Splunk Search

Splunk Search
Community Activity
caliburn7
Hello, I am trying to filter out events when the source username and destination username are the same, but it is no...
by caliburn7 Engager in Splunk Search 05-26-2016
0 6
0
6
Magrilloc
I am calculating a bunch of rates and I would like to take all of the rates I have calculated and divide by one of th...
by Magrilloc New Member in Splunk Search 05-26-2016
0 3
0
3
athorat
got a date extracted from a file name and got the count of files received on for that extracted date. date-2016-03-2...
by athorat Communicator in Splunk Search 05-26-2016
0 3
0
3
qiaojing
Hi, I'm trying to search for users that access the SAME system more than 5 times in 10 minutes, in order to identif...
by qiaojing Path Finder in Splunk Search 05-26-2016
0 3
0
3
vil505
As a normal user, is there any way for me to use: ps -aux| grep httpd| wc -l in Splunk's search bar? I'm trying t...
by vil505 Explorer in Splunk Search 05-26-2016
0 1
0
1
jhayIV
I am trying to provide a chart that shows multiple locations as a default, then allow them to use the multiselect to ...
by jhayIV Engager in Splunk Search 05-26-2016
0 1
0
1
mmcclelland86
I'm going crazy trying to figure this out. Splunk is not my primary job function, so I am no good at time manipulatio...
by mmcclelland86 Explorer in Splunk Search 05-26-2016
0 5
0
5
billycote
This is my query. index=snaptor sourcetype=AccessApp | fillnull value=NULL | eval query_string = upper(query_string...
by billycote Path Finder in Splunk Search 05-26-2016
0 6
0
6
cpershey
Trying to see when this search would've triggered an alert over the last few hours. The search normally runs every 10...
by cpershey Explorer in Splunk Search 05-26-2016
0 13
0
13
kodaganti
I have the below working SPLUNK query which is being used to print the timechart. I would like to trigger an email al...
by kodaganti New Member in Splunk Search 05-26-2016
0 1
0
1
abhaybhagat08
Hi All, I have logs in Splunk separated by comma e,g A ,B,C,D,E,F,.,., everything is separated by comma , now I ...
by abhaybhagat08 New Member in Splunk Search 05-26-2016
0 1
0
1
dbcase
Hi, I have a data set that looks like this: I need to calculate the avg duration of the power loss (event where E...
by dbcase Motivator in Splunk Search 05-26-2016
0 4
0
4
HeinzWaescher
Hi, I've calculated the amount of purchase actions grouped by the productId and the elapsed time (in minutes) after ...
by HeinzWaescher Motivator in Splunk Search 05-26-2016
0 1
0
1
edwinmae
Additional question 'to the same scenario': "How to use rex to extract Linux directory sizes and names?" On other s...
by edwinmae Path Finder in Splunk Search 05-26-2016
0 3
0
3
mschlager
I would like to color a single value, based on a field value that is not the one displayed in the panel. I was able t...
by mschlager New Member in Splunk Search 05-26-2016
0 2
0
2
qiaojing
Hi, may i know how to configure Splunk to only retain a rolling window of 3 months of logs data? I'm completely ne...
by qiaojing Path Finder in Splunk Search 05-26-2016
0 1
0
1
djconroy
I am trying to come up with the search syntax that would get me the the values of a field that exist in one search th...
by djconroy Path Finder in Splunk Search 05-25-2016
2 4
2
4
thewho123
I have the entries below from different sessions: sessionId="001" data="[{message=timing_stats, data=[{beginF=155065...
by thewho123 Explorer in Splunk Search 05-25-2016
0 4
0
4
vchitrala
Hi, I have execution time in the format of D:HH:DD:SS (0:00:00:22 ,0:00:00:55 ) that I need to convert to seconds. ...
by vchitrala New Member in Splunk Search 05-25-2016
0 11
0
11
dmilushev81
Hi, I am interested in the possibility of sending queries from an application (Lavastorm) to Splunk to retrieve re...
by dmilushev81 New Member in Splunk Search 05-25-2016
0 1
0
1
packet_hunter
Scenario: I have the following field called 'filePath' /src/lkfdjgsryj3kt4z57RdC-1-SomeDocument.doc I would like ...
by packet_hunter Contributor in Splunk Search 05-25-2016
0 17
0
17
katalinali
Hi all, I have a transaction which have keyword "start" and "stop", I use startswith and endswith to define the whol...
by katalinali Path Finder in Splunk Search 05-25-2016
0 3
0
3
cpalicensing
I have a source type full of data with cryptic username fields. These usernames translate to human readable username...
by cpalicensing New Member in Splunk Search 05-25-2016
0 1
0
1
aniketb
I have a lot of scheduled searches in one of our shared accounts. How do you analyze which are the top aggressive se...
by aniketb Path Finder in Splunk Search 05-25-2016
0 2
0
2
nikunj_mochi
Hi Team, I am creating a pie chart based on eventtype. For my one of the application logs, I have two logs for one u...
by nikunj_mochi New Member in Splunk Search 05-25-2016
0 2
0
2
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors