Splunk Search

Splunk Search
Community Activity
msachdeva3
I have a csv file with some stats code, i have added as a lookup . I want to use two fields in stats code with say ...
by msachdeva3 Explorer in Splunk Search 11-03-2016
0 2
0
2
pjasa
Hi splunkers. Im running Splunk v6.4.3 and I need to match the output from a normal sourcetype="cisco:syslog" sear...
by pjasa New Member in Splunk Search 11-02-2016
0 3
0
3
vamshi245
I have a form, which has a text field for users to enter the orderid. users can enter in lower case or upper case. Th...
by vamshi245 New Member in Splunk Search 11-02-2016
0 4
0
4
deepak312
I have this search which is not returning any result, I am not sure of the issue. Any help? index=my_index status!=2...
by deepak312 Explorer in Splunk Search 11-02-2016
0 2
0
2
dreeck
I would like to find lines in log A based on the results of search B, but havent been able to get what I want using s...
by dreeck Path Finder in Splunk Search 11-02-2016
0 2
0
2
AndySplunks
I'm having trouble creating a chart overlay. Every example for a chart overlay is for a timechart, leading me to won...
by AndySplunks Communicator in Splunk Search 11-02-2016
0 5
0
5
hagjos43
Current search results are in a table form such as the following: Search String | Search Engine | Visits | Percent D...
by hagjos43 Contributor in Splunk Search 11-02-2016
1 5
1
5
Kukkadapu
Hi, I've created a datamodel which has a TRANSACTION. When I try to use the datamodel query for a longer period of ti...
by Kukkadapu Path Finder in Splunk Search 11-02-2016
0 2
0
2
cchange
Hi, I'm trying to append the results from two tables. I used appendcols with override option. But results showing di...
by cchange Path Finder in Splunk Search 11-02-2016
0 2
0
2
ddrillic
We have the following working query - (index= primary_claim amt > 1000 ) OR (index=secondary_cla...
by ddrillic Ultra Champion in Splunk Search 11-02-2016
0 21
0
21
anshumandas
Hi, I would like to join 2 tables with multiple fields based on common field Column 1 where Table:1 will have field...
by anshumandas New Member in Splunk Search 11-02-2016
0 7
0
7
vkakani60
Is there any way to save the count of the events before doing the dedup ? This is my query index="webapplication_lo...
by vkakani60 Path Finder in Splunk Search 11-02-2016
0 4
0
4
robertlynch2020
Hi I am looking for a way to get the number of events from host=ALL with sourcetype=tps. However it looks like i can...
by robertlynch2020 Influencer in Splunk Search 11-02-2016
0 1
0
1
Kukkadapu
Hi, I see that the access count of the datamodel is always zero, even though we are using the datamodel in searches a...
by Kukkadapu Path Finder in Splunk Search 11-02-2016
0 2
0
2
SecureIA
Hi all, I currently have a very simple search that looks at the distinct visitors for a website per day. See below, ...
by SecureIA Path Finder in Splunk Search 11-02-2016
0 2
0
2
arjangoos
I want to combine two events based on different fields (ID and PARENT_ID) that have the same value and then find the ...
by arjangoos Path Finder in Splunk Search 11-02-2016
0 1
0
1
jberd126
I'm struggling to convert a duration in format HH:MM:SS.NNNNNNN to seconds in a concise manner. For example, 01:03:0...
by jberd126 Path Finder in Splunk Search 11-02-2016
0 2
0
2
burras
Attempting to build some monitoring whereby we run a Splunk search from the command line interface (CLI) over a given...
by burras Communicator in Splunk Search 11-02-2016
0 5
0
5
mute_dammit
I've created a custom command in python that needs to view an entire set of events as a single batch, because it's co...
by mute_dammit Engager in Splunk Search 11-02-2016
1 9
1
9
splunkrocks2014
How to write a search that will determine if a lookup file has been updated? Thanks.
by splunkrocks2014 Communicator in Splunk Search 11-02-2016
0 4
0
4
wcooper003
I have an intensive search populating a dashboard that i'd like to schedule once a day, or as requested by the user -...
by wcooper003 Communicator in Splunk Search 11-02-2016
0 2
0
2
gpburgett
I've got a custom command that we're running over a large set of data. When I just run the part of the query up to ri...
by gpburgett Splunk Employee Splunk Employee in Splunk Search 11-02-2016
1 1
1
1
asingla
I have components which are sending UDP messages to splunk. The message format is key1=value1|key2=value2|.... Fe...
by asingla Communicator in Splunk Search 11-02-2016
4 12
4
12
aliroumani
Dear Sirs, in symantec dlp we have different policies consider it as (1,2,3,...etc) and when i user violate any polic...
by aliroumani Explorer in Splunk Search 11-02-2016
0 1
0
1
wgoodwin_splunk
I have a customer that is attempting to check a field “Account_Name”. Some of the events have multiple account names...
by wgoodwin_splunk Splunk Employee Splunk Employee in Splunk Search 11-02-2016
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...