Splunk Search

Splunk Search
Community Activity
pdumblet
I have the following results from my search. I am trying to extract the Application Name from the raw log using the f...
by pdumblet Explorer in Splunk Search 07-08-2016
0 2
0
2
mjones414
Sample data: I have several field values in one sourcetype that are variable limits that can change week by week. Th...
by mjones414 Contributor in Splunk Search 07-08-2016
0 5
0
5
adamblock2
The following search returns results when I run it as a search, but not when it is used as a dashboard panel. The das...
by adamblock2 Path Finder in Splunk Search 07-08-2016
0 1
0
1
adamblock2
I am interested in identifying when a field contains 2 specific field values appear within 5 minutes of each other. ...
by adamblock2 Path Finder in Splunk Search 07-08-2016
0 5
0
5
moaf13
I have multiple CSV lookup files and I want to use a variable to determine which lookup table to choose in my search....
by moaf13 Path Finder in Splunk Search 07-08-2016
0 2
0
2
Sravan_C
Hi All, I am writing various Splunk searches to get result set from iis logs. For each search, I have different wher...
by Sravan_C New Member in Splunk Search 07-08-2016
0 9
0
9
PRIYANKA_1993
I'm fetching the data from a CSV file, but the issue with my data is that some of the values are in PDT and some are ...
by PRIYANKA_1993 New Member in Splunk Search 07-08-2016
0 7
0
7
yzimmer
Hi everybody! In a Splunk Dashboard, I created a Bar Panel with this: * | stats count(U*) as U* | transpose | renam...
by yzimmer New Member in Splunk Search 07-08-2016
0 4
0
4
Urias
Hello! I've been told to use stats values() instead of transaction for performance issues. However, with long log fi...
by Urias Engager in Splunk Search 07-08-2016
0 6
0
6
rashid47010
HI everyone, I am trying to figure out about Unauthorised Vulnerability Scan - External.. we detected an external ho...
by rashid47010 Communicator in Splunk Search 07-08-2016
0 8
0
8
tdewitt_atl_rea
I have 2 logs: an error log and a success log. When an item fails (error log), it is retried. I would like to filter ...
by tdewitt_atl_rea New Member in Splunk Search 07-07-2016
0 4
0
4
khubyarb
I am trying to validate whether data from two separate sources is the same. I have indexed two csv files of 450,000+ ...
by khubyarb Path Finder in Splunk Search 07-07-2016
0 3
0
3
raby1996
Null
by raby1996 Path Finder in Splunk Search 07-07-2016
0 10
0
10
zsizemore
Hi, I have a query showing the amount of distinct logins by IP address based on the "term" i've created in the query...
by zsizemore Path Finder in Splunk Search 07-07-2016
0 5
0
5
iKate
Hi! Is it possible to pass into lookup's name created by outputlookup command a token or a search value? Smth like ...
by iKate Builder in Splunk Search 07-07-2016
1 2
1
2
jtuni
I have log data that doesn't always contain a user ID, but I would like to fill the user ID field with the last known...
by jtuni Engager in Splunk Search 07-07-2016
0 4
0
4
daniel333
alt text I want an alert if an application pool drops more than 99% of logging. (We have an issue where before a JVM ...
by daniel333 Builder in Splunk Search 07-07-2016
0 2
0
2
mgrimes
So I've posted a question a week ago regarding finding the max EPS for a timespan of a day. The query that I am using...
by mgrimes New Member in Splunk Search 07-07-2016
0 8
0
8
arrowecssupport
So I've got 2 different values I'm trying to use; letters & numbers. I want to be able to say If letters = a b or c...
by arrowecssupport Communicator in Splunk Search 07-07-2016
0 1
0
1
Buscatrufas
Hi guys, I need to create a join with a row, and this row has multiple occurrences in another table. What is the bes...
by Buscatrufas Path Finder in Splunk Search 07-07-2016
0 2
0
2
jonathan_yan5
how to place commas in the output of a chart with columns that varies depending on the search (example is date). Sam...
by jonathan_yan5 Explorer in Splunk Search 07-07-2016
0 12
0
12
saradachelluboy
Hi All, When I execute the search below, it works fine: index="X" sourcetype="xx" "applicationCode: 123" "provider...
by saradachelluboy Explorer in Splunk Search 07-06-2016
0 12
0
12
Buscatrufas
Hi guys, I have a problem with a table with 78k of register. I'm trying to expand a multivalue field, but the searc...
by Buscatrufas Path Finder in Splunk Search 07-06-2016
0 2
0
2
psable
Hi, I posted similar question earlier but I dont see it anymore as posted so reposting simplified version. json has ...
by psable Explorer in Splunk Search 07-06-2016
0 3
0
3
jwalzerpitt
We are ingesting some of our email logs, and one of the fields is 'Subject'. I was wondering if anyone has created ...
by jwalzerpitt Influencer in Splunk Search 07-06-2016
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...