Splunk Search

Splunk Search
Community Activity
cmeyers
I would like to have a panel that shows total logs per hour over 24 hours in a column graph, and show the average log...
by cmeyers Explorer in Splunk Search 03-26-2016
0 6
0
6
CYBR_AH
Hi All, I'm trying to search for start up and shutdown message of AWS instances and build a nice table. On my test i...
by CYBR_AH Explorer in Splunk Search 03-26-2016
0 3
0
3
CYBR_AH
Hi Community, I'm trying to figure out how to get the signature and signature id to their own fields. This has been ...
by CYBR_AH Explorer in Splunk Search 03-25-2016
0 6
0
6
chris
Does anyone know what the metric 'active_searches' in remote_searches.log represents? This is a sample log event: ...
by chris Motivator in Splunk Search 03-25-2016
1 1
1
1
sideview
We frequently have search results where for one or more numeric fields, each row might have only one value for the nu...
by SplunkTrust SplunkTrust in Splunk Search 03-25-2016
1 5
1
5
senkumar
hi , i want to create a dashboard which will show the individual response time for the respective webservice. i hav...
by senkumar New Member in Splunk Search 03-25-2016
0 2
0
2
smiehe
I'd like to count the occurrences of a certain string for a specific server. Right now I'm using: host="host.test.co...
by smiehe New Member in Splunk Search 03-25-2016
0 4
0
4
saimack
Please help me in this query. --I have a query which produces result like uid user ip 1001 xyz 1.1.1.1 1002 abc ...
by saimack New Member in Splunk Search 03-25-2016
0 3
0
3
sandeep_splunk
Status transition is not working from "New" to other statuses other than "Resolved". When we try to edit the transiti...
by sandeep_splunk Engager in Splunk Search 03-24-2016
0 1
0
1
mhamano
I am trying to calculate hourly decline percentage rates for several different payment gateways. The percentage is ...
by mhamano Explorer in Splunk Search 03-24-2016
0 2
0
2
windbishn
By default, data on all sites will be collected. If only data on specific sites is required please edit the 'allSites...
by windbishn Explorer in Splunk Search 03-24-2016
0 2
0
2
smhsplunk
I tried to use regex on inputlookup csv file, but seems that although Splunk regex works fine on search but it doesnt...
by smhsplunk Communicator in Splunk Search 03-24-2016
0 3
0
3
szabados
How can I provide field values to the startswith argument of the transaction command? Like I would do in a search: ...
by szabados Communicator in Splunk Search 03-24-2016
0 1
0
1
splunkgk
need to identify high cpu usage searches and stop them.
by splunkgk Path Finder in Splunk Search 03-24-2016
0 2
0
2
Reosoul
Given bunch of results in a format like: 6d2112effbe814f41ef6a6b984221c2490ef5112b70d394c074bb1427561556c some.site....
by Reosoul New Member in Splunk Search 03-24-2016
0 3
0
3
SPETZD11
I have a log file multiple service requests/responses that I am logging in JSON. I am able to take the those requests...
by SPETZD11 New Member in Splunk Search 03-24-2016
0 4
0
4
Makinde
Hello, I am not sure what I am doing wrong but logically I feel this search string should work however it isn't work...
by Makinde New Member in Splunk Search 03-24-2016
0 5
0
5
landen99
With the simplest search: index=checkpoint action=accept | head 1 The normalizedSearch (under Job Inspect, 8.34s) ...
by landen99 Motivator in Splunk Search 03-24-2016
1 10
1
10
ewanbrown
Hi I have a query that produces some output like this: ID server_a.1 server_a.2 server_b.1 server...
by ewanbrown Path Finder in Splunk Search 03-24-2016
0 5
0
5
wweiland
I'm having a problem where I have 5 indexers and 1 search head. All 5 show up in the search peers under distributed ...
by wweiland Contributor in Splunk Search 03-24-2016
0 5
0
5
tgdvopab
I want to use a dashed line in my timechart. I know that this is possible with advenced XML. But is this also possibl...
by tgdvopab Path Finder in Splunk Search 03-24-2016
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please with something that I just don't understand. I'm using th...
by IRHM73 Motivator in Splunk Search 03-24-2016
0 4
0
4
zeophlite
Hi I'm looking to extract a specific subset of events in my Splunk data. _time=3:01 type=update user=user2 _time=3:...
by zeophlite New Member in Splunk Search 03-23-2016
0 5
0
5
ericdelacruz
I have a search that is showing the data I want, but I want to isolate it to a specific team and not show all results...
by ericdelacruz Engager in Splunk Search 03-23-2016
0 1
0
1
splunkman341
Hi all, I currently have a search that I need a little tweaking to get something else that I want. So the current s...
by splunkman341 Communicator in Splunk Search 03-23-2016
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors