Splunk Search

Splunk Search
Community Activity
Cuyose
I cannot find a working example of this anywhere. I can find examples a mile long on google, but am having trouble a...
by Cuyose Builder in Splunk Search 09-01-2016
0 4
0
4
trevorQmulos
I have a CSV that has the setup as shown below. Date |Score 1/1/2016 | 4.3 2/1/2016 | 5.7 I need to extract t...
by trevorQmulos New Member in Splunk Search 09-01-2016
0 2
0
2
mwdbhyat
Hi, Is it possible to use a backfill script without the need of pointing to an app name? EG - ./splunk cmd python f...
by mwdbhyat Builder in Splunk Search 09-01-2016
0 1
0
1
Meena_0627
In extreme search, i would like to know what this statement means and how it is derived by Splunk "xwhere count from...
by Meena_0627 New Member in Splunk Search 09-01-2016
0 1
0
1
phudinhha
Dear Team, I am trying to build a chart like this: - x-axis is the website name - y-axis is the number of request...
by phudinhha Explorer in Splunk Search 09-01-2016
0 3
0
3
nivethainspire_
I have tried the below query,it works fine,but its complicated, Can anyone suggest a better way to write the same que...
by nivethainspire_ Explorer in Splunk Search 09-01-2016
0 1
0
1
mabdelfattah
Hello, I'm getting "No results found." whenever I search for any term in splunk. I have 29,123,099 Events INDEXED a...
by mabdelfattah New Member in Splunk Search 09-01-2016
0 18
0
18
arrowecssupport
So when I get an error with the message "(Failed)" i want the line to be added to an extracted field as a value. 9:0...
by arrowecssupport Communicator in Splunk Search 09-01-2016
0 21
0
21
evelenke
Hi, Splunkers! I have log where some different events (event A, event B, event C...) are expected to be generated pe...
by evelenke Contributor in Splunk Search 09-01-2016
0 2
0
2
ahogbin
I am attempting to remove duplicate occurrences from a results table. What I have ID 1 NewBusiness $123 ID 1 NewBusi...
by ahogbin Communicator in Splunk Search 08-31-2016
0 4
0
4
ariyazudeen
Say I have a column with 5 records in it 88 22 67 44 55 I want to compare the last record 55 with that of second las...
by ariyazudeen New Member in Splunk Search 08-31-2016
0 4
0
4
pavanae
The following were some of the events html tags 2016-04-21 09:42:38,574 DEBUG lksjfd laskdfj lskfj alsdkfj htmlta...
by pavanae Builder in Splunk Search 08-31-2016
0 10
0
10
scottrunyon
When I run a simple query "index=syslog update sourcetype=fgt_event devname=xxxxx", it returns duplicate (2) events...
by scottrunyon Contributor in Splunk Search 08-31-2016
0 5
0
5
lycollicott
The macro consists of this code: index=_internal source=*license_usage.log type="Usage" | eval h=if(len(h)=0 OR isnu...
by lycollicott Motivator in Splunk Search 08-31-2016
0 1
0
1
lpolo
I would like to extract the key=value pairs found in a multivalue field, but without doing mvexpand mvfield. Note: t...
by lpolo Motivator in Splunk Search 08-31-2016
0 3
0
3
jmaple
I'm trying to create a report that details our VPN usage over the course of a month. I've got the base of the report ...
by jmaple Communicator in Splunk Search 08-31-2016
0 1
0
1
Kukkadapu
Hi, I need some help to transform the below event? Thanks for your time. 2016-08-30 13:13:48,525 log_level='INFO' ab...
by Kukkadapu Path Finder in Splunk Search 08-31-2016
0 4
0
4
trevorQmulos
I have the current search right now but am getting inaccurate numbers due to an issue with my search. I would like to...
by trevorQmulos New Member in Splunk Search 08-31-2016
0 6
0
6
pavanae
I got a strange situation here. I have two different searches as follows. search 1: index=* [ search index=_interna...
by pavanae Builder in Splunk Search 08-31-2016
0 3
0
3
ashishlal82
How can I use timestamps from 2 different sources and calucate them inorder to find the difference and convert in nu...
by ashishlal82 Explorer in Splunk Search 08-31-2016
0 15
0
15
ebailey
We are using a search head cluster and we are having an issue with the following workflow. A user has lookup table th...
by ebailey Communicator in Splunk Search 08-31-2016
1 2
1
2
plucas_splunk
Given a search: index="muni" | nbclosest | timechart span=30m dc(vehicle_id) as NumVehicles (where nbclosest is a ...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-31-2016
0 3
0
3
pavanae
The following is my search query :- index=* | regex _raw!=".2016-\d{2}-\d{2}." | stats values(host) as hosts Also ...
by pavanae Builder in Splunk Search 08-31-2016
0 5
0
5
andreafebbo
Hi all. I have a normal time selector in splunk that I think that everybody know. I noticed that in my dashboard i...
by andreafebbo Communicator in Splunk Search 08-31-2016
1 1
1
1
singhh4
Hey people! So I may be a big idiot and be missing something very simple but i cant seem to figure it out. here is ...
by singhh4 Path Finder in Splunk Search 08-31-2016
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors