Splunk Search

Splunk Search
Community Activity
loveforsplunk
Query I am using is : index=anyvalue host=anyvalue keyword [search index=anyvalue host=anyvalue source=y/y/y/y| ...
by loveforsplunk Explorer in Splunk Search 11-19-2016
0 1
0
1
premselvans
I have a table as below. I need to calculate the time difference between the below two events. request_pid _time...
by premselvans New Member in Splunk Search 11-19-2016
0 3
0
3
tpirozzi
So if I have over the past 30 days various counts per day I want to display the following in a stats table showing th...
by tpirozzi Explorer in Splunk Search 11-19-2016
0 1
0
1
demkic
Hi all, Is it possible to combine several field variables into one variable but keep it in the same field? Here is an...
by demkic Explorer in Splunk Search 11-18-2016
0 2
0
2
swe
Hi there, i have a multisensor device sending messages via MQTT. i am trying to extract the fields from it. it wor...
by swe Path Finder in Splunk Search 11-18-2016
0 2
0
2
sundarrajan
Reason for this specific question is to understand the performance quotient for each command like rex/xmlkv/spath/mul...
by sundarrajan Path Finder in Splunk Search 11-18-2016
0 1
0
1
gaurav_gg
CF_MSG(field name) : "App instance exited with guid fd4c7738-1dea-449d-a13b-7856d843c5b3 payload: {\"instance\"=\u00...
by gaurav_gg New Member in Splunk Search 11-18-2016
0 2
0
2
sravankaripe
I need a sample code for field extraction during index time in props.conf and transforms.conf for the below use case....
by sravankaripe Communicator in Splunk Search 11-18-2016
0 1
0
1
kiran331
Hi From the search, i get the event_date field. How can I filter the events by using the event_date field? event_...
by kiran331 Builder in Splunk Search 11-18-2016
0 1
0
1
splunkin11
Is there a way to change the time duration calculated to a more readable format? Trying to go from something like th...
by splunkin11 Path Finder in Splunk Search 11-18-2016
0 3
0
3
redlose
Hi everybody I'm going crazy because of a "timeproblem" which sounds not hard to handle, but i don't get it... My h...
by redlose New Member in Splunk Search 11-18-2016
0 3
0
3
kiran_mh
Hi, I have the following expression (?=[^C]*(?:CASE|C.*CASE))^(?:[^:\n]*:){5}\s+\w+(?P.+), which is used to extract ...
by kiran_mh Explorer in Splunk Search 11-18-2016
0 4
0
4
adityapavan18
Hi I have a custom app, it is a simple app which contains a few dashboards and nothing more. When i click app it's s...
by adityapavan18 Contributor in Splunk Search 11-18-2016
0 2
0
2
puneethgowda
source=DAM_DB_SUMMARY_REPORT | eval Date=substr(DATES,1,10) | stats sum(TOTAL_RECORDS) as "Total Records" by Date | ...
by puneethgowda Communicator in Splunk Search 11-18-2016
0 3
0
3
rodneyjerome
Hi, I am trying to extract fields from a JSON input. I don't understand if I am making any mistake in getting the eve...
by rodneyjerome Explorer in Splunk Search 11-18-2016
0 3
0
3
daniel333
All, Assuming Splunk has a function for this. But for the life of me I can't find it. Is there a tool to convert de...
by daniel333 Builder in Splunk Search 11-18-2016
1 3
1
3
rajgowd1
Hi, i have created dashboard with 2 dropdowns based on host and based on Time Range. When select host it is working b...
by rajgowd1 Communicator in Splunk Search 11-17-2016
0 2
0
2
ddrillic
We have an HDFS source with sqoop files that have this naming pattern - 000000_0 to 003064_0 and each file is at the ...
by ddrillic Ultra Champion in Splunk Search 11-17-2016
0 2
0
2
pavanae
I have a splunk Query as below earliest=-1d@d latest=@d index=abc | where date_hour>=15 OR date_hour<9 | stats earli...
by pavanae Builder in Splunk Search 11-17-2016
0 1
0
1
jbsplunk
Using redhat 6, I've noticed that my Splunk instance has searches that are consuming large amounts of CPU and I am ex...
by jbsplunk Splunk Employee Splunk Employee in Splunk Search 11-17-2016
4 3
4
3
sushmitha_mj
I wanted to accelerate my searches so I am using data models and pivot. | pivot Accounting Accounting sum(Input) A...
by sushmitha_mj Communicator in Splunk Search 11-17-2016
1 4
1
4
abhijit_mhatre
Please let me know the regex for this. How can the extracted field be modified? Thanks
by abhijit_mhatre Path Finder in Splunk Search 11-17-2016
1 2
1
2
rajgowd1
Hi, we have 2 configuration files like spg.conf and spg.conf.1162016 and we written perl program to find the differen...
by rajgowd1 Communicator in Splunk Search 11-17-2016
0 6
0
6
pramaswamy
I have a Splunk application with two Dashboards. Dashboard1 ( D1 ) is a higher level dashboard that reports overall u...
by pramaswamy Path Finder in Splunk Search 11-17-2016
0 4
0
4
dstark75
I have JSON data that is broken into fields. I'm trying to add color to my stats panel or pivot table, but I'm unabl...
by dstark75 New Member in Splunk Search 11-17-2016
0 12
0
12
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...