Splunk Search

Splunk Search
Community Activity
lguinn2
I have a list of hosts; I need to see if these hosts appear anywhere in my Splunked events. It is a very long list, s...
by Legend in Splunk Search 05-24-2016
0 1
0
1
qiaojing
Hi, I'm trying to get the system with the most number of logs (usage) for every hour. I did a search for: eventtyp...
by qiaojing Path Finder in Splunk Search 05-24-2016
0 1
0
1
geantver0000
Hi, I have found many searches using lookup files, but none works correctly for me What is the correct search to get...
by geantver0000 Engager in Splunk Search 05-23-2016
0 3
0
3
tp92222
hi, I have log with 3 columns ID....TYPE...... DESC 1.......A............Member Since Year-2015 2...... B.............
by tp92222 Explorer in Splunk Search 05-23-2016
0 4
0
4
proctormap
I am trying to group by text within a specific field. I'm essentially searching a message content field called event....
by proctormap New Member in Splunk Search 05-23-2016
0 6
0
6
krantik
I am not sure if this is feasible and done before. We have anonymous users, each have their own sensors which genera...
by krantik New Member in Splunk Search 05-23-2016
0 5
0
5
thewho123
I display two different graphs by using the following strings. "Sending" earliest=-7days | eval gigabytes=((bytes/10...
by thewho123 Explorer in Splunk Search 05-23-2016
0 3
0
3
dpanych
I had a previous thread open, but since then I worked on the alert and refined some criteria. The alert is running of...
by dpanych Communicator in Splunk Search 05-23-2016
1 2
1
2
Cuyose
If I have a search of search|stats max(duration) by Action When I run the search, how can I add the time for each...
by Cuyose Builder in Splunk Search 05-23-2016
0 10
0
10
TheJagoff
When I enter this search: sourcetype=win* (EventCode=4624 OR EventCode=4634)| stats latest(eval(if(EventCode=4624,_...
by TheJagoff Communicator in Splunk Search 05-23-2016
0 2
0
2
ra01
When I try the search to create a running total out of the streamstats documentation, it doesn't work. Nothing change...
by ra01 Path Finder in Splunk Search 05-23-2016
0 4
0
4
spandana9
I have cache hit as well as cache miss reports, How do i get the ratio of cache hit i.e, cache hit / (cache hit + cac...
by spandana9 Engager in Splunk Search 05-23-2016
0 3
0
3
anewell
I am collecting a PerfmonMK dataset that includes a memory value in bytes. I would like to display the value in KB. ...
by anewell Path Finder in Splunk Search 05-23-2016
0 5
0
5
SecurityIsMyMid
I'm looking to create a report that finds expected hosts not reporting to Splunk without using the Macro. Anyone have...
by SecurityIsMyMid Explorer in Splunk Search 05-23-2016
0 4
0
4
Joshua
Hi, Can someone help me? I have the searches below and need to be combine the two to display the expected results: ...
by Joshua Explorer in Splunk Search 05-23-2016
0 3
0
3
drinkingjimmy
I'm trying to run a search where I will get results if a field matches one of many predetermined values and I'm worri...
by drinkingjimmy Explorer in Splunk Search 05-23-2016
0 4
0
4
Fleshwriter
Hello. I have a simple question: I would like to have a specified index with sensitive data in it, however, I don'...
by Fleshwriter Explorer in Splunk Search 05-23-2016
0 1
0
1
jojujose
First of all I am very new to splunk!  My data can be simplified to look something like this. Employee = (UniqueId...
by jojujose New Member in Splunk Search 05-23-2016
0 2
0
2
edwinmae
I run a daily script on the server, du -sk, against a certain directory that contains 200 subdirectories and write th...
by edwinmae Path Finder in Splunk Search 05-23-2016
0 3
0
3
mbosse
I'm relatively new to Splunk queries. I have an event that contains JSON and within the JSON data is an array. Ther...
by mbosse Explorer in Splunk Search 05-22-2016
0 6
0
6
raby1996
Hi all, I'm using the Splunk Field Extractor in order clean up the my search a bit, and I'm using the following rex ...
by raby1996 Path Finder in Splunk Search 05-22-2016
0 9
0
9
grannnt
On my dashboard, I have a graph displaying how many workstations have out of date virus definitions. Several of these...
by grannnt New Member in Splunk Search 05-22-2016
0 2
0
2
Esky73
http://imgur.com/MbH4w37 Trying to recreate this chart in Splunk - can anyone assist, as I'm a bit uncertain where t...
by Esky73 Builder in Splunk Search 05-21-2016
0 7
0
7
thisissplunk
I might be going to deep here but I figured I'd give it shot... I have a stats command keying off of a domain name....
by thisissplunk Builder in Splunk Search 05-21-2016
0 4
0
4
thisissplunk
I need to join data from two (or more, ultimately) different sourcetypes based on the shared "host" field. Just a sub...
by thisissplunk Builder in Splunk Search 05-21-2016
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors