Splunk Search

Splunk Search
Community Activity
jaho_splunk
If I leave the Restrict search terms option empty and only make searchable indexes available via the Selected search ...
by jaho_splunk Engager in Splunk Search 04-11-2016
0 1
0
1
denniscastillo
Need assistance with Regex to parse the user from the event below. I'm looking to get the value of a string between =...
by denniscastillo New Member in Splunk Search 04-11-2016
0 2
0
2
vysean
Not sure how or if this can be fixed, but iplocation is reporting Germany as the country for datacenter.fiberdc.com.t...
by vysean Explorer in Splunk Search 04-11-2016
0 2
0
2
jevenson
I'm trying to group IP address results in CIDR format. Most likely I'll be grouping in /24 ranges. Is there an easy w...
by jevenson Path Finder in Splunk Search 04-11-2016
1 4
1
4
ronj_clark
Background: My windows AD users are in index "windersAD". All of their web traffic is logged in index "wsa". I would...
by ronj_clark Explorer in Splunk Search 04-11-2016
0 3
0
3
tedder
This should be an easy one, how do I get a list of my top users accessing Splunk?
by tedder Communicator in Splunk Search 04-11-2016
1 4
1
4
olheiser01
Here is an example of the log I am dealing with: <123 Main St> <456 Center St.> I'd like to simply extract the nam...
by olheiser01 New Member in Splunk Search 04-11-2016
0 4
0
4
yahoohunk
Each log entry contains some json. There is a field that is an array. I want to count the items in that array. Exa...
by yahoohunk Explorer in Splunk Search 04-11-2016
0 2
0
2
a212830
Hi, I need to run a compare against the count of two different searches - how would I do that? I'm counting the num...
by a212830 Champion in Splunk Search 04-11-2016
0 14
0
14
polymorphic
I need to change sharing and permissions for a lookup table file using the REST API. I have been searching high and ...
by polymorphic Communicator in Splunk Search 04-11-2016
3 23
3
23
mszebenyi_splun
Is there a way to dynamically assign chart labels using a search? My search ends with a timechart values(foo) as bar,...
by mszebenyi_splun Splunk Employee Splunk Employee in Splunk Search 04-11-2016
2 3
2
3
RogueMrSmith
Hello Everyone, With my current search I am able to display results in three rows, however, I need two of the rows t...
by RogueMrSmith Engager in Splunk Search 04-11-2016
0 2
0
2
apurva1707
For example: source = D:\Users\ABC\Desktop\splunk\abc.log I have extracted the part of string I wanted using (?\w+...
by apurva1707 New Member in Splunk Search 04-11-2016
0 1
0
1
asingla
I have a submit button module containing search module and I want to execute the search only when user clicks on the ...
by asingla Communicator in Splunk Search 04-10-2016
0 6
0
6
kuga_mbsd
Hi there, My external program is retrieving the data and creating lookup table every night. The files are stored lik...
by kuga_mbsd New Member in Splunk Search 04-10-2016
0 7
0
7
NickJLange
Why does my query blow-up in size with a join? I have a query which without a join (for further analysis) runs in 2M...
by NickJLange Explorer in Splunk Search 04-10-2016
0 4
0
4
DavidHourani
Hello dear splunkers, Can anyone tell me why these two commands give different results ? sourcetype=shopping date="...
by DavidHourani Super Champion in Splunk Search 04-09-2016
0 12
0
12
tissparkle
hi, I would like to build a graph with these values: a 100 b 97,56 c 99,34 my issue is when i try to see a graph.. ...
by tissparkle Explorer in Splunk Search 04-09-2016
0 4
0
4
athorat
Hi we are using fs_notification and monitoring a specific path. I have a field called path which has the following v...
by athorat Communicator in Splunk Search 04-09-2016
0 3
0
3
ibekacyril
This should be an easy thing to do but obviously, I am missing it. I need to extract "cannot be located" c.f.a.k.m....
by ibekacyril Explorer in Splunk Search 04-09-2016
0 7
0
7
Makinde
Hello, Like the title says, I have the search criteria pretty nailed down, however, I would like to do a count so on...
by Makinde New Member in Splunk Search 04-09-2016
0 6
0
6
amoldesai
Hi, Here are the three sources that I have for the below query that I need to optimize : a) tech_detail.gz b) group_...
by amoldesai Explorer in Splunk Search 04-08-2016
0 2
0
2
Aaron_Fogarty
I have a CSV file uploaded as a lookup. I am using the userID from my search with the lookup, but for some reason, th...
by Aaron_Fogarty Path Finder in Splunk Search 04-08-2016
0 6
0
6
waldez
I am capturing events every minute. Within the events, there is a continuously compounding field: "FlowTotal_Running...
by waldez Engager in Splunk Search 04-08-2016
0 3
0
3
tkwaller
I am trying to test a sedcmd command, inline, that Im going to add. I am finding a string and replacing it with a fie...
by tkwaller Builder in Splunk Search 04-08-2016
0 7
0
7
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...