Splunk Search

Splunk Search
Community Activity
rijinc
Hi Team, I have three sourcetypes, all the sourcetypes have two or three common fields , how to extract the data as...
by rijinc Explorer in Splunk Search 11-03-2016
0 1
0
1
sweenj
I have a search string. index=data sourcetype=jobs QUEUE=myqueue| dedup JOBID | FIELDS CPU_USED, USER group by USER...
by sweenj Explorer in Splunk Search 11-03-2016
0 3
0
3
sarnagar
I'm completely new to REGEX. Started off learning by going through some videos and splunk docs. Can someone please pr...
by sarnagar Contributor in Splunk Search 11-03-2016
0 2
0
2
ssujin
I have created tags in tags.conf inside my splunk app as below. [index=index1] app_index = enabled [index=index2] a...
by ssujin Explorer in Splunk Search 11-03-2016
1 2
1
2
hartfoml
I have two field names from different sourcetype with the desired value that I want to put in a table with the same n...
by hartfoml Motivator in Splunk Search 11-03-2016
0 2
0
2
surekhasplunk
AM not able to see all the incidents which are there in my servicenow instance. I have splunk_TA_Snow app configured...
by surekhasplunk Communicator in Splunk Search 11-03-2016
0 1
0
1
msachdeva3
I have a csv file with some stats code, i have added as a lookup . I want to use two fields in stats code with say ...
by msachdeva3 Explorer in Splunk Search 11-03-2016
0 2
0
2
pjasa
Hi splunkers. Im running Splunk v6.4.3 and I need to match the output from a normal sourcetype="cisco:syslog" sear...
by pjasa New Member in Splunk Search 11-02-2016
0 3
0
3
vamshi245
I have a form, which has a text field for users to enter the orderid. users can enter in lower case or upper case. Th...
by vamshi245 New Member in Splunk Search 11-02-2016
0 4
0
4
deepak312
I have this search which is not returning any result, I am not sure of the issue. Any help? index=my_index status!=2...
by deepak312 Explorer in Splunk Search 11-02-2016
0 2
0
2
dreeck
I would like to find lines in log A based on the results of search B, but havent been able to get what I want using s...
by dreeck Path Finder in Splunk Search 11-02-2016
0 2
0
2
AndySplunks
I'm having trouble creating a chart overlay. Every example for a chart overlay is for a timechart, leading me to won...
by AndySplunks Communicator in Splunk Search 11-02-2016
0 5
0
5
hagjos43
Current search results are in a table form such as the following: Search String | Search Engine | Visits | Percent D...
by hagjos43 Contributor in Splunk Search 11-02-2016
1 5
1
5
Kukkadapu
Hi, I've created a datamodel which has a TRANSACTION. When I try to use the datamodel query for a longer period of ti...
by Kukkadapu Path Finder in Splunk Search 11-02-2016
0 2
0
2
cchange
Hi, I'm trying to append the results from two tables. I used appendcols with override option. But results showing di...
by cchange Path Finder in Splunk Search 11-02-2016
0 2
0
2
ddrillic
We have the following working query - (index= primary_claim amt > 1000 ) OR (index=secondary_cla...
by ddrillic Ultra Champion in Splunk Search 11-02-2016
0 21
0
21
anshumandas
Hi, I would like to join 2 tables with multiple fields based on common field Column 1 where Table:1 will have field...
by anshumandas New Member in Splunk Search 11-02-2016
0 7
0
7
vkakani60
Is there any way to save the count of the events before doing the dedup ? This is my query index="webapplication_lo...
by vkakani60 Path Finder in Splunk Search 11-02-2016
0 4
0
4
robertlynch2020
Hi I am looking for a way to get the number of events from host=ALL with sourcetype=tps. However it looks like i can...
by robertlynch2020 Influencer in Splunk Search 11-02-2016
0 1
0
1
Kukkadapu
Hi, I see that the access count of the datamodel is always zero, even though we are using the datamodel in searches a...
by Kukkadapu Path Finder in Splunk Search 11-02-2016
0 2
0
2
SecureIA
Hi all, I currently have a very simple search that looks at the distinct visitors for a website per day. See below, ...
by SecureIA Path Finder in Splunk Search 11-02-2016
0 2
0
2
arjangoos
I want to combine two events based on different fields (ID and PARENT_ID) that have the same value and then find the ...
by arjangoos Path Finder in Splunk Search 11-02-2016
0 1
0
1
jberd126
I'm struggling to convert a duration in format HH:MM:SS.NNNNNNN to seconds in a concise manner. For example, 01:03:0...
by jberd126 Path Finder in Splunk Search 11-02-2016
0 2
0
2
burras
Attempting to build some monitoring whereby we run a Splunk search from the command line interface (CLI) over a given...
by burras Communicator in Splunk Search 11-02-2016
0 5
0
5
mute_dammit
I've created a custom command in python that needs to view an entire set of events as a single batch, because it's co...
by mute_dammit Engager in Splunk Search 11-02-2016
1 9
1
9
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...