Splunk Search

Splunk Search
Community Activity
mohanmk1905
I am getting Username and User id Fields while search using username, then I pipe it and search user ID to get the pa...
by mohanmk1905 New Member in Splunk Search 11-15-2016
0 5
0
5
serenalin
Hello, I want to delete the time point if there is the one or more host max(time)>avg(time)+5 at that point in time....
by serenalin New Member in Splunk Search 11-15-2016
0 1
0
1
smudge797
I have a set of ticket data and trying to match the words with the description to track issues. My current search is ...
by smudge797 Path Finder in Splunk Search 11-15-2016
0 1
0
1
wegscd
Trying to get our freshly working DB Connect configured. I am finding a problem in that I cannot save some new datab...
by wegscd Contributor in Splunk Search 11-15-2016
0 7
0
7
uhkc777
Hi, I saved one report and enabled summary indexing. This is the saved search: index=Test |stats count(ip) as Coun...
by uhkc777 Explorer in Splunk Search 11-15-2016
0 15
0
15
burras
I have what should be a fairly simple timechart that I'm looking to do. In our data, we have a field (util) that r...
by burras Communicator in Splunk Search 11-15-2016
1 3
1
3
rajgowd1
hi, I have data like below and extracted fields hostname ,logname and data. By using these and existing defaults fie...
by rajgowd1 Communicator in Splunk Search 11-15-2016
0 1
0
1
tkwaller
Hello Trying to get this search to work, it works if I remove the BY clause: index=java host=*myhost* "PLACEORDER_A...
by tkwaller Builder in Splunk Search 11-15-2016
0 7
0
7
rwiley
i have a search with these results. description, stringValue datetime, "epoc time" zone, "zone...
by rwiley Explorer in Splunk Search 11-15-2016
0 5
0
5
jwalzerpitt
I have a lookup table that has five fields: User Account Type Employee RC Employee Department Student RC ...
by jwalzerpitt Influencer in Splunk Search 11-15-2016
0 14
0
14
himapate
I need to build a search for tracing logs cleared from /var/log/message/ or /var/log/secure/ .
by himapate Explorer in Splunk Search 11-15-2016
0 1
0
1
andyp54
Hello New to Splunk, so I know there is a simple answer to this, but I just can't find it  I have two inputlookup ...
by andyp54 New Member in Splunk Search 11-15-2016
0 2
0
2
shreyasathavale
I have a search that returns 25 hosts, but on a chart at the bottom, the legend just shows 10 hosts. I want to displa...
by shreyasathavale Communicator in Splunk Search 11-15-2016
0 4
0
4
bcronrath
I've tried this with multiple fields now and the same behavior occurs. What I want is simple: To auto extract a fie...
by bcronrath Path Finder in Splunk Search 11-14-2016
0 1
0
1
theouhuios
Hello I am trying to add a image onto the data in the table. This is what I am trying to make The images should c...
by theouhuios Motivator in Splunk Search 11-14-2016
1 9
1
9
kreekoor
Hi All, I'm creating a dashboard containing a forecast for a number of expected calls. Should look something like t...
by kreekoor Engager in Splunk Search 11-14-2016
0 2
0
2
prashanthberam
I WANT TO COMBINE THOSE TIMESTAMP INTO ONE COLUMN HOW CAN I DO THAT BUT I DON'T WANT USE THE TRANSACTION COMMAND H...
by prashanthberam Explorer in Splunk Search 11-14-2016
0 7
0
7
vRman
Is there a way to set sampling ratio directly in an SPL query rather than in the GUI or Simple XML ?
by vRman Engager in Splunk Search 11-14-2016
0 1
0
1
HMTODD
I have data for a batch job that runs each day. I have StartTime, EndTime, and a calculated value for duration. The...
by HMTODD Explorer in Splunk Search 11-14-2016
0 4
0
4
thepocketwade
I want to avoid killing somebody else's search in the event I need to restart splunk. Is there any way to see all the...
by thepocketwade Path Finder in Splunk Search 11-14-2016
4 7
4
7
naty
Hey, i'm trying to merge/join 2 searches into 1, and create a table of the data. this is my starting query: index=...
by naty Path Finder in Splunk Search 11-14-2016
0 1
0
1
horsefez
Hi fellow splunkers, I ran into a problem regarding "Overwriting of an existing sourcetype via props and transforms...
by horsefez Motivator in Splunk Search 11-14-2016
1 2
1
2
vhuphilo
I would like to search for values that end with or begin with specific characters
by vhuphilo Engager in Splunk Search 11-14-2016
0 1
0
1
daniel_knights
We have made a dashboard to show the rare events generated by users Account_Name=XX* |rare limit=20 EventCode |tabl...
by daniel_knights New Member in Splunk Search 11-14-2016
0 2
0
2
dsofoulis
I would like to change the name of an index without losing any data etc. Is it possible to modify an index name in th...
by dsofoulis Path Finder in Splunk Search 11-14-2016
0 1
0
1
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...