
by splunkreal Motivator in Splunk Search 11-09-2016
0 8
0
8
sravankaripe
We have X-numbers of search heads. i want to create a dashboard which will calculate searches per minute on each Splu...
by sravankaripe Communicator in Splunk Search 11-09-2016
0 1
0
1
ColinCH
Hi I want to extract some JSON fields (ENV,IP,PORT) from an already extracted field (http_cookie). That was not the ...
by ColinCH Path Finder in Splunk Search 11-09-2016
0 2
0
2
k_harini
I have to get the count of records with multiple status and due date less than current date.. Below query - This qu...
by k_harini Communicator in Splunk Search 11-09-2016
0 2
0
2
ravitejaj
For example I have the below data as text: Aug-16 Sep-16 Oct-16 Nov-16 Feb-16 When I sort it with Month, I wish to ...
by ravitejaj Explorer in Splunk Search 11-09-2016
0 7
0
7
pavanae
I have my search as below index=xyz source=yhg | convert ctime(_time) as Date_and_Time|convert timeformat="%m/%d/%Y ...
by pavanae Builder in Splunk Search 11-08-2016
0 1
0
1
pavanae
I have my two searches as below search 1 index=xyz source=yhg | top 5 student_id search 2 index=xyz source=yh...
by pavanae Builder in Splunk Search 11-08-2016
0 2
0
2
pavanae
I have my splunk search as below My Search | where date_hour>=16 OR date_hour<9| convert ctime(_time) as Date_and_Ti...
by pavanae Builder in Splunk Search 11-08-2016
0 1
0
1
markwymer
HI, Apologies if this is answered elsewhere but I can't find a question that fits my situation although I'm sure tha...
by markwymer Path Finder in Splunk Search 11-08-2016
0 2
0
2
pavanae
I have a search which displays the average_time_spent in the format "hh:mm:ss" my search | eval field_in_hhmmss=tost...
by pavanae Builder in Splunk Search 11-08-2016
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...