Splunk Search

Splunk Search
Community Activity
abhaybhagat08
Hi All, I have logs in Splunk separated by comma e,g A ,B,C,D,E,F,.,., everything is separated by comma , now I ...
by abhaybhagat08 New Member in Splunk Search 05-26-2016
0 1
0
1
dbcase
Hi, I have a data set that looks like this: I need to calculate the avg duration of the power loss (event where E...
by dbcase Motivator in Splunk Search 05-26-2016
0 4
0
4
HeinzWaescher
Hi, I've calculated the amount of purchase actions grouped by the productId and the elapsed time (in minutes) after ...
by HeinzWaescher Motivator in Splunk Search 05-26-2016
0 1
0
1
edwinmae
Additional question 'to the same scenario': "How to use rex to extract Linux directory sizes and names?" On other s...
by edwinmae Path Finder in Splunk Search 05-26-2016
0 3
0
3
mschlager
I would like to color a single value, based on a field value that is not the one displayed in the panel. I was able t...
by mschlager New Member in Splunk Search 05-26-2016
0 2
0
2
qiaojing
Hi, may i know how to configure Splunk to only retain a rolling window of 3 months of logs data? I'm completely ne...
by qiaojing Path Finder in Splunk Search 05-26-2016
0 1
0
1
djconroy
I am trying to come up with the search syntax that would get me the the values of a field that exist in one search th...
by djconroy Path Finder in Splunk Search 05-25-2016
2 4
2
4
thewho123
I have the entries below from different sessions: sessionId="001" data="[{message=timing_stats, data=[{beginF=155065...
by thewho123 Explorer in Splunk Search 05-25-2016
0 4
0
4
vchitrala
Hi, I have execution time in the format of D:HH:DD:SS (0:00:00:22 ,0:00:00:55 ) that I need to convert to seconds. ...
by vchitrala New Member in Splunk Search 05-25-2016
0 11
0
11
dmilushev81
Hi, I am interested in the possibility of sending queries from an application (Lavastorm) to Splunk to retrieve re...
by dmilushev81 New Member in Splunk Search 05-25-2016
0 1
0
1
packet_hunter
Scenario: I have the following field called 'filePath' /src/lkfdjgsryj3kt4z57RdC-1-SomeDocument.doc I would like ...
by packet_hunter Contributor in Splunk Search 05-25-2016
0 17
0
17
katalinali
Hi all, I have a transaction which have keyword "start" and "stop", I use startswith and endswith to define the whol...
by katalinali Path Finder in Splunk Search 05-25-2016
0 3
0
3
cpalicensing
I have a source type full of data with cryptic username fields. These usernames translate to human readable username...
by cpalicensing New Member in Splunk Search 05-25-2016
0 1
0
1
aniketb
I have a lot of scheduled searches in one of our shared accounts. How do you analyze which are the top aggressive se...
by aniketb Path Finder in Splunk Search 05-25-2016
0 2
0
2
nikunj_mochi
Hi Team, I am creating a pie chart based on eventtype. For my one of the application logs, I have two logs for one u...
by nikunj_mochi New Member in Splunk Search 05-25-2016
0 2
0
2
sfatnass
Hi I want to change a multivalue field from: Abcd=0.3333 GBTDF=0.25 JKLLIH=0.5 to: Abcd 33% GBTDF 25% JKLLIH 50%...
by sfatnass Contributor in Splunk Search 05-25-2016
0 3
0
3
lohitkidu
Hi , I am not sure how to use the metadata command using the Python API as it is required to be the first command li...
by lohitkidu Path Finder in Splunk Search 05-25-2016
0 3
0
3
akazarov
Hello, When indexing data, I extract some selected fields. Thus, these fields are not part of 'EXTRACT-fields' line ...
by akazarov Path Finder in Splunk Search 05-25-2016
0 1
0
1
mortenb123
Hi Splunkers We have an ever growing pile of dashboards where we like to compare old statistics. Is it possible to ...
by mortenb123 Path Finder in Splunk Search 05-25-2016
0 2
0
2
maximus_reborn
I am calculating distance between the 2 latitude and longitude and if the distance > 0, then it will return the event...
by maximus_reborn Path Finder in Splunk Search 05-24-2016
0 6
0
6
tp92222
Hi, I have two indexes: index="abc" index="dummy" Now both indexes have one common field ID. I want to compare in...
by tp92222 Explorer in Splunk Search 05-24-2016
0 6
0
6
jpkeeton
This can't be answered by limiting the time range searched. Repro: - I set my search terms and date range. - I get...
by jpkeeton New Member in Splunk Search 05-24-2016
0 2
0
2
jojujose
For simplicity sake, my data definition looks like: (FileId,ObjectId,ParentObjectId) My data sample may look like: f1...
by jojujose New Member in Splunk Search 05-24-2016
0 2
0
2
changux
Hi all. I have this search: index="bucle_cm" sourcetype="cierres-pendientes" "Tipo Actuacion"="*" "Tipo Actuacion"!...
by changux Builder in Splunk Search 05-24-2016
0 12
0
12
daniel333
All, I have an automatic lookup table working great, however, when a value isn't in my lookup table, I was hoping t...
by daniel333 Builder in Splunk Search 05-24-2016
0 1
0
1
Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...