Splunk Search

Splunk Search
Community Activity
dean1
Hello Splunk Ninjas I'm trying to convert my addcoltotals of MB to TB using the eval statement which does not work.....
by dean1 New Member in Splunk Search 06-14-2016
0 2
0
2
servlette
Hi, I have something like the following which gets logged: sessionId=A,phone=4155550123 sessionId=B,phone=141555501...
by servlette Engager in Splunk Search 06-14-2016
0 6
0
6
sieutruc
Hello, I have the log like below : Jun 13 10:18:59 Debug: IID 917966106 done Jun 13 10:18:59 Debug: IID 917967047 a...
by sieutruc Contributor in Splunk Search 06-14-2016
0 6
0
6
jxiongjx
Each of the events in my log files has a data value for example, Data = a I am using a transaction to group my events...
by jxiongjx Engager in Splunk Search 06-14-2016
0 2
0
2
splunkreal
Data sample : Date;User "2016-04-01 09:31:05";"john.doe@gmail.com "2016-04-01 09:31:06";"jessica.doe@hotmail.com "20...
by splunkreal Motivator in Splunk Search 06-14-2016
0 2
0
2
arrowecssupport
So my email using the iMail Mailbox comes in with headers like this. I need everything after the "___________________...
by arrowecssupport Communicator in Splunk Search 06-14-2016
0 4
0
4
ishaanshekhar
I have a base search in my dashboard that refers to a scheduled search: <search id="Base_Search" ref="Scheduled_Repo...
by ishaanshekhar Communicator in Splunk Search 06-14-2016
0 3
0
3
TheGU
When I run transaction command, some transaction may be more than 500 events but splunk split it to a set of 500 even...
by TheGU Path Finder in Splunk Search 06-14-2016
2 4
2
4
jcpsupport
New to Splunk. Created a custom dashboard using Search App, but it is private. When I am trying to make it Global, I ...
by jcpsupport New Member in Splunk Search 06-13-2016
0 1
0
1
smudge797
If I add 1 host and remove another host in a month, the stats will be the same and the delta zero but we had movement...
by smudge797 Path Finder in Splunk Search 06-13-2016
0 3
0
3
Yaichael
I would like to exclude certain fields from search results and keep the rest of the information (not discarding the e...
by Yaichael Communicator in Splunk Search 06-13-2016
0 2
0
2
vkakani60
I would like to assign a string to a variable, like valid ="error" then use the variable with the stats or timechart ...
by vkakani60 Path Finder in Splunk Search 06-13-2016
0 5
0
5
a212830
Is there a quick way (metadata? tstats?) to get the average event size for my events? Querying every event would tak...
by a212830 Champion in Splunk Search 06-13-2016
0 6
0
6
kennyja
I would like to create a new tag field based on multiple conditions. I think I have figured out how to specify my con...
by kennyja Explorer in Splunk Search 06-13-2016
0 4
0
4
a212830
Hi, I'd like to determine the size of certain sources, but don't want the overhead of reading the entire file. Is t...
by a212830 Champion in Splunk Search 06-13-2016
0 3
0
3
cmac2001
Hi I am very new to Splunk and I am hoping that I can get a little help with my current problem I have two sources ...
by cmac2001 New Member in Splunk Search 06-13-2016
0 3
0
3
abbam
Hi guys, Wondering if anyone can help me and if this can be done. I have a CSV file with two columns. CSV file loo...
by abbam Explorer in Splunk Search 06-13-2016
0 8
0
8
dpoloche
Disclaimer: I know the search below is ugly, its based on several examples including the exploring splunk book. I was...
by dpoloche Explorer in Splunk Search 06-13-2016
0 4
0
4
ccsfdave
Greetings, I am using a form and the dynamic inputs is a table of usernames. The search results in Domain\username....
by ccsfdave Builder in Splunk Search 06-13-2016
0 3
0
3
deenadp
Hi, I would like to extract the strings between multiple delimiters as below. INPUT : src=`D:\GENEOS Program Files\...
by deenadp Explorer in Splunk Search 06-13-2016
1 5
1
5
wzgoda
Hey, I was looking run a historical search for a specific alert over a period of time. What search can I run in ord...
by wzgoda Explorer in Splunk Search 06-13-2016
0 1
0
1
smudge797
Your rex command does nothing at all so we can remove it. You also are not using Region so it can go. The dedup com...
by smudge797 Path Finder in Splunk Search 06-13-2016
0 1
0
1
reswob4
The following search works just fine in the search bar in Splunk: index=stuff earliest=-1d | eval newtime = strptime...
by reswob4 Builder in Splunk Search 06-13-2016
0 4
0
4
blues1990
For this query: index=4_ip_sql source=CNVIP101 Priority=4 Quality=192 (Message="jam" OR Message="stop" OR Message="...
by blues1990 Explorer in Splunk Search 06-13-2016
0 1
0
1
sousouheyl
Hello everyone, I'm trying to count every occurrences words from all events and get a TOP 10. Each sentences is an ...
by sousouheyl Engager in Splunk Search 06-13-2016
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...