Splunk Search

Splunk Search
Community Activity
PreetiKa
I have a search which uses an eval expression for a calculation. eval UsedMemory= (Avg_Memory/Total_Memory) I wan...
by PreetiKa Engager in Splunk Search 04-21-2016
0 4
0
4
BT_Neophyte
I'm having an issue with certain events that contain values with quotation marks in them. This is causing Splunk to ...
by BT_Neophyte Explorer in Splunk Search 04-20-2016
3 2
3
2
pgadhari
Hi All, I want a single regex for multiple types of events getting generated in my access logs. I have written the f...
by pgadhari Builder in Splunk Search 04-20-2016
0 5
0
5
CSMounsey01
I'm trying to create a single chart showing % Processor Time and % User Time by host My example so far: host="pvaw...
by CSMounsey01 New Member in Splunk Search 04-20-2016
0 1
0
1
jl_Splunk
Hello All, Does anyone know of an efficient method to deploy Splunk UF v6.3.3 with Splunk_TA_Windows to several hund...
by jl_Splunk Engager in Splunk Search 04-20-2016
0 2
0
2
danielpops
I have an alert named e.g. "My Alert". How do I search for it in Splunk using the REST API? I can successfully sear...
by danielpops Engager in Splunk Search 04-20-2016
2 5
2
5
bestpa
Hi everyone, I have a monitored file that is appended to by a cron job. Sometimes splunk checks the file in the mi...
by bestpa Explorer in Splunk Search 04-20-2016
0 11
0
11
proletariat99
If I leave my Splunk WebUI dormant for a bit (I think about 30m), I get the following error message with scary, red, ...
by proletariat99 Communicator in Splunk Search 04-20-2016
0 2
0
2
intelsubham
Need to sum a field value with a condition. For example, every log contains a field value pair "failedcount" with int...
by intelsubham Explorer in Splunk Search 04-20-2016
0 3
0
3
pkeller
Recently started encountering issues where one node of a 4 node search head cluster starts reporting: SHPMaster -...
by pkeller Contributor in Splunk Search 04-20-2016
0 1
0
1
ccsfdave
I have been through the field extractor, answers.splunk.com, and the interwebs looking for help on this one. So our ...
by ccsfdave Builder in Splunk Search 04-20-2016
2 5
2
5
ethanrulez80
I currently get events that shows bytes received from a router. What I'm trying to do is use stats to obtained a sum ...
by ethanrulez80 New Member in Splunk Search 04-20-2016
0 1
0
1
tippy
I have an entry in /var/log/messages which contains a string of multiple sets of 6 keypairs (pairdelim="," kvdelim=":...
by tippy New Member in Splunk Search 04-20-2016
0 1
0
1
alon7786
Hi, Is there a way to use fields in rex expression? I would like to do something like this: | eval num=1 | accum n...
by alon7786 New Member in Splunk Search 04-20-2016
0 2
0
2
evelenke
Hi Splunkers, I have pie chart with 2 values for the field state: "Active" and "Inactive" appended by percentage and...
by evelenke Contributor in Splunk Search 04-20-2016
0 7
0
7
ks2211
Hi All, I'm trying to build a mini SDK for the REST API using Golang (focusing on the search/saved search endpoints ...
by ks2211 Engager in Splunk Search 04-20-2016
0 8
0
8
xiangtaner
Hi, Here is an example. I have a list of IP addresses and for each IP address I need to find out all the hosts assig...
by xiangtaner Path Finder in Splunk Search 04-20-2016
1 7
1
7
the_wolverine
What is the syntax, please?
by the_wolverine Champion in Splunk Search 04-20-2016
1 5
1
5
sureshsala
I need help with the regular expression for field extraction of login status: Successful: source="/var/log/secure"...
by sureshsala Explorer in Splunk Search 04-20-2016
0 4
0
4
BaptVe
Hello, I'm searching to show all source from indexes on a search form. I'm able to extract the list of indexes with...
by BaptVe Path Finder in Splunk Search 04-19-2016
0 4
0
4
xiangtaner
Hi, I have two pieces of data: 1. a list of IP addresses stored in a lookup table host2ips.csv; 2. a source where IP...
by xiangtaner Path Finder in Splunk Search 04-19-2016
0 2
0
2
HattrickNZ
this is my search: | makeresults count=2 | eval start=relative_time(now(),"@d") | eval start_string=strftime(star...
by HattrickNZ Motivator in Splunk Search 04-19-2016
0 2
0
2
Kukkadapu
Hi, I have multiple columns (number of columns may vary) and wanted to search a string if it exists in any of the c...
by Kukkadapu Path Finder in Splunk Search 04-19-2016
0 6
0
6
ramaswamy
From Splunk Web, when I run a search, I receive the following message Search not executed: The minimum free disk spa...
by ramaswamy New Member in Splunk Search 04-19-2016
0 4
0
4
ddrillic
I have a large results set of a search which I would like to store as a lookup table. How can I do that?
by ddrillic Ultra Champion in Splunk Search 04-19-2016
0 6
0
6
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...