Splunk Search

Splunk Search
Community Activity
chburnett
So this is going to be a little...odd. I realize I'm asking a very circumstance-specific and idiosyncratic question; ...
by chburnett New Member in Splunk Search 05-20-2016
0 1
0
1
richgalloway
I have a CSV file I'm trying to index, but the wrong timestamp field is getting selected. UTC,LOCAL,HOSTNAME,SEVERIT...
by SplunkTrust SplunkTrust in Splunk Search 05-20-2016
0 9
0
9
goodsellt
I'm attempting to us rex or a similar function that will be able to help me remove the domain identifier from a usern...
by goodsellt Contributor in Splunk Search 05-20-2016
0 4
0
4
mark_groenveld
We would like to count the number of error events in 15 minute intervals and show that number as the number of errors...
by mark_groenveld Path Finder in Splunk Search 05-20-2016
0 1
0
1
ttoine
I am working on a graph in order to identify the most pinging customer accounts (traffic optimization, security). I w...
by ttoine Explorer in Splunk Search 05-20-2016
0 2
0
2
nicocin
I'm trying to convert a string to a date. The string looks like 2016-05-20T05:16:02.007+02:00
by nicocin Path Finder in Splunk Search 05-20-2016
0 4
0
4
jamesplouffe
I have events (call them "approvedset" events) generated on a regular interval which each containing a field called l...
by jamesplouffe New Member in Splunk Search 05-19-2016
0 2
0
2
SplunkNoviceUse
Hi I need help in creating a timechart for visualization of events with multiple fields of interest in a dashboard....
by SplunkNoviceUse Explorer in Splunk Search 05-19-2016
0 3
0
3
Phil219
To make a "plain english" dashboard panel, I currently use the following search to change a duration value (SecondsSi...
by Phil219 Path Finder in Splunk Search 05-19-2016
0 1
0
1
jwalzerpitt
I'm trying to craft a search that will show the percentage of quarantined messages by country, but I'm struggling a l...
by jwalzerpitt Influencer in Splunk Search 05-19-2016
0 12
0
12
aaronkorn
Hello, We have the Splunk windows app setup to monitor the system eventlogs on our citrix server and it appears to b...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 05-19-2016
1 12
1
12
muebel
How can I make a search case-sensitive? That is to say, I search for the general term "FOO" and want to only match "...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2016
10 7
10
7
jlkokko
I have a simple search parsing project activity logs to pull a list of projects and people working on those projects:...
by jlkokko Path Finder in Splunk Search 05-19-2016
0 4
0
4
UCOP
I have created a field extraction for the data I am looking for. The field looks as follows: messages_read total/in...
by UCOP New Member in Splunk Search 05-19-2016
0 8
0
8
kiran331
Hi all, I have to trigger an alert for event=1, if there is no event=2 within 30min of event=1. Search I'm using: i...
by kiran331 Builder in Splunk Search 05-19-2016
0 3
0
3
smhsplunk
index=main source=locations sourcetype=location_information | search * AND address=$token1$ OR...
by smhsplunk Communicator in Splunk Search 05-19-2016
0 4
0
4
kiran331
Hi all, I'm trying to trigger an alert when an ID occurs more than 10 times in an hour and alert should be in a tab...
by kiran331 Builder in Splunk Search 05-19-2016
0 1
0
1
muralianup
I am trying to create a graph for status history of some machine. Values I have are the name of machine & its server ...
by muralianup Communicator in Splunk Search 05-19-2016
0 1
0
1
pradeepkumarg
I want to blacklist all the lookups from the replication bundle and would like to understand what are some valid use ...
by pradeepkumarg Influencer in Splunk Search 05-19-2016
0 3
0
3
melonman
Hi, I am looking for the chart property to control the max number of data points that a chart can handle. There are ...
by melonman Motivator in Splunk Search 05-19-2016
3 10
3
10
dhavamanis
We have the events like below (fields like flowId, action..etc) and need a final output between the events (action = ...
by dhavamanis Builder in Splunk Search 05-19-2016
0 2
0
2
HeinzWaescher
Hi, I would like to extract the duration in seconds from values like these: "2 dy 13 hr 49 min 13 sec" "1 hr 49 min ...
by HeinzWaescher Motivator in Splunk Search 05-19-2016
0 9
0
9
lubson
Hello, I have been struggling with this for a while. I would like to create dashboard for following use case: QA dash...
by lubson New Member in Splunk Search 05-19-2016
0 1
0
1
alexl1
hi, Did newer versions of Splunk stop renaming fields with periods to underscores? This used to work, but does not ...
by alexl1 Path Finder in Splunk Search 05-18-2016
0 1
0
1
peterchow
Dear all, I have a following search host="1.1.1.1" VPN=A | join IP [search host="1.1.1.1" VPN=b] table _time,userna...
by peterchow Explorer in Splunk Search 05-18-2016
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...