Splunk Search

Splunk Search
Community Activity
SplunkNoviceUse
Hi I need help in creating a timechart for visualization of events with multiple fields of interest in a dashboard....
by SplunkNoviceUse Explorer in Splunk Search 05-19-2016
0 3
0
3
Phil219
To make a "plain english" dashboard panel, I currently use the following search to change a duration value (SecondsSi...
by Phil219 Path Finder in Splunk Search 05-19-2016
0 1
0
1
jwalzerpitt
I'm trying to craft a search that will show the percentage of quarantined messages by country, but I'm struggling a l...
by jwalzerpitt Influencer in Splunk Search 05-19-2016
0 12
0
12
aaronkorn
Hello, We have the Splunk windows app setup to monitor the system eventlogs on our citrix server and it appears to b...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 05-19-2016
1 12
1
12
muebel
How can I make a search case-sensitive? That is to say, I search for the general term "FOO" and want to only match "...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2016
10 7
10
7
jlkokko
I have a simple search parsing project activity logs to pull a list of projects and people working on those projects:...
by jlkokko Path Finder in Splunk Search 05-19-2016
0 4
0
4
UCOP
I have created a field extraction for the data I am looking for. The field looks as follows: messages_read total/in...
by UCOP New Member in Splunk Search 05-19-2016
0 8
0
8
kiran331
Hi all, I have to trigger an alert for event=1, if there is no event=2 within 30min of event=1. Search I'm using: i...
by kiran331 Builder in Splunk Search 05-19-2016
0 3
0
3
smhsplunk
index=main source=locations sourcetype=location_information | search * AND address=$token1$ OR...
by smhsplunk Communicator in Splunk Search 05-19-2016
0 4
0
4
kiran331
Hi all, I'm trying to trigger an alert when an ID occurs more than 10 times in an hour and alert should be in a tab...
by kiran331 Builder in Splunk Search 05-19-2016
0 1
0
1
muralianup
I am trying to create a graph for status history of some machine. Values I have are the name of machine & its server ...
by muralianup Communicator in Splunk Search 05-19-2016
0 1
0
1
pradeepkumarg
I want to blacklist all the lookups from the replication bundle and would like to understand what are some valid use ...
by pradeepkumarg Influencer in Splunk Search 05-19-2016
0 3
0
3
melonman
Hi, I am looking for the chart property to control the max number of data points that a chart can handle. There are ...
by melonman Motivator in Splunk Search 05-19-2016
3 10
3
10
dhavamanis
We have the events like below (fields like flowId, action..etc) and need a final output between the events (action = ...
by dhavamanis Builder in Splunk Search 05-19-2016
0 2
0
2
HeinzWaescher
Hi, I would like to extract the duration in seconds from values like these: "2 dy 13 hr 49 min 13 sec" "1 hr 49 min ...
by HeinzWaescher Motivator in Splunk Search 05-19-2016
0 9
0
9
lubson
Hello, I have been struggling with this for a while. I would like to create dashboard for following use case: QA dash...
by lubson New Member in Splunk Search 05-19-2016
0 1
0
1
alexl1
hi, Did newer versions of Splunk stop renaming fields with periods to underscores? This used to work, but does not ...
by alexl1 Path Finder in Splunk Search 05-18-2016
0 1
0
1
peterchow
Dear all, I have a following search host="1.1.1.1" VPN=A | join IP [search host="1.1.1.1" VPN=b] table _time,userna...
by peterchow Explorer in Splunk Search 05-18-2016
0 5
0
5
snehalk
Hello All, How can we get a list of sources which did not have any data for last 24 hours in Splunk for a particular...
by snehalk Communicator in Splunk Search 05-18-2016
0 4
0
4
raby1996
Hello, I'm running the following search for a runtime report: my search | rex field=source ".*?(?<Machin...
by raby1996 Path Finder in Splunk Search 05-18-2016
0 2
0
2
jtracy
So I've been reading around and most people point to xpath, but after hours of troubleshooting I can't seem to get it...
by jtracy Engager in Splunk Search 05-18-2016
0 3
0
3
Splunk_SachinKu
Hi All, I have following URI in my logs. /svc/appName/1234567890/catalog/search/(status), /svc/appName/1234567890/...
by Splunk_SachinKu New Member in Splunk Search 05-18-2016
0 1
0
1
changux
Hi all. I have one field called date1 with a timestamp like this: 5/7/16 16:35 I need the time difference (just...
by changux Builder in Splunk Search 05-18-2016
0 7
0
7
eastgrant
Does anyone know the command or search string to see which Cisco firewalls are sending traffic to Splunk?
by eastgrant New Member in Splunk Search 05-18-2016
0 1
0
1
ttoine
I am working on a pie chart to identify the main categories of some data. Below are some possible values: Apple Peach...
by ttoine Explorer in Splunk Search 05-18-2016
0 6
0
6
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...
Top Solution Authors