Splunk Search

Splunk Search
Community Activity
sarit_s
HelloI'm trying to calculate ratio of two fields but im getting wrong resultsif i'm calculating each one of them sepa...
by sarit_s Communicator in Splunk Search 10-05-2023
0 8
0
8
Muditks
This splunk search is not showing any result. index=os OR index=linux sourcetype=vmstat OR source=iostat [| input loo...
by Muditks Observer in Splunk Search 10-05-2023
0 1
0
1
yohhpark
system_id = AA-1, AA-1-a, AA-1-b, AA-10, AA-10-a, AA-10-b, AA-12, AA-12-a, AA-12-b,,, and so on. Notice all the syste...
by yohhpark Path Finder in Splunk Search 10-05-2023
0 1
0
1
jamesvz84
I am trying to determine how many searches are searching on a particular index per day. I know how much data the ind...
by jamesvz84 Communicator in Splunk Search 10-05-2023
1 8
1
8
finchy
Hi, What's the best way to only do a Lookup based on the results of the main search?  I want to only run this when 2 ...
by finchy Explorer in Splunk Search 10-04-2023
0 5
0
5
TaraAshley
Hello, I was wondering if it is possible to locate or search in Splunk if a specific lookup table is being used in a ...
by TaraAshley Engager in Splunk Search 10-04-2023
0 2
0
2
runiyal
Have following data in the logfile    {xxxx},{"GUID":"5561859B8D624FFC8FF0B87219060DC5"} {xxxx},{"GUID":"5561859B8D62...
by runiyal Path Finder in Splunk Search 10-04-2023
0 5
0
5
NanSplk01
I have found a search in the charge back application that might fit for seeing the SVC's by index.  Unfortunately tha...
by NanSplk01 Communicator in Splunk Search 10-04-2023
0 2
0
2
faustf
Hi,we are logging api requests in Splunk. I would like to create a sort of health check table where every column repr...
by faustf Communicator in Splunk Search 10-04-2023
0 3
0
3
Tester237
Hi, I'm trying to plot graph for previous 2 weekday average. Below is the query usedindex="xyz" sourcetype="abc" app...
by Tester237 Explorer in Splunk Search 10-04-2023
0 2
0
2
P3G4SUS
Lets say I have a table of two fields. and some of the cells are empty.How do I find the number of empty cells using ...
by P3G4SUS New Member in Splunk Search 10-04-2023
0 2
0
2
alexeysharkov
Hello friends!I get JSON like this{"key":"27.09.2023","value_sum":35476232.82,"value_cnt":2338}and so on...{ [-]   ke...
by alexeysharkov Path Finder in Splunk Search 10-04-2023
0 4
0
4
shreyasbsharma
Hi Team, I have a got a request to plot graph of previous 30 days. But the org has a retention period of 7days set on...
by shreyasbsharma Engager in Splunk Search 10-04-2023
0 7
0
7
sarit_s
HelloIm trying to run a chart command grouped by 2 fields but im getting an error:this is my query :   | chart value...
by sarit_s Communicator in Splunk Search 10-03-2023
0 8
0
8
FGAnders
Hi,Is it somehow possible to find difference between two or more amounts from different events when the events are so...
by FGAnders Explorer in Splunk Search 10-03-2023
0 3
0
3
Sekhar
Log like.message: [22/09/23 10:31:47:935 GMT] [ThreadPoolExecutor-thread-15759] INFO failed.", suspenseAccountNumber=...
by Sekhar Explorer in Splunk Search 10-03-2023
0 5
0
5
yohhpark
system_id = AA-1, AA-1-a, AA-1-b, AA-10, AA-10-a, AA-10-b, AA-12, AA-12-a, AA-12-b,,, and so on. Notice all the syste...
by yohhpark Path Finder in Splunk Search 10-03-2023
0 2
0
2
Akmal57
Hi, i have lookup which list out all red hat linux. for example, in my lookup have red hat 7, red hat 8 and so on.i n...
by Akmal57 Path Finder in Splunk Search 10-03-2023
0 5
0
5
jwhughes58
I'm working with these events Oct 3 17:11:23 hostname Tetration Alert[1485]: [ERR] {"keyId":"keyId","eventTime":"169...
by jwhughes58 Contributor in Splunk Search 10-03-2023
0 4
0
4
scout29
Looking to create a search / report showing the ingest by source ingestion method in the last 24hours. I am looking f...
by scout29 Path Finder in Splunk Search 10-03-2023
0 2
0
2
yohhpark
trying to set a token where system_id shows ABC1, ABC1-a, ABC10, ABC10-a and so on. when I set the token for that sys...
by yohhpark Path Finder in Splunk Search 10-03-2023
0 2
0
2
El_Franco
Hopefully this will set the issue out clearly. I have two sources, Transaction and Request.The Transaction holds the ...
by El_Franco Explorer in Splunk Search 10-03-2023
0 1
0
1
Geep
Is it possible to modify the value of a token obtained from a dashboard input prior to it being used in a panel? In t...
by Geep Engager in Splunk Search 10-03-2023
0 2
0
2
TheMorf
I am trying to extract the difference of time(duration) of 2 events in days. I have 2 saperate event for the same ID....
by TheMorf New Member in Splunk Search 10-03-2023
0 1
0
1
JohnEGones
Hi Fellow Splunkers,Have a hopefully quick question:Want to pull out the source and host from the Windows _internal s...
by JohnEGones Communicator in Splunk Search 10-03-2023
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...