Splunk Search

Splunk Search
Community Activity
dbcase
How do I use the results of one search (2 sources) as input to a second search (3rd source)? Here is what I have (bu...
by dbcase Motivator in Splunk Search 06-28-2016
0 8
0
8
emamedov
I'm currently using the following log statement: Jun-28 12:00:28 | INFO| [Controller:116] Downloading file content: ...
by emamedov Explorer in Splunk Search 06-28-2016
0 2
0
2
svercelli
So what I have are two different types of events. However, both have an key field that connect the two events togethe...
by svercelli Path Finder in Splunk Search 06-28-2016
0 2
0
2
john_dagostino
In my data, I have a list of assets that occur with a "First Found" date as well as a "Last Found" date. I need to g...
by john_dagostino Path Finder in Splunk Search 06-28-2016
0 2
0
2
sr_dhinesh
index=xyz [|inputlookup error_strings | table string | rename string as search | format] In the lookup I have a li...
by sr_dhinesh Path Finder in Splunk Search 06-28-2016
0 19
0
19
zafunt
My search is ... sourcetype=linux_audit (type="SYSCALL" OR type="PATH") | transaction host lin_audit_event maxevents...
by zafunt Explorer in Splunk Search 06-28-2016
0 5
0
5
ashishlal82
example: I have Current output sha256 md5 000sadasd asdasdasdsad Desired Output Has...
by ashishlal82 Explorer in Splunk Search 06-28-2016
0 10
0
10
pwunderlich
Hi I am new here and I have an issue which is unsolvable for me. I hope some of you can help me. The result of my ...
by pwunderlich Engager in Splunk Search 06-28-2016
0 7
0
7
splunker9999
Hi , We have a field called AGING which tells how many days a ticket exists. In order to get the accurate age, we ...
by splunker9999 Path Finder in Splunk Search 06-28-2016
0 2
0
2
Laya123
Hi Team, May be you feel that this is a repetitive questio,n but I didn't get response, so I opened a new question. ...
by Laya123 Communicator in Splunk Search 06-28-2016
0 4
0
4
TheHardHattedGe
Let's say I have a service that spits out information such as the following: localhost;PING;PING OK - Packet loss = ...
by TheHardHattedGe Explorer in Splunk Search 06-28-2016
0 5
0
5
chandra61446
I have below search which has a CSV input (example host and category) host server1 server2 server3 ...
by chandra61446 New Member in Splunk Search 06-28-2016
0 2
0
2
adamguzek
Doing a simple search index=test over 10mln events gives me browsing speed around 5000 events per second. Extremely s...
by adamguzek Explorer in Splunk Search 06-28-2016
0 5
0
5
Buscatrufas
Hi, I want to split data from this XML structure, but I cannot because the extracted field only gets the first elem...
by Buscatrufas Path Finder in Splunk Search 06-28-2016
0 2
0
2
bbialek
I have events from an application containing various logger type messages, I.e: INFO, WARN, ERROR... Searching just f...
by bbialek Path Finder in Splunk Search 06-27-2016
1 2
1
2
pboynton63
I have this search that I run looking back at the last 30 days index = ib_dhcp_lease_history dhcpd OR dhcpdv6 r - l ...
by pboynton63 Explorer in Splunk Search 06-27-2016
1 9
1
9
nagendra008
Hello experts, I have a case where I need to show a field in a table, but I need to hide it in the chart. Search: ...
by nagendra008 Explorer in Splunk Search 06-27-2016
0 2
0
2
adityapavan18
I have a scenario where I have a table panel I would like to hide the last column of that table but still be able to ...
by adityapavan18 Contributor in Splunk Search 06-27-2016
5 2
5
2
smudge797
What I want is to many adds/removes (new hosts vs host decoms) month on month index=* | stats dc(Host_Name) by date_...
by smudge797 Path Finder in Splunk Search 06-27-2016
0 14
0
14
g038123
Hello, I'm having trouble finding the correct syntax and function to get the desired end result. I have a search base...
by g038123 Explorer in Splunk Search 06-27-2016
0 3
0
3
Aaron_Fogarty
I am looking to display individual URI count by User on a timechart. Is this possible? My current search returns the...
by Aaron_Fogarty Path Finder in Splunk Search 06-27-2016
0 4
0
4
laurazeno
Hello Fellow Splunkers, I am trying to write a search to compare the sitename and referrer to find all results where...
by laurazeno Explorer in Splunk Search 06-27-2016
0 4
0
4
Aexyn
Hi, I want to filter Windows Security event logs in (/etc/system/local/)props.conf/transforms.conf. Here is my tran...
by Aexyn Engager in Splunk Search 06-27-2016
0 4
0
4
shenjunwei
I have data like below. How do I calculate the time difference between A.1-B. 1, A.2-B.2......A.n-B.n Time Offset Wo...
by shenjunwei New Member in Splunk Search 06-26-2016
0 4
0
4
kalyanilandge
Hi Team, I have upgraded Splunk from 6.2 to 6.3.1 version. I restored backup, but still I am not getting any output ...
by kalyanilandge New Member in Splunk Search 06-26-2016
0 13
0
13
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...