Splunk Search

Splunk Search
Community Activity
evanleair
Hello Splunk Masters, I'm working on a radial gauge that will show successful IIS requests. I need to be able to bui...
by evanleair Explorer in Splunk Search 09-20-2016
1 1
1
1
ankithreddy777
I don't see the real time option in the time range picker. I do have queries to search in real time.
by ankithreddy777 Contributor in Splunk Search 09-20-2016
0 4
0
4
ECovell
I am attempting to create a search that would pull information about search usage. I have an index generated off of t...
by ECovell Path Finder in Splunk Search 09-20-2016
0 6
0
6
DaClyde
I'm extracting a piece of a filename to create a field using makemv and a rex command. The extracted field should be...
by DaClyde Contributor in Splunk Search 09-20-2016
0 4
0
4
rajksplunk
please let me know via CLI or Splunkweb.?
by rajksplunk New Member in Splunk Search 09-20-2016
0 4
0
4
justx001
I have a search from web logs that I need to calculate a percentage based on a custom range. Search example: index...
by justx001 Explorer in Splunk Search 09-20-2016
0 3
0
3
dfexsplunk
It's a query for a staked column chart. index=myCompIn source="/locatedin/mySrc.log" "Reply Back" "CAT-IN " "SOME ST...
by dfexsplunk New Member in Splunk Search 09-20-2016
0 9
0
9
Justin1224
I have this search string, and I'm unsure of what some of it does. This is the search: | inputlookup append=T malwar...
by Justin1224 Communicator in Splunk Search 09-20-2016
0 6
0
6
a212830
Hi, Is there a way to limit how long a real-time search can run? I have customers firing them up (legitimately) and...
by a212830 Champion in Splunk Search 09-20-2016
0 4
0
4
ivarny
We have users with somewhat limited capabilities using custom search home apps. They are able to search the data they...
by ivarny Path Finder in Splunk Search 09-20-2016
0 5
0
5
rb51
hi all, I am working on a PCI environment and need to get audit logs from Linux RHEL machines into Splunk. LAN Segm...
by rb51 Explorer in Splunk Search 09-20-2016
0 2
0
2
twtyj
I have events containing field "Agent_Local_Time="9/19/2016 1:36:19 PM", I use EVAL to format the time "eval final_ti...
by twtyj New Member in Splunk Search 09-19-2016
0 2
0
2
rmuraly
index="test" [search index="test_summary" key_field="y" | head 1 | eval search = "_time>" . _time | fields search] |...
by rmuraly Explorer in Splunk Search 09-19-2016
0 2
0
2
namritha
Hi, I used splunk to extract a new field and it has used this regular expression, rex "^(?:[^\|\n]*\|){6}(?P<error...
by namritha Path Finder in Splunk Search 09-19-2016
0 6
0
6
brian1_tate
I have a general question and I am more of a power user than admin level here (but I'm in the process of becoming one...
by brian1_tate Path Finder in Splunk Search 09-19-2016
0 2
0
2
a212830
Hi, I am querying an accelerated data model for active directory, using the search below. However, the results are ...
by a212830 Champion in Splunk Search 09-19-2016
0 3
0
3
lbogle
Hello Splunkers, I've got a search built thats working properly but I'm not able to get the events with a particular ...
by lbogle Contributor in Splunk Search 09-19-2016
10 8
10
8
andreacorrie
How do I search multiple source files within my search? I want to do something like: source="/foo/bar/2016/09/{08,15...
by andreacorrie Explorer in Splunk Search 09-19-2016
0 8
0
8
pgort
I have a dashboard panel that shows the sum of outbound data where I want to click on a value and display the raw eve...
by pgort New Member in Splunk Search 09-19-2016
0 3
0
3
dmbreton
I am trying to figure out how to extract structured data from an HL7 2.x message The entire message is wrapped in a...
by dmbreton New Member in Splunk Search 09-19-2016
0 3
0
3
dbcase
Hi, I have a query that looks like this <chart depends="$tableurlerror$"> <title>URL Errors by Host Detail...
by dbcase Motivator in Splunk Search 09-19-2016
0 12
0
12
ozirus
Hi, I've a periodic anomaly detection search (alert) query that results like this in inline mail result table; AVER...
by ozirus Path Finder in Splunk Search 09-19-2016
0 3
0
3
dbcase
Hi, I have this search index=main | rex "(?i)\".*? /(?P<URL_HEADER>\w+/\w+)"| rex "(?i) UCT\-(?P<URL_MICRO_SECONDS>...
by dbcase Motivator in Splunk Search 09-19-2016
0 2
0
2
JoshuaJohn
I want to create a single value panel that starts at 100, and when a specific alert goes off with an assigned weight,...
by JoshuaJohn Contributor in Splunk Search 09-19-2016
0 15
0
15
JBNB007
I am writing a custom sql dbxquery. When this custom query executes I want to know when it gets started and when its ...
by JBNB007 New Member in Splunk Search 09-19-2016
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...