Splunk Search

Splunk Search
Community Activity
pradjswl
I can use a query that display the result in verbose mode with all fields displayed in interesting field area. I woul...
by pradjswl Explorer in Splunk Search 08-10-2016
0 2
0
2
asarran
Hey Fellow Splunkers I'm looking to possibly create a regular expression that can be used to extract a field. The da...
by asarran Path Finder in Splunk Search 08-10-2016
0 10
0
10
pradjswl
I have the following events. event 1) [08-09-2016_08:00:40.567_PDT] [ERROR] - [ePdv0XVRu2] [xxx@yyy.com] [] [auth] ...
by pradjswl Explorer in Splunk Search 08-10-2016
0 8
0
8
robettinger
Hi, I wonder if someone can help me on something. I created a report which runs absolutely fine no matter when I run...
by robettinger Explorer in Splunk Search 08-10-2016
0 3
0
3
Esky73
I'm trying to rectify a search where the chart should represent a Trend but is actually just adding the last active u...
by Esky73 Builder in Splunk Search 08-09-2016
0 2
0
2
ashishlal82
I am trying to calculate percentage from a field in my lookup (xyz ) to an event field in splunk (abc). Technically i...
by ashishlal82 Explorer in Splunk Search 08-09-2016
0 11
0
11
sridharreddy
Hi Splunkers, How to add or SUM values in timechart as shown below: Search I used: base search|transaction....|ti...
by sridharreddy New Member in Splunk Search 08-09-2016
0 1
0
1
splunkin11
Is using TERM() the same as searching for something in quotes, in that the search is not checking letter by letter, b...
by splunkin11 Path Finder in Splunk Search 08-09-2016
0 1
0
1
ashishlal82
base search| mvexpand Name | stats dc(Name) as totalcve by severity | appendcols [|inputlookup lookupname| stats coun...
by ashishlal82 Explorer in Splunk Search 08-09-2016
0 2
0
2
tccooper
We are trying to chart multiple results with some success. I am able to have everything sorted based off the Device c...
by tccooper Explorer in Splunk Search 08-09-2016
0 5
0
5
chadman
I have a chart and would like to get a total of all the peaks values on the chart. This chart calculates idle time a...
by chadman Path Finder in Splunk Search 08-09-2016
0 7
0
7
elusive
I am indexing some logs and I see some events are filled with "\x00" while some other events are indexed correctly.
by elusive Splunk Employee Splunk Employee in Splunk Search 08-09-2016
5 6
5
6
dperry
I'm importing a file into Splunk and the file always has these fields: Date (07/25/16 ) | Time (01:12:04) | Message...
by dperry Communicator in Splunk Search 08-09-2016
0 6
0
6
prakash007
Looking for a regex in 612,200(threadDuration) and 3(no.of.Threads) for the log message below... WSVR0605W: Thread “...
by prakash007 Builder in Splunk Search 08-09-2016
1 2
1
2
_dave_b
Hello. I'm trying to construct a footer containing my app's version in a dashboard. The footer resides in a differe...
by _dave_b Communicator in Splunk Search 08-09-2016
0 5
0
5
simona2121
I want to know the exact difference between sma and avg. Also, can someone pls provide detailed description of trend...
by simona2121 Path Finder in Splunk Search 08-09-2016
2 3
2
3
Javo222
I've messed my Splunk system up a bit and some jobs or searches (I don't remember) are continuously running (every mi...
by Javo222 Path Finder in Splunk Search 08-09-2016
0 3
0
3
Gayathirik
How to detect if there is a growing number of a particular type of event? It could indicate “flapping” on the Exchang...
by Gayathirik Path Finder in Splunk Search 08-09-2016
0 4
0
4
plucas_splunk
Given public transit log data of the form: 2016-08-01 13:34:03 GMT vehicle_id="1234" stop_id="5678" I would like t...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 08-08-2016
0 1
0
1
basanthp
The below is the windows security logs Message field data. The Security_ID field is splunk identified and contains 2 ...
by basanthp Path Finder in Splunk Search 08-08-2016
1 7
1
7
wuwangjun
Hi Guys, I have the below XML in a log file: I can't get the the name attribute via "path="Customer{@value}")" patt...
by wuwangjun New Member in Splunk Search 08-08-2016
0 6
0
6
sureshwalmart
Hi This is my current Splunk search: index=pqaestore source="/log/jboss_jmx_stats.log" | dedup host | rex field=_ra...
by sureshwalmart Explorer in Splunk Search 08-08-2016
0 1
0
1
sridharreddy
Hi Somesh, How My search: transaction part| timechart values(duration) as duration,values(rollno) as rollno Resu...
by sridharreddy New Member in Splunk Search 08-08-2016
0 1
0
1
cegoes
Pastebin of search.log: http://pastebin.com/aAzw697G Job inspect statistics: 0.00 command.fields 15 197...
by cegoes Explorer in Splunk Search 08-08-2016
0 3
0
3
pradjswl
I have tried the following search, but it doesn't work correctly. Option 1) Using following join command, it works g...
by pradjswl Explorer in Splunk Search 08-08-2016
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...