Splunk Search

Splunk Search
Community Activity
virgilg
I have log lines of the form (relevant excerpt only, they contain also hostname, timestamp, etc): data_name: A B C D...
by virgilg Explorer in Splunk Search 09-30-2016
0 1
0
1
chrisboy68
Hi, can't seem to get what I'm looking for working. Here is what I want to do. Issue a main search of events. Find e...
by chrisboy68 Contributor in Splunk Search 09-30-2016
1 5
1
5
keerthana_k
I have created a csv file mapping a field from my raw index to a more readable version. Some of the values for that f...
by keerthana_k Communicator in Splunk Search 09-30-2016
1 2
1
2
kiran331
How can I change the format of the filed values using regex. what it is now: 0xBCDDADAF7BSS What I need: remove 0x ...
by kiran331 Builder in Splunk Search 09-30-2016
0 3
0
3
Upas02
I am using Splunk 6.4. I am able to extract many fields from my data using erex comand. However, for URL fields, the...
by Upas02 Path Finder in Splunk Search 09-30-2016
0 1
0
1
surekhasplunk
Hi , I want a chart exactly like the image attached. My data is input lookup csv file . My time filed name is "Ope...
by surekhasplunk Communicator in Splunk Search 09-30-2016
1 4
1
4
surekhasplunk
Am using query "index=level3 host=Test | stats count by Age | sort Age" and visualizing it in a pie chart. Now my r...
by surekhasplunk Communicator in Splunk Search 09-30-2016
0 1
0
1
DonaldvdHoogenb
Hi fellow splunkers, I have multiple search heads on which I want to increase the maximum number of (historical and)...
by DonaldvdHoogenb Path Finder in Splunk Search 09-30-2016
0 2
0
2
chvnc
I have one field with values xyz_onprem abc_onprem gghf_onprem abc_aws gfd_aws I want to see the count of values end...
by chvnc Explorer in Splunk Search 09-30-2016
0 2
0
2
simona2121
Hi .. I need to extract back123 from the source field. pls provide the entire rex command needed to fetch back123 to ...
by simona2121 Path Finder in Splunk Search 09-29-2016
0 7
0
7
tsunamii
Looking to how to enable the message block starting with "The following messages were returned by the search subsyste...
by tsunamii Path Finder in Splunk Search 09-29-2016
3 4
3
4
balleste
I have the following log format and I'm trying to create a table that will have the following format: "Device","Obje...
by balleste Engager in Splunk Search 09-29-2016
0 2
0
2
patelpin
Hello. I have a few servers: a,b,c and 1,2,3 Servers a,b,c work with this - base search | rex field=cs_uri_stem "...
by patelpin New Member in Splunk Search 09-29-2016
0 6
0
6
JoshuaJohn
I have this query index=nitro_prod earliest=-30d ESK** (job_class=* OR NOT job_class=*) compl_code=* | fields app_...
by JoshuaJohn Contributor in Splunk Search 09-29-2016
0 1
0
1
alandeandrea
I'm looking to enrich a search of firewall IP data with DNS host data from proxy logs. To be clear, I don't want to d...
by alandeandrea Explorer in Splunk Search 09-29-2016
0 4
0
4
zhatsispgx
When i run the following query, my legend has the values as values(fieldname): index=main source=daily_report sourc...
by zhatsispgx Path Finder in Splunk Search 09-29-2016
0 3
0
3
bensonqiu
If I make a POST request to "services/search/jobs", it will return a job-id. Let's say the job is taking too long, an...
by bensonqiu Engager in Splunk Search 09-29-2016
0 1
0
1
rob9mcneil9
Hi All, I'm new to Splunk and new to get a count of the daily active users in the last 3 days. Users in our system a...
by rob9mcneil9 Engager in Splunk Search 09-29-2016
0 2
0
2
terryloar
Has anyone run into this message? "Search generated too much data for the current display configuration, results hav...
by terryloar Path Finder in Splunk Search 09-29-2016
2 4
2
4
jdschmitz
Trying to take a multi-value field using that to lookup values then placing the return information into the correct f...
by jdschmitz New Member in Splunk Search 09-29-2016
0 1
0
1
lbogle
Hello Splunkers, These results may be truncated. This visualization is configured to display a maximum of 1000 resul...
by lbogle Contributor in Splunk Search 09-29-2016
4 10
4
10
avisram
I am attempting to generate an area chart for the past 15 days using the following search: index=test sourcetype=abc...
by avisram Path Finder in Splunk Search 09-29-2016
3 3
3
3
my2ndhead
It seems that the undocumented TERM() operator can give quite a performance boost to searches. E.g. I ran a search o...
by SplunkTrust SplunkTrust in Splunk Search 09-29-2016
5 5
5
5
surekhasplunk
Am using this search index=level3 host=Test | chart count over "Opened" by "Assignment group" I am getting the de...
by surekhasplunk Communicator in Splunk Search 09-29-2016
0 2
0
2
kiran331
Hello, I have to get the individual count of three lookups A,B,C. How can I show the count of each lookup n Dashboar...
by kiran331 Builder in Splunk Search 09-29-2016
1 1
1
1
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Solution Authors