Splunk Search

Splunk Search
Community Activity
mexscrabbler
I'm using a Splunk application I developed myself 2 years ago. At the time, I had an Enterprise trial license. I save...
by mexscrabbler Explorer in Splunk Search 11-07-2016
0 8
0
8
zuokun
Newbie here, would appreciate if anyone can help to answer this little question. I have two sourcetypes, A and B. A...
by zuokun New Member in Splunk Search 11-07-2016
0 1
0
1
nivethainspire_
My field has following value summary="java running in chrome" I need a search such that summary should have the wo...
by nivethainspire_ Explorer in Splunk Search 11-07-2016
0 4
0
4
slr
Hi there. I'm trying to do something like this: Relative Conversion = Event Conversion / Total Conversion Where: ...
by slr Communicator in Splunk Search 11-07-2016
0 4
0
4
nivethainspire_
I need to add a column stating the difference in count (today - yesterday). How can I write this search? Existing se...
by nivethainspire_ Explorer in Splunk Search 11-07-2016
0 5
0
5
ColinCH
Hi, We have a script that runs every day. The script adds a field called "export_time" which i use to determine the ...
by ColinCH Path Finder in Splunk Search 11-07-2016
0 3
0
3
dfwissman
I'm trying to manipulate some data from our incident management software to calculate the amount of time an incident ...
by dfwissman New Member in Splunk Search 11-07-2016
0 3
0
3
Hemnaath
Hi All, Currently I am facing an issue with scheduled reports. The scheduled job is getting executed as per the cr...
by Hemnaath Motivator in Splunk Search 11-07-2016
0 17
0
17
bowesmana
I think I am going mad... I set up a lookup table (points.csv) containing range,Place,Points 2013,1,20 2013,2,15 20...
by SplunkTrust SplunkTrust in Splunk Search 11-07-2016
0 2
0
2
sailey
Below are the few patterns that I wanted to search from multiple sourcetypes and get the count. I have around 50 patt...
by sailey New Member in Splunk Search 11-07-2016
0 1
0
1
pguridi
Hi everyone, Splunk noob here.. so any I help I would be grateful!. I've been trying to use the percX() function with...
by pguridi New Member in Splunk Search 11-06-2016
0 1
0
1
kamal_jagga
I have the following values in the field and need to write regex for this. Regex :(?P\d\,\d\d\d) Input 9 19 157 1,5...
by kamal_jagga Contributor in Splunk Search 11-05-2016
0 4
0
4
nivethainspire_
I have 3 columns in a table as below. I need to sum two colums(mag and depth) if place="7km W of Cobb,california" or...
by nivethainspire_ Explorer in Splunk Search 11-05-2016
0 1
0
1
k_harini
The below EVAL function is working as search command, but not working when added as calculated field myindex |EVAL t...
by k_harini Communicator in Splunk Search 11-04-2016
0 8
0
8
aparnaa
Hello I have 2 queries, one to find top 10 CPU utilising process and 1 more for finding the avg CPU utilisation but ...
by aparnaa Path Finder in Splunk Search 11-04-2016
0 5
0
5
a212830
Hi, I want to run reports against certain slaves reporting into the license manager, and filter them via a lookup. ...
by a212830 Champion in Splunk Search 11-04-2016
0 3
0
3
splunker9999
Hi, Can you please help us in changing time from central to EST during search time? We have our server in central zo...
by splunker9999 Path Finder in Splunk Search 11-04-2016
0 5
0
5
TobiasBoone
| foreach p* [eval val='<>' | lookup wkst_risk_control asset_risk_position AS 'val'] I have 19 separate p extractio...
by TobiasBoone Communicator in Splunk Search 11-04-2016
0 1
0
1
ekremikizoglu
Hi, Following the Documentation provided by splunk I triggered streamfwd from the command line for my pcap. http://d...
by ekremikizoglu Explorer in Splunk Search 11-04-2016
0 3
0
3
kiran331
Hi How to add the line break in the eval function base search|eval new = src_host+","+"Event Code="+EventCode+","...
by kiran331 Builder in Splunk Search 11-04-2016
0 3
0
3
zeewagon
INFO : Start Outputing Report: Project ID:c_exactworld_17121, Format:EXCEL Above is my search result, and I wanna ex...
by zeewagon Engager in Splunk Search 11-04-2016
0 9
0
9
jnithya
I am using the tag name in search query to filter down the app specific index, followed by "index=index1" to filter d...
by jnithya Engager in Splunk Search 11-04-2016
0 1
0
1
surekhasplunk
I have a search which will return me field email id. index=snow description=*CPU* |table number sys_created_by nu...
by surekhasplunk Communicator in Splunk Search 11-04-2016
2 4
2
4
danielcmarcosjr
Hi All, I want to search a word in Splunk in a certain field for example "foo" and will return the following: foo b...
by danielcmarcosjr Explorer in Splunk Search 11-04-2016
1 23
1
23
a212830
Hi, I have a regex to allow certain data into Splunk via a transforms, and now I need to update it. I made some chan...
by a212830 Champion in Splunk Search 11-04-2016
0 10
0
10
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors