Splunk Search

Splunk Search
Community Activity
dbcase
Hi, First time doing drill downs, so pardon the newbie question. I'm having a tough time grasping the drilldown c...
by dbcase Motivator in Splunk Search 08-04-2016
0 14
0
14
JeffCr
How do I extract the following which always occurs as the last part of the raw text in message e.g "Took 13983.1468ms...
by JeffCr Explorer in Splunk Search 08-04-2016
0 11
0
11
smhsplunk
In previous version of the Splunk one could goto the Edit Icon in each page and could Disable/Enable the drilldown ...
by smhsplunk Communicator in Splunk Search 08-04-2016
0 2
0
2
gesman
When i run search: index=my_summary sourcetype=stash ip=13.13.137.13 | head 5 Job inspector's "normalizedSearch" as ...
by gesman Communicator in Splunk Search 08-04-2016
0 1
0
1
arkadyz1
I have data which contain a field with a lot of values and has duplicates on almost every one - a barcode, scanned in...
by arkadyz1 Builder in Splunk Search 08-04-2016
0 7
0
7
dcascione
Hello Splunk Ninjas I'm trying to create a SPL query that displays the avg and max response time. When I run my sea...
by dcascione Explorer in Splunk Search 08-04-2016
0 7
0
7
Gayathirik
I have a search to alert on account lockouts: index=winsec EventCodeDescription="A user account was locked out"|dedu...
by Gayathirik Path Finder in Splunk Search 08-04-2016
1 4
1
4
niftynicholas
I am developing a dashboard to analyze users logs from an email application. The dashboard has a Time (Time Picker) a...
by niftynicholas New Member in Splunk Search 08-04-2016
0 4
0
4
priyankamundarg
Kindly help me with crontab schedule and Trigger Conditions. Am confused in that part. If string matches what should ...
by priyankamundarg Explorer in Splunk Search 08-04-2016
0 2
0
2
splunksridhar
Hi, I am new to splunk and know the basics of search. Below is how my logs looks like. 2016-08-03 23:51:00,607 INFO ...
by splunksridhar New Member in Splunk Search 08-04-2016
0 2
0
2
the_wolverine
What am I doing wrong? I've tried several iterations of the following all which return 2 columns with a count of 0: ...
by the_wolverine Champion in Splunk Search 08-04-2016
2 4
2
4
BinnyK
I have some values in a fied which are email addresses. eg: Values of F may be "[""email_type2@gmail.com""]" "[""ema...
by BinnyK Explorer in Splunk Search 08-04-2016
0 5
0
5
syed_star357
Hi, Can anyone tell me why this comment is not working? I have all the mentioned fields in my data, but when I add s...
by syed_star357 New Member in Splunk Search 08-04-2016
0 4
0
4
kiran_mh
hi, index=msexchange sourcetype="MSExchange:2013:HttpProxy" host="ftlpex02cas01.citrite.net" RpcHttp AND "/rpc/rpcpr...
by kiran_mh Explorer in Splunk Search 08-04-2016
0 2
0
2
omend
Hi all, I have gathered into Splunk sales information of store branches across the US. The data is in the format: ...
by omend Path Finder in Splunk Search 08-04-2016
1 3
1
3
zabarai
Hi, I'm trying to come up with a search that would help identify spam. It would have to look at sender domain and ...
by zabarai Engager in Splunk Search 08-03-2016
0 2
0
2
iiierdna
I am working to connect Splunk with my Active Directory using LDAP, and during the process, I have enabled DEBUG on b...
by iiierdna Explorer in Splunk Search 08-03-2016
0 3
0
3
Sukisen1981
I have a reqquirement as follows: I have a time chart with 3 fields A,B,C C=A-B+previous value of C in row immediate...
by Sukisen1981 Champion in Splunk Search 08-03-2016
0 5
0
5
ID_SplunkUser
Displaying the multiple fields on X-axis of chart. Below is my current search: index=home | eval Value=substr(Name,-...
by ID_SplunkUser Path Finder in Splunk Search 08-03-2016
0 3
0
3
kartik13
Hi , I have a timechart with different columns. I want to display those events from a time chart which are continuo...
by kartik13 Communicator in Splunk Search 08-03-2016
0 3
0
3
marcus933
I have the following 2 charts <panel> <chart> <title>HDB Resale index By Year</title> <search> <quer...
by marcus933 New Member in Splunk Search 08-03-2016
0 2
0
2
spammenot66
Is there anyway to treat all loaded home pages for a given URL path to be the same? For example the home page can sho...
by spammenot66 Contributor in Splunk Search 08-03-2016
0 2
0
2
spammenot66
I currently have a working tstats search, but when I use real-time, it returns the following error: Error in 'tstat...
by spammenot66 Contributor in Splunk Search 08-03-2016
0 3
0
3
deodion
How does Splunk assign processor cores to execute a job like running script, scheduled search, ad hoc search, etc. L...
by deodion Path Finder in Splunk Search 08-03-2016
1 2
1
2
ID_SplunkUser
I want to color the column bars based on the Status value I'm getting, having trouble in doing that. Can anyone help ...
by ID_SplunkUser Path Finder in Splunk Search 08-03-2016
0 2
0
2
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...