Splunk Search

Splunk Search
Community Activity
ponsakthi
The intermediate result of a query is Machine | ErrorType |ErrorCount A | ErrorA | 4 A ...
by ponsakthi Engager in Splunk Search 10-17-2016
0 1
0
1
rajgowd1
i am trying to search some strings like Error OR WARNING and IPADDRESS or HOSTNAME from /var/log/messages file and d...
by rajgowd1 Communicator in Splunk Search 10-17-2016
0 6
0
6
smhsplunk
So I am generating an alert everyday at 2am, the alert is basically a table with several fields, now I would like the...
by smhsplunk Communicator in Splunk Search 10-17-2016
0 6
0
6
Justin1224
What is being counted in this query? Here it is: | `tstats` count from datamodel=Authentication by _time span=10m | ...
by Justin1224 Communicator in Splunk Search 10-17-2016
0 5
0
5
snoobzilla
Is it possible to include a custom search command in your app as a calculated field? One that would automatically app...
by snoobzilla Builder in Splunk Search 10-17-2016
1 3
1
3
tkwaller
Trying to find a way to put the results of this search into a chart. I know the issue is that there are 2 fields Im t...
by tkwaller Builder in Splunk Search 10-17-2016
0 12
0
12
jmaple
I'm trying to create a simple report that shows the number of unique users logged into our Cisco ASA over the course ...
by jmaple Communicator in Splunk Search 10-17-2016
0 3
0
3
jurbain
Hi I need to extract multivalue field from an event structured in xml. <job> <nameJob>Job1</nameJob> <execut...
by jurbain New Member in Splunk Search 10-17-2016
0 4
0
4
tkwaller
I know this is fairly simple question. I am trying to do a couple evals on userAgent fields, as I am trying not to us...
by tkwaller Builder in Splunk Search 10-17-2016
0 5
0
5
Paul1896
Hello, I hope anyone can help me. My search eval epochtime=strptime(DATUM,"%d.%m.%Y") | eval datefield=strftime(ep...
by Paul1896 Path Finder in Splunk Search 10-17-2016
0 16
0
16
gcusello
Hi at all, I would extract a field as a part of source field and I know how to do this using rex command | rex field...
by SplunkTrust SplunkTrust in Splunk Search 10-17-2016
0 4
0
4
egreibl
Hi guys, hope you can help me. I want to have a statistic of my users. The most of the users access the search&repo...
by egreibl Engager in Splunk Search 10-17-2016
0 4
0
4
sumituv
Hi, I am configuring Field Extractor to extract fields from a single files directly from events>action>extract field...
by sumituv New Member in Splunk Search 10-16-2016
0 2
0
2
dbcase
Hi, I'm trying to pull the user ID from the below data? The userids are: mspeer2, ddaniel, mirella, jcrews I have...
by dbcase Motivator in Splunk Search 10-16-2016
0 7
0
7
brywilk_umich
Hello, I have the following search index=collaboration sourcetype="mail-2" Auth | geoip simta_client_ip | dedup simt...
by brywilk_umich Path Finder in Splunk Search 10-16-2016
0 2
0
2
mbintz
If I have a search that returns a table with multi-values in two different columns, how can I find the unique element...
by mbintz Explorer in Splunk Search 10-15-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the following subqueries: The first extracts ...
by IRHM73 Motivator in Splunk Search 10-15-2016
0 9
0
9
VidhyaR
We have different indexes with varied retention and volumes. We would like to be able to restrict some roles to searc...
by VidhyaR New Member in Splunk Search 10-14-2016
0 3
0
3
rajgowd1
How to display values in xyseries format? i have log like below tcp 0 0 12b8-splfwd02.nam.nsro:7171 poc-...
by rajgowd1 Communicator in Splunk Search 10-14-2016
0 15
0
15
rajgowd1
HI Experts, i am able to exact 4th and 5th fields from below log but i am able to exact get the value if the 4th or 5...
by rajgowd1 Communicator in Splunk Search 10-14-2016
0 8
0
8
landen99
Searching for events which match any of multiple values for the same field times several fields in a lookup using the...
by landen99 Motivator in Splunk Search 10-14-2016
0 1
0
1
viggor
I woudl like to know, per CountryId, what fraction of FooId equal to BarId In the follwoing log: MyEvent CountryId=...
by viggor Path Finder in Splunk Search 10-14-2016
0 1
0
1
larryleeroberts
I am trying to pull data from Splunk via a search and send it to Netcool OMNIbus. Right now I am just sending it via ...
by larryleeroberts Path Finder in Splunk Search 10-14-2016
0 7
0
7
justx001
I am having alot of trouble setting up rolling averages in Splunk. I would love to be able to overlay a 30, 60, 90 da...
by justx001 Explorer in Splunk Search 10-14-2016
1 4
1
4
DEAD_BEEF
I have some Windows event log data that shows the ID when a user logs in and logs out. In addition, it shows me the ...
by DEAD_BEEF Builder in Splunk Search 10-14-2016
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...