Splunk Search

Splunk Search
Community Activity
sidhantbhayana
Hi All, I have a scenario where an entity when enrolled has many status i.e. EntityName Date Status...
by sidhantbhayana Path Finder in Splunk Search 09-11-2016
0 6
0
6
vkakani60
I want to run Splunk query from the cmd prompt. It works just fine with basic error search, but when I tried with ...
by vkakani60 Path Finder in Splunk Search 09-10-2016
1 5
1
5
rafasalo
Hi, I'm trying to execute this query: index=index_cbo [search index=index_cbo 12018955000155 "An error ocurred dur...
by rafasalo Engager in Splunk Search 09-09-2016
0 12
0
12
iamsgsn
Hi Team, I have fields like txn_id and txn_chain_id where txn_chain_id can have more than 1 txn_id like: Log 1: ......
by iamsgsn New Member in Splunk Search 09-09-2016
0 3
0
3
pdpsplunk100
Hi - I'm having trouble in combining 2 separate searches and displaying the results on a single visualization (timech...
by pdpsplunk100 Path Finder in Splunk Search 09-09-2016
0 5
0
5
dbcase
Hi, I have data that looks like this: "-" 10.30.28.1 "10.30.28.1" - - [09/Sep/2016:16:58:31 -0500] "GET /ICHealthCh...
by dbcase Motivator in Splunk Search 09-09-2016
0 2
0
2
tinylund
Thanks in advance for any assistance.. I am trying to create an alert that creates a table that shows sourceIP, coun...
by tinylund Explorer in Splunk Search 09-09-2016
0 12
0
12
pm771
We have a listing of travelers. Every event has the following two fields: USER and LOCATION. I need a search that w...
by pm771 Communicator in Splunk Search 09-09-2016
0 2
0
2
uhkc777
Hi, Please see the image below. I want to get shipcond=NEXTDAY in the first column also. How can I get that? Here, S...
by uhkc777 Explorer in Splunk Search 09-09-2016
0 5
0
5
sfatnass
when i try to run a stats count using postprocess splunk doesn't resolve the query search and i don't know why ? th...
by sfatnass Contributor in Splunk Search 09-09-2016
0 5
0
5
dbcase
Hi, I have this query index=top10_1 source="*Account_Log*" OR source="*Arm_Disarm_Events*" OR source="*CPE_Commands...
by dbcase Motivator in Splunk Search 09-09-2016
0 2
0
2
michael_sleep
I've been racking my brain over multi-searches, subsearches, and a few other methods I harvested from Google and Splu...
by michael_sleep Communicator in Splunk Search 09-09-2016
0 1
0
1
josf999
I want a search that will list saved searches that are (historically) consuming high CPU, memory, and take a long tim...
by josf999 New Member in Splunk Search 09-09-2016
0 4
0
4
joydeep741
I have a forwarder and an indexer. I see the app is deployed in the forwarder at location etc/apps/. Forwarders are ...
by joydeep741 Path Finder in Splunk Search 09-09-2016
0 3
0
3
siddharthmis
I have the data like: 2016-09-09 06:21:31,858 ... blah ... blah... ... ORA-00001: unique constraint (AN_FIELD.CODE) ...
by siddharthmis Explorer in Splunk Search 09-09-2016
0 3
0
3
external_alien_
Hi guys! I have a bunch of test data in JSON files as my sources and they're structured in the following way: "/MyF...
by external_alien_ Explorer in Splunk Search 09-09-2016
0 3
0
3
changux
Hi all. I have an automatic file lookup configured to output some fields and works very well (using the sourcetype): ...
by changux Builder in Splunk Search 09-09-2016
0 2
0
2
bworrellZP
Have a search that gives data, for "yesterday" with specific criteria. Trying to show results by Location, with coun...
by bworrellZP Communicator in Splunk Search 09-09-2016
0 1
0
1
Parse
Hello all, I am trying to evaluate my process using two consecutive events and know whether my process succeeded or ...
by Parse New Member in Splunk Search 09-09-2016
0 1
0
1
cppandey80
I have log files which are in below format , I would like to scan them. When one logs reached to its size limit then ...
by cppandey80 New Member in Splunk Search 09-09-2016
0 1
0
1
schose
Hi all, I'm using multiple dashboards (for cpuusage, memusage, hdd usage) in an app where you can select different h...
by schose Builder in Splunk Search 09-09-2016
0 4
0
4
splunker9999
Hi, I am looking to format my current time to epoch time (as we need to calculate some math function on time) Time...
by splunker9999 Path Finder in Splunk Search 09-09-2016
0 3
0
3
krishnani
Our problem is, some people are running searches without specifying any source types and it's causing maximum system ...
by krishnani New Member in Splunk Search 09-09-2016
0 3
0
3
mwdbhyat
Hi there, How would I set up a table to find out which forwarders have not phoned home in the last day ? I am curren...
by mwdbhyat Builder in Splunk Search 09-09-2016
0 2
0
2
brian1_tate
I am somewhat baffled by what is returned when this search is executed. I know I can hide the OTHER or NULL values bu...
by brian1_tate Path Finder in Splunk Search 09-09-2016
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...