Splunk Search

Splunk Search
Community Activity
undercoverbroth
Hello I want to Display the CPU used from a Server depending on the users are working on that Server for several Serv...
by undercoverbroth New Member in Splunk Search 06-03-2016
0 7
0
7
chanmi2
Hi all, Can we use |append [|inputlookup tmp.csv] in a post process search? Here is the code: <table> <search i...
by chanmi2 Path Finder in Splunk Search 06-02-2016
0 2
0
2
saradachelluboy
The below search String works same for approved and decline. Can some let me know where the error is? All the time i...
by saradachelluboy Explorer in Splunk Search 06-02-2016
0 4
0
4
wsw70
Hello, I have 120,000 events with the same timestamp and the 100,000 first ones get indexed with that (correct) time...
by wsw70 Communicator in Splunk Search 06-02-2016
0 1
0
1
chrisduimstra
The values from field exception_info are long multi-line values that are shown properly, but they are unable to be se...
by chrisduimstra Path Finder in Splunk Search 06-02-2016
0 7
0
7
chandulal
I am using Java to make REST API call to Splunk to make a blocking search. We had deployed the app two days ago and t...
by chandulal Engager in Splunk Search 06-02-2016
1 1
1
1
splunker9999
Hi Splunkers, We are looking to join 2 searches in getting a single point result. Currently we have a search which ...
by splunker9999 Path Finder in Splunk Search 06-02-2016
0 2
0
2
renanprado96
How to change the color of the cell based on the results? I need the cells to turn red if below a certain value and t...
by renanprado96 Path Finder in Splunk Search 06-02-2016
0 3
0
3
packet_hunter
Scenario, I have a field (msg) below and I need to extract the user id which is user = [abcdefg] field msg = AAA u...
by packet_hunter Contributor in Splunk Search 06-02-2016
0 5
0
5
SecurityIsMyMid
I'm trying to sort an hour search with: eval mydiff=tostring(info_search_time-orig_time, "duration") | table orig_ho...
by SecurityIsMyMid Explorer in Splunk Search 06-02-2016
0 1
0
1
raby1996
Hi all, I have the following search "result generating search"| eval z=mvzip(Bundle, Load_Time) | mvexpand z | str...
by raby1996 Path Finder in Splunk Search 06-02-2016
0 5
0
5
phatfingers
I'm troubleshooting a regex to match against the following data (names and IP addresses are fictional): Aug 26 10:55...
by phatfingers Explorer in Splunk Search 06-02-2016
0 5
0
5
crhodes
I keep searching all over the Splunk site and I actually think there is TOO much data/information. Maybe I'm looking...
by crhodes Explorer in Splunk Search 06-02-2016
0 5
0
5
jsmith_splunk
I'm trying build a bar chart from an asset list that shows by bunit what percentage of a field called last has a valu...
by jsmith_splunk Splunk Employee Splunk Employee in Splunk Search 06-02-2016
0 4
0
4
jkalra
I have the following search which gives me the number of transactions per instance and also gives me the average over...
by jkalra Explorer in Splunk Search 06-02-2016
0 4
0
4
Powers64
Before I start, I found https://answers.splunk.com/answers/187080/how-to-create-a-search-to-predict-license-violatio....
by Powers64 Explorer in Splunk Search 06-02-2016
0 2
0
2
maddy1011
Hello, I am trying to extract the IP address that is noted after START: and the customer name. A customer could hav...
by maddy1011 Explorer in Splunk Search 06-02-2016
0 8
0
8
suarezry
I have bills that come in at irregular periods. Here is an example for 1 type: {name:building1Water, startDate:2015...
by suarezry Builder in Splunk Search 06-02-2016
0 4
0
4
mprreddy51
Hi, I need to get the first Message REQ and first Message RES from the below event and should show my below expected...
by mprreddy51 Explorer in Splunk Search 06-02-2016
0 5
0
5
maheshj
Hi everyone, Can you help me how to extract Date and Time from below XMLsample? Here is example of a log: I am l...
by maheshj Explorer in Splunk Search 06-02-2016
0 3
0
3
snoobzilla
Anyone run across anything like this? Adding a linebreak breaking existing regex... To address some issues around m...
by snoobzilla Builder in Splunk Search 06-02-2016
0 2
0
2
shankarananthth
My values are like: Miscellanious (Field name ) Off-line|Idle|In Service| NCR Custom Edition v3.13 build578907| In S...
by shankarananthth Explorer in Splunk Search 06-02-2016
0 2
0
2
gantonio
How can i extract the added, removed, and changed file/directory and list them to a field respectively using regular ...
by gantonio New Member in Splunk Search 06-02-2016
0 1
0
1
nikkkc
hi, would someone be so kind and help me to build a rex expression? i want to extract all "Audit ID" from this sample...
by nikkkc Path Finder in Splunk Search 06-02-2016
0 6
0
6
alextanght
I got data of each transaction with a customer_id in it If I want to know the daily average of count per hour, what ...
by alextanght Engager in Splunk Search 06-02-2016
2 3
2
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors