Splunk Search

Splunk Search
Community Activity
j_partsch
I apologize if this has already been answered, but I looked through numerous inquiries on answers.splunk.com and did ...
by j_partsch Explorer in Splunk Search 09-12-2016
0 8
0
8
ALevin123
I have the following search to find the number of switches "Off" on a day (call it day=0), and then use a field looku...
by ALevin123 New Member in Splunk Search 09-12-2016
0 10
0
10
jambalaya_rice
I was doing basic operations (+ - * / ) in Splunk and I noticed that if I was subtracting a number less than 0 with a...
by jambalaya_rice Engager in Splunk Search 09-12-2016
0 1
0
1
splunker9999
Hi , We need to set up an alert to check if events with below format exists: index=idx1 sourcetype=compass:services...
by splunker9999 Path Finder in Splunk Search 09-12-2016
0 5
0
5
namritha
Hi, I am trying to extract a field from a log event, but need help as my RegEx seems to be wrong. Input string: 201...
by namritha Path Finder in Splunk Search 09-12-2016
0 3
0
3
vkakani60
My query works from Splunk Web UI and returns field values of Source in a table form, but it doesn't work from the CL...
by vkakani60 Path Finder in Splunk Search 09-12-2016
0 10
0
10
Justin1224
I was just wondering if the commas in this search are just to aid readability of the code, or if they are important t...
by Justin1224 Communicator in Splunk Search 09-12-2016
1 5
1
5
Justin1224
Could someone please tell me what this does? I'm in the process of learning Splunk and knowing what each part of this...
by Justin1224 Communicator in Splunk Search 09-12-2016
0 24
0
24
a212830
Hi, Is it possible to create a lookup, and then validate that data has been received from each host in the lookup by...
by a212830 Champion in Splunk Search 09-12-2016
0 5
0
5
dbcase
Hi, I have data that looks like this: REBOOT_REASON,EVENT_SUB_TYPE uc-keypad,etherLoss uc-keypad,etherLossRes uc-ke...
by dbcase Motivator in Splunk Search 09-12-2016
0 7
0
7
jayadevanepSPL
I have a XML embedded in another XML with escape characters <Audit> <tracker>XXXXX123</tracker> <Message>&lt?xml ve...
by jayadevanepSPL New Member in Splunk Search 09-12-2016
0 6
0
6
tcmarquesi
I'm trying to evaluate the normal distribuiton's PDF into my search as follows: ... | eval prob=(1/sqrt(2*pi()*sigma...
by tcmarquesi Explorer in Splunk Search 09-12-2016
0 2
0
2
JoshuaJohn
I am trying to grab this response time **** info[[Path::/rest/motService][corRID::NAID-iOS-DFA65777-2339-4A0802F42C6...
by JoshuaJohn Contributor in Splunk Search 09-12-2016
0 2
0
2
alice_waynecorp
I've recently had some Ransomware that I think came off of a users USB drive. I am worried he might have shared it w...
by alice_waynecorp New Member in Splunk Search 09-12-2016
0 1
0
1
ulrich_track
I have created a search to produce a stacked bar chart: (each shop sells the same items but in different quantities) ...
by ulrich_track Path Finder in Splunk Search 09-12-2016
1 7
1
7
bld7262
Perhaps similar to: https://answers.splunk.com/answers/206372/enumerating-empty-searchresultstream-causes-invali-1.h...
by bld7262 New Member in Splunk Search 09-11-2016
0 2
0
2
Gayathirik
Hi I need to write a query for creating an alert whenever there is message in the "Splunk bar" message tab. Please ...
by Gayathirik Path Finder in Splunk Search 09-11-2016
0 6
0
6
sidhantbhayana
Hi All, I have a scenario where an entity when enrolled has many status i.e. EntityName Date Status...
by sidhantbhayana Path Finder in Splunk Search 09-11-2016
0 6
0
6
vkakani60
I want to run Splunk query from the cmd prompt. It works just fine with basic error search, but when I tried with ...
by vkakani60 Path Finder in Splunk Search 09-10-2016
1 5
1
5
rafasalo
Hi, I'm trying to execute this query: index=index_cbo [search index=index_cbo 12018955000155 "An error ocurred dur...
by rafasalo Engager in Splunk Search 09-09-2016
0 12
0
12
iamsgsn
Hi Team, I have fields like txn_id and txn_chain_id where txn_chain_id can have more than 1 txn_id like: Log 1: ......
by iamsgsn New Member in Splunk Search 09-09-2016
0 3
0
3
pdpsplunk100
Hi - I'm having trouble in combining 2 separate searches and displaying the results on a single visualization (timech...
by pdpsplunk100 Path Finder in Splunk Search 09-09-2016
0 5
0
5
dbcase
Hi, I have data that looks like this: "-" 10.30.28.1 "10.30.28.1" - - [09/Sep/2016:16:58:31 -0500] "GET /ICHealthCh...
by dbcase Motivator in Splunk Search 09-09-2016
0 2
0
2
tinylund
Thanks in advance for any assistance.. I am trying to create an alert that creates a table that shows sourceIP, coun...
by tinylund Explorer in Splunk Search 09-09-2016
0 12
0
12
pm771
We have a listing of travelers. Every event has the following two fields: USER and LOCATION. I need a search that w...
by pm771 Communicator in Splunk Search 09-09-2016
0 2
0
2
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...