Splunk Search

Splunk Search
Community Activity
r34220
I have the following search... index="server_inventory" NOT "OS Name"=enclosure NOT "OS Name"=na NOT "OS Name"=unk...
by r34220 Explorer in Splunk Search 04-29-2016
0 2
0
2
Kukkadapu
Hi, Do you know of any tool to beautify/format a Splunk search to make it readable? Thanks.
by Kukkadapu Path Finder in Splunk Search 04-29-2016
0 4
0
4
dsmc_adv
Hi, We want the following search, but for each span of time: index=test_index | chart sum(REQTIME) as reqtime by ur...
by dsmc_adv Path Finder in Splunk Search 04-29-2016
0 8
0
8
bharrell
I have a simple table showing the dropped links on my switches: this is generated by the following search: DellEven...
by bharrell Path Finder in Splunk Search 04-29-2016
1 2
1
2
rkoster
So I have this search that I believe makes other searches from a list of regexs that I have stored in a csv. [ | inp...
by rkoster Explorer in Splunk Search 04-29-2016
0 5
0
5
nts_cseidl
Dear Splunkers, I have an index with Windows DNS Logs, where I extract the requested record in to a field --> dns do...
by nts_cseidl New Member in Splunk Search 04-29-2016
0 1
0
1
mortenb123
Hi This is my current search: chart count(TYPE) over TYPE by _time I only get 10-12 columns, the rest is put in O...
by mortenb123 Path Finder in Splunk Search 04-29-2016
0 3
0
3
bworrellZP
So I did a search by one IP in this range, and I get matches. My thought was to try searching for any IP in the whol...
by bworrellZP Communicator in Splunk Search 04-29-2016
0 6
0
6
thisissplunk
I want to do something like this: index=* sourcetype=files (earliest="1459455814.788302" filename=hello.exe) OR (ear...
by thisissplunk Builder in Splunk Search 04-28-2016
0 6
0
6
lwilliams5301
Would like to index web page contents in Splunk. Is this possible?
by lwilliams5301 New Member in Splunk Search 04-28-2016
0 2
0
2
reachskhm
Need a way to select only specific events from the list of events, so here the example I have a query on iis logs whi...
by reachskhm New Member in Splunk Search 04-28-2016
0 8
0
8
rwells
When I run this search, everything runs fine, but I don't understand why my visualization tab does not populate. Does...
by rwells Engager in Splunk Search 04-28-2016
1 1
1
1
ketanadkar1
Hi I have extracted 2 fields from log file & now I have to show a chart based on these 2 values. How can I do that? ...
by ketanadkar1 New Member in Splunk Search 04-28-2016
0 2
0
2
maximus_reborn
I am getting the below error in the search.log when I am extracting hive data in Splunk. I am using thrift metastore ...
by maximus_reborn Path Finder in Splunk Search 04-28-2016
1 8
1
8
sreejithchmd
Hi, I have server message logs sending to Splunk. Eg 1000 servers sending logs at a time. Wanted to find a way to ...
by sreejithchmd New Member in Splunk Search 04-28-2016
0 2
0
2
javaj2e11
How to extract fdd1895d-63e9-4be2-b78b-ec784b00754f from below: 2016-04-28 15:12:56,939 GMT [transaction_id=20160428...
by javaj2e11 New Member in Splunk Search 04-28-2016
0 1
0
1
icquintos
I have an index with multiple fields, however one of my field could contain multiple quotes. Id="0001", Message="Th...
by icquintos New Member in Splunk Search 04-28-2016
0 7
0
7
sukundur
I am trying to get two files milli seconds from one line and merchant id from another line from the same tomcat tr...
by sukundur Engager in Splunk Search 04-28-2016
0 11
0
11
trunghung
I am try to write some query[ies] so that I find user who had done action A AFTER they did action B . the time span...
by trunghung Path Finder in Splunk Search 04-28-2016
0 6
0
6
renanprado96
Since day 23 so far, Splunk is not creating the date_month. It has not changed the date model is the same, as I verif...
by renanprado96 Path Finder in Splunk Search 04-28-2016
0 2
0
2
rwmilligan
I found another thread where the user was trying something similar, with this string: index= | transaction src_ip,u...
by rwmilligan Explorer in Splunk Search 04-28-2016
1 4
1
4
Amandeepsin
index="sc-general" info AND(heartbeat OR Successfully) NOT(created) | rex ":\s+(?\w+)" | eval entry_type=if(entry_t...
by Amandeepsin New Member in Splunk Search 04-28-2016
0 2
0
2
rndp89
I am using the search below to shunt "ORA-00001" from a set of log files. This search works fine for just one log fil...
by rndp89 Explorer in Splunk Search 04-28-2016
1 5
1
5
hkaiser
We use several scheduled reports to ensure that we do not have any duplicate events in our indexes. Our searches look...
by hkaiser Path Finder in Splunk Search 04-28-2016
0 23
0
23
horsefez
Hello fellow splunkers, I'm currently charting around with webserver access logs. My current search string looks ...
by horsefez Motivator in Splunk Search 04-28-2016
0 7
0
7
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors