Splunk Search

Splunk Search
Community Activity
nasamajh09
I want to count all the values of a field, and display all the values as well. How do I write a search in Splunk to a...
by nasamajh09 New Member in Splunk Search 10-27-2016
0 1
0
1
xfiles80
Hi, I am a begginner and can't find solution for my problem. I have 3 fields: 2 from one source Characteristic ( ha...
by xfiles80 New Member in Splunk Search 10-27-2016
0 7
0
7
danoconnl
So we got Splunk installed and started indexing our logs before changes were put in place to better integrate with Sp...
by danoconnl Explorer in Splunk Search 10-27-2016
0 3
0
3
aamirs291
Hello Everyone, I have two events which I have uploaded in CSV format and the events will be consistent as below: ...
by aamirs291 Path Finder in Splunk Search 10-27-2016
0 7
0
7
joshualarkins
I have a group of users to monitor. They create actions on a fairly regular basis, but they do not all follow the sam...
by joshualarkins Explorer in Splunk Search 10-26-2016
0 4
0
4
clintla
Not finding any examples so far, but not sure if it's possible. Wanting to have one dashboard panel that has a resu...
by clintla Contributor in Splunk Search 10-26-2016
2 4
2
4
jagadeeshm
I have front-end events with several dynamic uri patterns. I am trying to generate a report to summarize the average,...
by jagadeeshm Contributor in Splunk Search 10-26-2016
0 2
0
2
splunker12er
I have created a savedsearch which displays the Current license usage indexer wise. ("|rest" query) x- axis : Indexe...
by splunker12er Motivator in Splunk Search 10-26-2016
0 7
0
7
splgeek
I want to extract the PHP Message as a field so I can have all the various php error messages: 2016/10/20 21:23:18 [...
by splgeek Explorer in Splunk Search 10-26-2016
0 3
0
3
pavanae
I have a search as follows My search | bin span=1h _time | stats values(field_1) as Field_1 by _time Field_2 Which...
by pavanae Builder in Splunk Search 10-26-2016
0 1
0
1
erwin_pader_1dc
hi, i have a main search- |inputlookup wlaa_hosts.csv | eval Host=split(HostList,",") | stats count by Host that ...
by erwin_pader_1dc New Member in Splunk Search 10-26-2016
0 2
0
2
reed_kelly
We have accelerations turned on and at 100% for a number of our datamodels. I like the speed obtained by using |tstat...
by reed_kelly Contributor in Splunk Search 10-26-2016
1 3
1
3
mataharry
I was using dbinpect to calculates the first and last events in my buckets. In splunk 4.* and 5.*, it was returning 2...
by mataharry Communicator in Splunk Search 10-26-2016
1 3
1
3
david_halbeisen
| metadata type=sourcetypes index=* My time range picker is set to today (Today is July 30, 2015). I analyzed my da...
by david_halbeisen New Member in Splunk Search 10-26-2016
0 2
0
2
umsundar2015
Hi, I have scenario like having timechart to show spikes for different dates(ex for 7 days).But now it shows same va...
by umsundar2015 Path Finder in Splunk Search 10-26-2016
0 5
0
5
bakalon
Hey Guys, I have the following output: Server: abc-ij-qwerty88.asdf.xyz.com Address: 10.10.254.97 DNS request timed...
by bakalon Explorer in Splunk Search 10-26-2016
0 9
0
9
sarnagar
Hi All, I have JSON Logs like below: SAMPLE EVENT: { [-] line: 2016-10-21 19:16:00 INFO [CollectorAccess] Updat...
by sarnagar Contributor in Splunk Search 10-26-2016
0 3
0
3
umsundar2015
For me the below stats sum(count) by Asset_status provies no results . eval Asset_status= if(Asset_Class=Server OR A...
by umsundar2015 Path Finder in Splunk Search 10-26-2016
0 3
0
3
OMohi
I would like to remove real time searches from the Home Page and Search Panel on Splunk UI. I came across someone's o...
by OMohi Path Finder in Splunk Search 10-26-2016
1 3
1
3
carmackd
Is it possible to configure an automatic lookup to use a multivalued OUTPUT field? I should add that the lookups mat...
by carmackd Communicator in Splunk Search 10-26-2016
2 7
2
7
fedyshynyuriy
0
3
Justin1224
Is sparkline adding any new information to the results of this search, or is it just presenting the same information ...
by Justin1224 Communicator in Splunk Search 10-25-2016
0 3
0
3
willamwar
Dataset 10.24.11.102 - user1 [10/Sep/2016:02:46:12 -0400] "GET http://www.foo.org:80/lib/stone/csrf/token.json HTTP/...
by willamwar Path Finder in Splunk Search 10-25-2016
0 1
0
1
szimmer661
I am taking numerous log entries and trying to produce an output report that shows the earliest logon time and the la...
by szimmer661 Explorer in Splunk Search 10-25-2016
0 6
0
6
kent_farries
I need some help with this one since it is beyond my regex skills which are not the best. I would have used the fiel...
by kent_farries Path Finder in Splunk Search 10-25-2016
0 6
0
6
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...