Splunk Search

Splunk Search
Community Activity
dennisaraujo
Hi friends!!! I am using the delta command to show the difference between two entries/values, but need to have a bla...
by dennisaraujo Path Finder in Splunk Search 08-01-2016
0 2
0
2
mmclain1
I think I'm missing something. I have rex generating a new field for me. I want to return only events with the maximu...
by mmclain1 Explorer in Splunk Search 08-01-2016
1 3
1
3
infra2sec
Hi, I'd like to have Splunk display only matching names from my .csv data source which has 2 fields. I'd like to di...
by infra2sec Path Finder in Splunk Search 08-01-2016
1 5
1
5
lavanyaanne
i am using perl script to pull the data from DB. The data is indexed perfectly and it's using the header that i was m...
by lavanyaanne Path Finder in Splunk Search 08-01-2016
0 2
0
2
ektasiwani
Hi, In my search, I need to call a macro with the eval command, but I am getting error "bad request". My macros.conf...
by ektasiwani Communicator in Splunk Search 07-31-2016
0 3
0
3
jmaple
I'm looking to create a timechart of VPN sessions that shows the number of users logged on over the course of a 24 ho...
by jmaple Communicator in Splunk Search 07-30-2016
0 2
0
2
ccsfdave
Pretty simple question, hopefully it is a simple answer. I have data where one field has a URL of an image. I would...
by ccsfdave Builder in Splunk Search 07-29-2016
0 3
0
3
ashabc
I have certain logs which are indexed correctly. Field extraction using props.conf and transforms.conf works correctl...
by ashabc Contributor in Splunk Search 07-29-2016
0 1
0
1
splunker9999
Hi, We are planning to implement summary indexing in our dashboards. As part of it, I have created a scheduled searc...
by splunker9999 Path Finder in Splunk Search 07-29-2016
0 6
0
6
Rockn
Very much a newb looking to get some basic information from my Sonicwall logs. Setting up the search using multiple c...
by Rockn New Member in Splunk Search 07-29-2016
0 2
0
2
RobertKepner
I am trying to complete a request for a specific employees internet search history. I need to specify a date range, l...
by RobertKepner New Member in Splunk Search 07-29-2016
0 7
0
7
jsilverbears
I have a summary index that is holding lead information. One of the data points I created was the numeric day the lea...
by jsilverbears Path Finder in Splunk Search 07-29-2016
0 3
0
3
sjaworski
What are everyone's thoughts on whether you should or should not specify the index in your search? Is sourcetype=val...
by sjaworski Communicator in Splunk Search 07-29-2016
0 5
0
5
laberthelemy
In 6.4.2 version, when i try to count the integrated volume by sourcetype last day for example with this search : ea...
by laberthelemy Engager in Splunk Search 07-29-2016
0 7
0
7
bandit
The following search worked prior to upgrade: | stats sparkline count dc(sourcetype) as sourcetype last(_raw) as las...
by bandit Motivator in Splunk Search 07-29-2016
0 2
0
2
jamesoconnell
A ticket has come across my desk today where a customer is getting different results from different search heads for ...
by jamesoconnell Path Finder in Splunk Search 07-29-2016
0 8
0
8
vpao
Hello, I have events in index 1 and I have lookup table 1 created from a CSV file. I want to lookup events from index...
by vpao Engager in Splunk Search 07-29-2016
0 1
0
1
sfatnass
hi, i try to use left join to match between two index. index="myfirst_Index" | rex max_match=0 field=multivalu...
by sfatnass Contributor in Splunk Search 07-29-2016
0 5
0
5
yma8000
Hi folks, newbee here, I'm trying to do this: | stats values(duration) as DaysSinceLastAccess, count(duration) as Ac...
by yma8000 New Member in Splunk Search 07-29-2016
0 1
0
1
Anshumaan12
Hi All I am trying to compare the result of the query. In am getting this result from my query Hostname date time ...
by Anshumaan12 New Member in Splunk Search 07-29-2016
0 4
0
4
sdf5496d8f
Hey Guys, any chance to set a blacklist entry in the universal forwarders input.conf for not sending events where in...
by sdf5496d8f New Member in Splunk Search 07-29-2016
0 2
0
2
tac24
After the base search such as: ...... | stats sum(r1) as t_r1 sum(r2) as t_r2 sum(duras) as total_dura c(member) ...
by tac24 New Member in Splunk Search 07-29-2016
0 2
0
2
Fleshwriter
Hello, I am trying to find a way to show events which are not meeting transaction requirements. So of course I can't...
by Fleshwriter Explorer in Splunk Search 07-29-2016
0 4
0
4
jujis008
Hi, I was preparing a dashboard but i have some problems while generating the table. I am using sort and stats to gr...
by jujis008 Explorer in Splunk Search 07-28-2016
0 2
0
2
yma8000
Hi folks, newbie here, trying to use Splunk to do some stuff... I have a search that ends like below: | table DaysS...
by yma8000 New Member in Splunk Search 07-28-2016
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...