Splunk Search

Splunk Search
Community Activity
rewritex
Background: My data is being sent to a summary index. The search that populates the summary index is: index=test1 tr...
by rewritex Contributor in Splunk Search 05-02-2016
0 4
0
4
mattnovak
I'm attempting to use some KV pairs as tokens (i.e., $result.configuration$ and $result.version$) in an email alert. ...
by mattnovak Explorer in Splunk Search 05-02-2016
0 4
0
4
fmerrow
So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced". I see...
by fmerrow New Member in Splunk Search 05-02-2016
0 2
0
2
malderhout
If have the following search in Splunk: sourcetype = Tweets | stats count(eval(match(text, "string1"))) AS "string1"...
by malderhout New Member in Splunk Search 05-02-2016
0 4
0
4
lordadmiral
Hi there, I have events which indicate opening and closing of an event. I want to see the amount of open events (th...
by lordadmiral New Member in Splunk Search 05-02-2016
0 4
0
4
hcannon
I feel like this should be easily done with eval, but it doesn't seem to be working for me! I have data sets that in...
by hcannon Path Finder in Splunk Search 04-30-2016
0 3
0
3
Lucas_K
Is there a method that I can provide the app context to a cli export search? I have a savedsearch called "GetLogins"...
by Lucas_K Motivator in Splunk Search 04-30-2016
0 1
0
1
arkonner
Should be possible to determine the resource in use by each search or dashboard (mem, cpu...)
by arkonner Path Finder in Splunk Search 04-30-2016
1 1
1
1
maxiva01
Hi, Task: 2 different log files (source types). I want to find all transactions from first payload and check which o...
by maxiva01 Engager in Splunk Search 04-29-2016
1 1
1
1
r34220
I have the following search... index="server_inventory" NOT "OS Name"=enclosure NOT "OS Name"=na NOT "OS Name"=unk...
by r34220 Explorer in Splunk Search 04-29-2016
0 2
0
2
Kukkadapu
Hi, Do you know of any tool to beautify/format a Splunk search to make it readable? Thanks.
by Kukkadapu Path Finder in Splunk Search 04-29-2016
0 4
0
4
dsmc_adv
Hi, We want the following search, but for each span of time: index=test_index | chart sum(REQTIME) as reqtime by ur...
by dsmc_adv Path Finder in Splunk Search 04-29-2016
0 8
0
8
bharrell
I have a simple table showing the dropped links on my switches: this is generated by the following search: DellEven...
by bharrell Path Finder in Splunk Search 04-29-2016
1 2
1
2
rkoster
So I have this search that I believe makes other searches from a list of regexs that I have stored in a csv. [ | inp...
by rkoster Explorer in Splunk Search 04-29-2016
0 5
0
5
nts_cseidl
Dear Splunkers, I have an index with Windows DNS Logs, where I extract the requested record in to a field --> dns do...
by nts_cseidl New Member in Splunk Search 04-29-2016
0 1
0
1
mortenb123
Hi This is my current search: chart count(TYPE) over TYPE by _time I only get 10-12 columns, the rest is put in O...
by mortenb123 Path Finder in Splunk Search 04-29-2016
0 3
0
3
bworrellZP
So I did a search by one IP in this range, and I get matches. My thought was to try searching for any IP in the whol...
by bworrellZP Communicator in Splunk Search 04-29-2016
0 6
0
6
thisissplunk
I want to do something like this: index=* sourcetype=files (earliest="1459455814.788302" filename=hello.exe) OR (ear...
by thisissplunk Builder in Splunk Search 04-28-2016
0 6
0
6
lwilliams5301
Would like to index web page contents in Splunk. Is this possible?
by lwilliams5301 New Member in Splunk Search 04-28-2016
0 2
0
2
reachskhm
Need a way to select only specific events from the list of events, so here the example I have a query on iis logs whi...
by reachskhm New Member in Splunk Search 04-28-2016
0 8
0
8
rwells
When I run this search, everything runs fine, but I don't understand why my visualization tab does not populate. Does...
by rwells Engager in Splunk Search 04-28-2016
1 1
1
1
ketanadkar1
Hi I have extracted 2 fields from log file & now I have to show a chart based on these 2 values. How can I do that? ...
by ketanadkar1 New Member in Splunk Search 04-28-2016
0 2
0
2
maximus_reborn
I am getting the below error in the search.log when I am extracting hive data in Splunk. I am using thrift metastore ...
by maximus_reborn Path Finder in Splunk Search 04-28-2016
1 8
1
8
sreejithchmd
Hi, I have server message logs sending to Splunk. Eg 1000 servers sending logs at a time. Wanted to find a way to ...
by sreejithchmd New Member in Splunk Search 04-28-2016
0 2
0
2
javaj2e11
How to extract fdd1895d-63e9-4be2-b78b-ec784b00754f from below: 2016-04-28 15:12:56,939 GMT [transaction_id=20160428...
by javaj2e11 New Member in Splunk Search 04-28-2016
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...