Splunk Search

Splunk Search
Community Activity
NickJLange
Disclaimer: I'm not saying this particular example is useful analysis - I'm just not sure how to think about solving...
by NickJLange Explorer in Splunk Search 05-08-2016
0 9
0
9
nikhilhanda
first search: index=prod |table assetId,SIZE,FORMAT,_time,processingHint |where assetId!="null"|outputlookup assetId_...
by nikhilhanda New Member in Splunk Search 05-08-2016
0 2
0
2
arunsubram
Search String - Promotion Created, Coupon Settings For PromoCode=121509PromoId=3550966 : 17429150|Gillette|111082|99...
by arunsubram Explorer in Splunk Search 05-08-2016
0 5
0
5
johanupwork
If I want to add up all numbers I have in the nr_external_recipients field for a particular event type, is this the b...
by johanupwork New Member in Splunk Search 05-08-2016
0 1
0
1
hulahoop
I want the series to sort as 1,2,3,10,11,12 not 1,10,11,12,2,3. The sort functions do not seem to have any effect wh...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 05-07-2016
1 4
1
4
shashi319
Here is my raw data: advisories=[Advisory@51046c2f[advisory=6,rule=LOGIN_3,passive=true], Advisory@2f9ea478[advisory...
by shashi319 New Member in Splunk Search 05-07-2016
0 2
0
2
rohitgupta2476
Hi Experts , We are using Splunk UI to search Logged data. I am planning to create a java program and run queries t...
by rohitgupta2476 New Member in Splunk Search 05-07-2016
0 1
0
1
arunsubram
My search string "[.Id.IdCreateService] - Promotion Created, Promotion Settings For PromoCode=121509PromoId=3550966 ...
by arunsubram Explorer in Splunk Search 05-07-2016
0 1
0
1
richnavis
Good Day Everyone, I"m trying to construct a search that will search our weblogs over a one hour period and report ...
by richnavis Contributor in Splunk Search 05-07-2016
0 2
0
2
skender27
Hi, I have a search and an | append [subsearch] which adds at the bottom of the results (see image) a new row with t...
by skender27 Contributor in Splunk Search 05-07-2016
0 2
0
2
abhijitp
Hi, I am looking for a solution for this problem. I have implemented Lookup tables based on time and they are workin...
by abhijitp Path Finder in Splunk Search 05-07-2016
0 7
0
7
daniel333
So if I add a single search head and add my existing indexers/search peers to it. BUT DO NOT set data forwardering on...
by daniel333 Builder in Splunk Search 05-07-2016
0 2
0
2
sethuk555
Hi, index=test sourcetype=access "READ/1.1" idvalue="" | timechart count(idvalue) as TotalRequests span=30m | append...
by sethuk555 Engager in Splunk Search 05-06-2016
0 1
0
1
kmccowen
I need to sum the PMBI users and ADF Users to get total user count. Any suggestions? index=gateway host=sc58lgwap* ...
by kmccowen Path Finder in Splunk Search 05-06-2016
0 8
0
8
lycollicott
So, I use this query: index=perfmon object=Processor host=* counter="% Processor Time" | stats avg(Value) as 15minav...
by lycollicott Motivator in Splunk Search 05-06-2016
0 2
0
2
lukasz92
Hello! I have made a timechart with a command: (...) *| timechart limit=10 sum(bytes) by src_ip* . So I got top (re...
by lukasz92 Communicator in Splunk Search 05-06-2016
0 6
0
6
gregnsk
search returns valid results, but fails with Invalid search: AND AND if defined as subsearch: 1. Search works ok:...
by gregnsk Explorer in Splunk Search 05-06-2016
3 8
3
8
mgrosholz
Case Scenario: The search string is "google" The results should find g0ogle, go0gle, gogle, gooogle, etc... I have s...
by mgrosholz Path Finder in Splunk Search 05-06-2016
0 10
0
10
TheJagoff
I performed this search index=* source="WinEventLog:System" EventCode=3 host=jj1 | table host, _time, message and g...
by TheJagoff Communicator in Splunk Search 05-06-2016
0 3
0
3
mprreddy51
Hi, how to keep the earliest time as constant(Say 12.00AM) and latest as current time (now)in splunk dashboard? requ...
by mprreddy51 Explorer in Splunk Search 05-06-2016
0 4
0
4
pjohnson1
I have a field extraction which extracts the User Name. Some users will authenticate with their user name, but some ...
by pjohnson1 Path Finder in Splunk Search 05-06-2016
0 7
0
7
sureshsala
What does this message means The maximum number of historical concurrent system-wide searches has been reached. curre...
by sureshsala Explorer in Splunk Search 05-05-2016
0 1
0
1
bowesmana
I have an index with two 'transaction types'. Create and Offer. For each create, I get an ID and I want to find out a...
by SplunkTrust SplunkTrust in Splunk Search 05-05-2016
0 2
0
2
somnath_tm
A splunk novice question We have logs and the example is something like this 2016-05-05T09:05:50.610050-07:00 Correl...
by somnath_tm New Member in Splunk Search 05-05-2016
0 1
0
1
vrmandadi
I have two different searches which I have saved as reports and scheduled it to run every Monday, but can I get both ...
by vrmandadi Builder in Splunk Search 05-05-2016
0 2
0
2
Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors