Splunk Search

Splunk Search
Community Activity
awurster
just checking if this is true.. given a custom command i write with a single argument: ... | mycommand arg1="this is...
by awurster Contributor in Splunk Search 03-29-2016
2 9
2
9
vamseepotluri
HI, I am trying to write a regex to split these event lines into multiple fields. Can some one please help me how t...
by vamseepotluri New Member in Splunk Search 03-29-2016
0 7
0
7
anshumandas
category area period date count cats A1 20161 15-01-2016 120500 cats A1 20162 ...
by anshumandas New Member in Splunk Search 03-29-2016
0 3
0
3
crypt0
Hi, I am trying to do the following, but haven't been able to figure out how. For a particular event, I want to t...
by crypt0 New Member in Splunk Search 03-29-2016
0 3
0
3
sankarms
Whenever someone calls my rest service, the event gets logged into the logs like so: callerId:1324 How do I create...
by sankarms Explorer in Splunk Search 03-29-2016
0 2
0
2
reswob4
We have log entries similar to below and while I can write a regex expression to parse out all the kv pairs separated...
by reswob4 Builder in Splunk Search 03-29-2016
1 3
1
3
phspec
Hi, I'm trying to return some results with the AppID that is being searched. My current search does everything I wa...
by phspec Explorer in Splunk Search 03-29-2016
0 10
0
10
tasqn
We recently upgraded to 6.3 and I have been toying with using eval and search event handlers. In one of my dashboards...
by tasqn New Member in Splunk Search 03-29-2016
0 2
0
2
mikev
We have dashboards that show the average of user work for the last month this could be for any of the various departm...
by mikev Path Finder in Splunk Search 03-29-2016
0 3
0
3
sfellin
The DB Connect 1 page only has v1.2.2 available for download (indicates to use 1.1.7 for Java 6 but no link); I have ...
by sfellin Engager in Splunk Search 03-29-2016
0 1
0
1
jwalzerpitt
I am trying to create an alert which will notify me when the percentage change in the delta/difference of events exce...
by jwalzerpitt Influencer in Splunk Search 03-29-2016
0 3
0
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to compare the apps set up in my four environ...
by IRHM73 Motivator in Splunk Search 03-29-2016
0 6
0
6
cphair
Hello, I have some data for which I calculate hourly avg/max/stdev into a summary index, then calculate daily summar...
by cphair Builder in Splunk Search 03-29-2016
0 2
0
2
David_Hodgson
I have a system with customers interacting with a catalogue, stepping through the menus, searching etc. I can chunk ...
by David_Hodgson Engager in Splunk Search 03-29-2016
0 6
0
6
chetanchauhan
Hi, I have deployed splunk to log data of users who are logging onto servers (unix and windows). I want to create a...
by chetanchauhan New Member in Splunk Search 03-29-2016
0 5
0
5
sk_subhani
Hi, I am trying to run below query and the scenario is here. This is not returning any results though match exists. C...
by sk_subhani New Member in Splunk Search 03-29-2016
0 2
0
2
jamesvz84
I try the following search: | loadjob savedsearch="admin:app1:app1_view1" | fields hostname This returns "hostname...
by jamesvz84 Communicator in Splunk Search 03-29-2016
0 2
0
2
jalfrey
one of the values in my log is sent and received I believe it's bytes. I would like to display those as Kb and Mb. Us...
by jalfrey Communicator in Splunk Search 03-28-2016
1 6
1
6
blueyuan
Hi All, I am studying splunk recently and need help about some question, thanks. When I want to search one key word a...
by blueyuan New Member in Splunk Search 03-28-2016
0 2
0
2
vrmandadi
Hello, I am finding difficulty to use the mvindex command to remove all the characters after the second period (.). ...
by vrmandadi Builder in Splunk Search 03-28-2016
0 4
0
4
j_williams
Hello, Using Splunk Enterprise 6.2 I am running a prediction using 30+ historical days of data to predict the next ...
by j_williams Explorer in Splunk Search 03-28-2016
0 3
0
3
a212830
Hi, Are processes that contain "rt_scheduler" real-time scheduled searches? Example: splunk 15005 75443 0 10...
by a212830 Champion in Splunk Search 03-28-2016
0 3
0
3
burzynskih
I am trying to search for data that is in a .csv lookup file and NOT in Splunk. My issue is that my subsearch stops (...
by burzynskih Engager in Splunk Search 03-28-2016
0 5
0
5
reachskhm
On iis logs, suppose I have 60000 transactions per 24 hours. How can I get a random sample of say 5000 events? I need...
by reachskhm New Member in Splunk Search 03-28-2016
0 4
0
4
eandrus
I have a dashboard query that returns fields of a log file, and I'm only interested if the difference in time between...
by eandrus Engager in Splunk Search 03-28-2016
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...