Splunk Search

Splunk Search
Community Activity
mabdelfattah
Hello, I'm getting "No results found." whenever I search for any term in splunk. I have 29,123,099 Events INDEXED a...
by mabdelfattah New Member in Splunk Search 09-01-2016
0 18
0
18
arrowecssupport
So when I get an error with the message "(Failed)" i want the line to be added to an extracted field as a value. 9:0...
by arrowecssupport Communicator in Splunk Search 09-01-2016
0 21
0
21
evelenke
Hi, Splunkers! I have log where some different events (event A, event B, event C...) are expected to be generated pe...
by evelenke Contributor in Splunk Search 09-01-2016
0 2
0
2
ahogbin
I am attempting to remove duplicate occurrences from a results table. What I have ID 1 NewBusiness $123 ID 1 NewBusi...
by ahogbin Communicator in Splunk Search 08-31-2016
0 4
0
4
ariyazudeen
Say I have a column with 5 records in it 88 22 67 44 55 I want to compare the last record 55 with that of second las...
by ariyazudeen New Member in Splunk Search 08-31-2016
0 4
0
4
pavanae
The following were some of the events html tags 2016-04-21 09:42:38,574 DEBUG lksjfd laskdfj lskfj alsdkfj htmlta...
by pavanae Builder in Splunk Search 08-31-2016
0 10
0
10
scottrunyon
When I run a simple query "index=syslog update sourcetype=fgt_event devname=xxxxx", it returns duplicate (2) events...
by scottrunyon Contributor in Splunk Search 08-31-2016
0 5
0
5
lycollicott
The macro consists of this code: index=_internal source=*license_usage.log type="Usage" | eval h=if(len(h)=0 OR isnu...
by lycollicott Motivator in Splunk Search 08-31-2016
0 1
0
1
lpolo
I would like to extract the key=value pairs found in a multivalue field, but without doing mvexpand mvfield. Note: t...
by lpolo Motivator in Splunk Search 08-31-2016
0 3
0
3
jmaple
I'm trying to create a report that details our VPN usage over the course of a month. I've got the base of the report ...
by jmaple Communicator in Splunk Search 08-31-2016
0 1
0
1
Kukkadapu
Hi, I need some help to transform the below event? Thanks for your time. 2016-08-30 13:13:48,525 log_level='INFO' ab...
by Kukkadapu Path Finder in Splunk Search 08-31-2016
0 4
0
4
trevorQmulos
I have the current search right now but am getting inaccurate numbers due to an issue with my search. I would like to...
by trevorQmulos New Member in Splunk Search 08-31-2016
0 6
0
6
pavanae
I got a strange situation here. I have two different searches as follows. search 1: index=* [ search index=_interna...
by pavanae Builder in Splunk Search 08-31-2016
0 3
0
3
ashishlal82
How can I use timestamps from 2 different sources and calucate them inorder to find the difference and convert in nu...
by ashishlal82 Explorer in Splunk Search 08-31-2016
0 15
0
15
ebailey
We are using a search head cluster and we are having an issue with the following workflow. A user has lookup table th...
by ebailey Communicator in Splunk Search 08-31-2016
1 2
1
2
plucas_splunk
Given a search: index="muni" | nbclosest | timechart span=30m dc(vehicle_id) as NumVehicles (where nbclosest is a ...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-31-2016
0 3
0
3
pavanae
The following is my search query :- index=* | regex _raw!=".2016-\d{2}-\d{2}." | stats values(host) as hosts Also ...
by pavanae Builder in Splunk Search 08-31-2016
0 5
0
5
andreafebbo
Hi all. I have a normal time selector in splunk that I think that everybody know. I noticed that in my dashboard i...
by andreafebbo Communicator in Splunk Search 08-31-2016
1 1
1
1
singhh4
Hey people! So I may be a big idiot and be missing something very simple but i cant seem to figure it out. here is ...
by singhh4 Path Finder in Splunk Search 08-31-2016
0 2
0
2
annamareddi
i have a regex pattern in my .CSV file. Pattern1= A$B$C|K$L$M|X$Y$Z. where "$" is a variable like date and ID eac...
by annamareddi New Member in Splunk Search 08-31-2016
0 2
0
2
plucas_splunk
A particular public transit line is served by, say, N vehicles concurrently at any given time in the range [0,M] wher...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-31-2016
0 8
0
8
PPape
Hi Guys, I need some help with a stats command. Given is Data like this csv Round,Player1,Player2,ScorePlayer1,Sco...
by PPape Contributor in Splunk Search 08-31-2016
0 3
0
3
ahogbin
I am slowly progressing on a report but I am stuck on trying to extract some values from xml. The values I am trying...
by ahogbin Communicator in Splunk Search 08-30-2016
0 3
0
3
ID_SplunkUser
Hi All, I have a scenario to combine the search results from 2 queries. For Type= 101 I don't have fields "Amount" a...
by ID_SplunkUser Path Finder in Splunk Search 08-30-2016
0 5
0
5
ZacEsa
Hi all, I realized then Splunk hasn't been correctly auto-setting the sourcetypes for my incoming logs, resulting in...
by ZacEsa Communicator in Splunk Search 08-30-2016
0 4
0
4
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors