Splunk Search

Splunk Search
Community Activity
splunker9999
Hi, I have this search below, which produces results, but need to format these in a report. index=imdc_w sourcetyp...
by splunker9999 Path Finder in Splunk Search 09-01-2016
0 4
0
4
HCadmins
Hi Splunk Answers! I'm new to Splunk. I am trying to create a statistics table that shows our VPN users, their faile...
by HCadmins Communicator in Splunk Search 09-01-2016
0 9
0
9
jdanij
Hi, I'm trying to reuse an old app for a new environment and, of course, data and fields similar but different, so a...
by jdanij Path Finder in Splunk Search 09-01-2016
0 11
0
11
Cuyose
I cannot find a working example of this anywhere. I can find examples a mile long on google, but am having trouble a...
by Cuyose Builder in Splunk Search 09-01-2016
0 4
0
4
trevorQmulos
I have a CSV that has the setup as shown below. Date |Score 1/1/2016 | 4.3 2/1/2016 | 5.7 I need to extract t...
by trevorQmulos New Member in Splunk Search 09-01-2016
0 2
0
2
mwdbhyat
Hi, Is it possible to use a backfill script without the need of pointing to an app name? EG - ./splunk cmd python f...
by mwdbhyat Builder in Splunk Search 09-01-2016
0 1
0
1
Meena_0627
In extreme search, i would like to know what this statement means and how it is derived by Splunk "xwhere count from...
by Meena_0627 New Member in Splunk Search 09-01-2016
0 1
0
1
phudinhha
Dear Team, I am trying to build a chart like this: - x-axis is the website name - y-axis is the number of request...
by phudinhha Explorer in Splunk Search 09-01-2016
0 3
0
3
nivethainspire_
I have tried the below query,it works fine,but its complicated, Can anyone suggest a better way to write the same que...
by nivethainspire_ Explorer in Splunk Search 09-01-2016
0 1
0
1
mabdelfattah
Hello, I'm getting "No results found." whenever I search for any term in splunk. I have 29,123,099 Events INDEXED a...
by mabdelfattah New Member in Splunk Search 09-01-2016
0 18
0
18
arrowecssupport
So when I get an error with the message "(Failed)" i want the line to be added to an extracted field as a value. 9:0...
by arrowecssupport Communicator in Splunk Search 09-01-2016
0 21
0
21
evelenke
Hi, Splunkers! I have log where some different events (event A, event B, event C...) are expected to be generated pe...
by evelenke Contributor in Splunk Search 09-01-2016
0 2
0
2
ahogbin
I am attempting to remove duplicate occurrences from a results table. What I have ID 1 NewBusiness $123 ID 1 NewBusi...
by ahogbin Communicator in Splunk Search 08-31-2016
0 4
0
4
ariyazudeen
Say I have a column with 5 records in it 88 22 67 44 55 I want to compare the last record 55 with that of second las...
by ariyazudeen New Member in Splunk Search 08-31-2016
0 4
0
4
pavanae
The following were some of the events html tags 2016-04-21 09:42:38,574 DEBUG lksjfd laskdfj lskfj alsdkfj htmlta...
by pavanae Builder in Splunk Search 08-31-2016
0 10
0
10
scottrunyon
When I run a simple query "index=syslog update sourcetype=fgt_event devname=xxxxx", it returns duplicate (2) events...
by scottrunyon Contributor in Splunk Search 08-31-2016
0 5
0
5
lycollicott
The macro consists of this code: index=_internal source=*license_usage.log type="Usage" | eval h=if(len(h)=0 OR isnu...
by lycollicott Motivator in Splunk Search 08-31-2016
0 1
0
1
lpolo
I would like to extract the key=value pairs found in a multivalue field, but without doing mvexpand mvfield. Note: t...
by lpolo Motivator in Splunk Search 08-31-2016
0 3
0
3
jmaple
I'm trying to create a report that details our VPN usage over the course of a month. I've got the base of the report ...
by jmaple Communicator in Splunk Search 08-31-2016
0 1
0
1
Kukkadapu
Hi, I need some help to transform the below event? Thanks for your time. 2016-08-30 13:13:48,525 log_level='INFO' ab...
by Kukkadapu Path Finder in Splunk Search 08-31-2016
0 4
0
4
trevorQmulos
I have the current search right now but am getting inaccurate numbers due to an issue with my search. I would like to...
by trevorQmulos New Member in Splunk Search 08-31-2016
0 6
0
6
pavanae
I got a strange situation here. I have two different searches as follows. search 1: index=* [ search index=_interna...
by pavanae Builder in Splunk Search 08-31-2016
0 3
0
3
ashishlal82
How can I use timestamps from 2 different sources and calucate them inorder to find the difference and convert in nu...
by ashishlal82 Explorer in Splunk Search 08-31-2016
0 15
0
15
ebailey
We are using a search head cluster and we are having an issue with the following workflow. A user has lookup table th...
by ebailey Communicator in Splunk Search 08-31-2016
1 2
1
2
plucas_splunk
Given a search: index="muni" | nbclosest | timechart span=30m dc(vehicle_id) as NumVehicles (where nbclosest is a ...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-31-2016
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...