Splunk Search

Splunk Search
Community Activity
TMazurek
Hello, I have dashboard with drop-down button. Token for button is named Area. Values are: Name - Value: All Areas ...
by TMazurek New Member in Splunk Search 10-18-2016
0 1
0
1
lakromani
I have data in this format: client=green value=house client=yellow value=appartement client=black value=bungalow cl...
by lakromani Builder in Splunk Search 10-18-2016
0 12
0
12
rajgowd1
I am trying to search /var/log/messages log with keywords like shutdown or Error and storing it in message.log and d...
by rajgowd1 Communicator in Splunk Search 10-18-2016
0 4
0
4
splunkrocks2014
How to get all possible entries from two lookups? For instance, lookup_1 and lookup_2 lookup_1 application ...
by splunkrocks2014 Communicator in Splunk Search 10-17-2016
1 3
1
3
jph11
Been working on a report to show the best data on authentications failed more than ten times in a time span of 10 min...
by jph11 New Member in Splunk Search 10-17-2016
0 3
0
3
anoopambli
I am extracting a field using regular expression, it looks like below, These are top 5 processes which is consuming h...
by anoopambli Communicator in Splunk Search 10-17-2016
0 6
0
6
neiowe
I am looking to take the results of the following search: sourcetype="cisco:asa" AND dest_ip=10.3.10.12 AND dest_po...
by neiowe Path Finder in Splunk Search 10-17-2016
0 5
0
5
theactiveactor
The slices on my pie chart are currently displaying the numerical value of an enum, which isn't too useful. Instead o...
by theactiveactor New Member in Splunk Search 10-17-2016
0 3
0
3
hanijamal
I lose my field extractions when I add a search parameter to my search: THIS WORKS: (I see fields on the left hand s...
by hanijamal New Member in Splunk Search 10-17-2016
0 4
0
4
circleup
How do I add a new field extraction using the field transformations I've configured? We're using Splunk Light Cloud....
by circleup Explorer in Splunk Search 10-17-2016
0 5
0
5
viggor
When I use | stats max(foo) I get the largest value of foo. Is it possible to get the whole line of the log which co...
by viggor Path Finder in Splunk Search 10-17-2016
0 1
0
1
shahzadarif
Hi, I need to figure out what fields our Splunk users are searching for, either in their reports or dashboards. Is ...
by shahzadarif Path Finder in Splunk Search 10-17-2016
0 7
0
7
srikanth1213
Hi Team, How do I write a search to alert me when one of the critical indexers is not receiving the data from the s...
by srikanth1213 Path Finder in Splunk Search 10-17-2016
1 5
1
5
splgeek
Hello Splunkers Can anyone explain in simple terms what is a Splunk Base Search?
by splgeek Explorer in Splunk Search 10-17-2016
0 4
0
4
ponsakthi
The intermediate result of a query is Machine | ErrorType |ErrorCount A | ErrorA | 4 A ...
by ponsakthi Engager in Splunk Search 10-17-2016
0 1
0
1
rajgowd1
i am trying to search some strings like Error OR WARNING and IPADDRESS or HOSTNAME from /var/log/messages file and d...
by rajgowd1 Communicator in Splunk Search 10-17-2016
0 6
0
6
smhsplunk
So I am generating an alert everyday at 2am, the alert is basically a table with several fields, now I would like the...
by smhsplunk Communicator in Splunk Search 10-17-2016
0 6
0
6
Justin1224
What is being counted in this query? Here it is: | `tstats` count from datamodel=Authentication by _time span=10m | ...
by Justin1224 Communicator in Splunk Search 10-17-2016
0 5
0
5
snoobzilla
Is it possible to include a custom search command in your app as a calculated field? One that would automatically app...
by snoobzilla Builder in Splunk Search 10-17-2016
1 3
1
3
tkwaller
Trying to find a way to put the results of this search into a chart. I know the issue is that there are 2 fields Im t...
by tkwaller Builder in Splunk Search 10-17-2016
0 12
0
12
jmaple
I'm trying to create a simple report that shows the number of unique users logged into our Cisco ASA over the course ...
by jmaple Communicator in Splunk Search 10-17-2016
0 3
0
3
jurbain
Hi I need to extract multivalue field from an event structured in xml. <job> <nameJob>Job1</nameJob> <execut...
by jurbain New Member in Splunk Search 10-17-2016
0 4
0
4
tkwaller
I know this is fairly simple question. I am trying to do a couple evals on userAgent fields, as I am trying not to us...
by tkwaller Builder in Splunk Search 10-17-2016
0 5
0
5
Paul1896
Hello, I hope anyone can help me. My search eval epochtime=strptime(DATUM,"%d.%m.%Y") | eval datefield=strftime(ep...
by Paul1896 Path Finder in Splunk Search 10-17-2016
0 16
0
16
gcusello
Hi at all, I would extract a field as a part of source field and I know how to do this using rex command | rex field...
by SplunkTrust SplunkTrust in Splunk Search 10-17-2016
0 4
0
4
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors