Splunk Search

Splunk Search
Community Activity
trevorr2004
I am currenlty trying to make a search a little more dynamic based off scanned devices rather than a static number i...
by trevorr2004 Engager in Splunk Search 08-26-2016
0 4
0
4
cbright
Trying to use multiple searches to get a percentage of total servers to be restored and total currently restored but ...
by cbright Explorer in Splunk Search 08-26-2016
1 2
1
2
JoshuaJohn
I am trying to extract the response time from this statement (Just the number, not the words response time or the ms ...
by JoshuaJohn Contributor in Splunk Search 08-26-2016
0 2
0
2
samarkumar
Hi I have a timestamp field with values as below "2016-08-25T13:30:36.82" "2016-08-25T13:13:38.737" "2016-08-25T1...
by samarkumar Path Finder in Splunk Search 08-26-2016
0 2
0
2
Rukmani_Splunk
I have table as below generated from splunk C:x D:x E:x F:x C:y D:y E:y F:y A 2 1 0 3 5 ...
by Rukmani_Splunk Path Finder in Splunk Search 08-26-2016
0 1
0
1
ipops
Having issues getting the NANP app to work (https://splunkbase.splunk.com/app/1515/) I have the following search but...
by ipops Path Finder in Splunk Search 08-26-2016
0 1
0
1
the_wolverine
Why doesn't fillnull work here? | rest /servicesNS/-/-/saved/searches splunk_server=local | search disabled=0 is_sch...
by the_wolverine Champion in Splunk Search 08-26-2016
0 3
0
3
sanorthrup
We always see some failures in our logs. But when we have an issue, the number of failures goes thru the roof. I'm tr...
by sanorthrup Path Finder in Splunk Search 08-26-2016
0 3
0
3
samarkumar
I am using the below query search|eval 3CMStartTime = _time|table Corr 3CMStartTime|join Corr [search XXXXX|eval 3CM...
by samarkumar Path Finder in Splunk Search 08-26-2016
0 4
0
4
tcmarquesi
I need to extract some keys/values from a certain field, however it doesn't have a fixed format. Actually this field ...
by tcmarquesi Explorer in Splunk Search 08-26-2016
0 2
0
2
Bhanus1
join/combine two searches into single table, duplicate records override with the first value. Search1: host=test* s...
by Bhanus1 New Member in Splunk Search 08-26-2016
0 5
0
5
annamareddi
unique_exception= pattern1|pattern2|pattern3 all these three patterns(1,2,3) are tagged to unique number 111. eval te...
by annamareddi New Member in Splunk Search 08-26-2016
0 2
0
2
vrvasantharaj
I need to read content from a second log file based on the field value which is extracted from the first log file. I ...
by vrvasantharaj New Member in Splunk Search 08-26-2016
0 3
0
3
ashutoshsharma1
Tried using the already answered question on splunk answer on the same topic they say do it using lookup or sub searc...
by ashutoshsharma1 Path Finder in Splunk Search 08-26-2016
0 7
0
7
pasokkum
Hi, We are using html views to run slpunk queries.. Is there any way to make the search run in fast mode in views fo...
by pasokkum Path Finder in Splunk Search 08-26-2016
0 2
0
2
napoleon_bing
I have successfully made an identity and connection. And have successfully validated that I am able to connect. ATM I...
by napoleon_bing New Member in Splunk Search 08-26-2016
0 5
0
5
vikramphilar
Here's my input: .... .... TradeDetailsDTO [ShortName=ABCD, allocated=600], TradeDetailsDTO [ShortName=EFGH, alloca...
by vikramphilar New Member in Splunk Search 08-25-2016
0 3
0
3
dbcase
Hi, I have data that looks like this I'd like to extract the json out of the message field. I see the spath comm...
by dbcase Motivator in Splunk Search 08-25-2016
0 16
0
16
daniel_augustyn
I've been trying to filter unwanted events on a heavy forwarder from being sent to indexers. I followed the instructi...
by daniel_augustyn Contributor in Splunk Search 08-25-2016
0 2
0
2
dbcase
Hi, First time trying this. I have the below data. Using the | character as a delimiter, then going thru the field...
by dbcase Motivator in Splunk Search 08-25-2016
0 1
0
1
trevorr2004
I have a search that comes up with a score based off a custom formula from nessus scan results. I want to plot that v...
by trevorr2004 Engager in Splunk Search 08-25-2016
0 6
0
6
uhkc777
Here is my search query. index=parmed-stage|eval _time=_time+14400|table _time OrderId OrderDetailID _raw|search NOT...
by uhkc777 Explorer in Splunk Search 08-25-2016
0 12
0
12
elijahputnam
Hello, I have search and currently the results show in MB. For example: Current Search: Vol in MB 112435 9734 298...
by elijahputnam New Member in Splunk Search 08-25-2016
0 3
0
3
myungjaeyi
Hi! So I have two drop-downs on my dashboard: one with a static list of options (dd1), and a second one which will ...
by myungjaeyi Engager in Splunk Search 08-25-2016
0 4
0
4
jdepp
I found a few answers here on this forum on how to use a date string field as the datetime for a timechart. I tried t...
by jdepp Path Finder in Splunk Search 08-25-2016
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...