Splunk Search

Splunk Search
Community Activity
chris
Does anyone know what the metric 'active_searches' in remote_searches.log represents? This is a sample log event: ...
by chris Motivator in Splunk Search 03-25-2016
1 1
1
1
sideview
We frequently have search results where for one or more numeric fields, each row might have only one value for the nu...
by SplunkTrust SplunkTrust in Splunk Search 03-25-2016
1 5
1
5
senkumar
hi , i want to create a dashboard which will show the individual response time for the respective webservice. i hav...
by senkumar New Member in Splunk Search 03-25-2016
0 2
0
2
smiehe
I'd like to count the occurrences of a certain string for a specific server. Right now I'm using: host="host.test.co...
by smiehe New Member in Splunk Search 03-25-2016
0 4
0
4
saimack
Please help me in this query. --I have a query which produces result like uid user ip 1001 xyz 1.1.1.1 1002 abc ...
by saimack New Member in Splunk Search 03-25-2016
0 3
0
3
sandeep_splunk
Status transition is not working from "New" to other statuses other than "Resolved". When we try to edit the transiti...
by sandeep_splunk Engager in Splunk Search 03-24-2016
0 1
0
1
mhamano
I am trying to calculate hourly decline percentage rates for several different payment gateways. The percentage is ...
by mhamano Explorer in Splunk Search 03-24-2016
0 2
0
2
windbishn
By default, data on all sites will be collected. If only data on specific sites is required please edit the 'allSites...
by windbishn Explorer in Splunk Search 03-24-2016
0 2
0
2
smhsplunk
I tried to use regex on inputlookup csv file, but seems that although Splunk regex works fine on search but it doesnt...
by smhsplunk Communicator in Splunk Search 03-24-2016
0 3
0
3
szabados
How can I provide field values to the startswith argument of the transaction command? Like I would do in a search: ...
by szabados Communicator in Splunk Search 03-24-2016
0 1
0
1
splunkgk
need to identify high cpu usage searches and stop them.
by splunkgk Path Finder in Splunk Search 03-24-2016
0 2
0
2
Reosoul
Given bunch of results in a format like: 6d2112effbe814f41ef6a6b984221c2490ef5112b70d394c074bb1427561556c some.site....
by Reosoul New Member in Splunk Search 03-24-2016
0 3
0
3
SPETZD11
I have a log file multiple service requests/responses that I am logging in JSON. I am able to take the those requests...
by SPETZD11 New Member in Splunk Search 03-24-2016
0 4
0
4
Makinde
Hello, I am not sure what I am doing wrong but logically I feel this search string should work however it isn't work...
by Makinde New Member in Splunk Search 03-24-2016
0 5
0
5
landen99
With the simplest search: index=checkpoint action=accept | head 1 The normalizedSearch (under Job Inspect, 8.34s) ...
by landen99 Motivator in Splunk Search 03-24-2016
1 10
1
10
ewanbrown
Hi I have a query that produces some output like this: ID server_a.1 server_a.2 server_b.1 server...
by ewanbrown Path Finder in Splunk Search 03-24-2016
0 5
0
5
wweiland
I'm having a problem where I have 5 indexers and 1 search head. All 5 show up in the search peers under distributed ...
by wweiland Contributor in Splunk Search 03-24-2016
0 5
0
5
tgdvopab
I want to use a dashed line in my timechart. I know that this is possible with advenced XML. But is this also possibl...
by tgdvopab Path Finder in Splunk Search 03-24-2016
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please with something that I just don't understand. I'm using th...
by IRHM73 Motivator in Splunk Search 03-24-2016
0 4
0
4
zeophlite
Hi I'm looking to extract a specific subset of events in my Splunk data. _time=3:01 type=update user=user2 _time=3:...
by zeophlite New Member in Splunk Search 03-23-2016
0 5
0
5
ericdelacruz
I have a search that is showing the data I want, but I want to isolate it to a specific team and not show all results...
by ericdelacruz Engager in Splunk Search 03-23-2016
0 1
0
1
splunkman341
Hi all, I currently have a search that I need a little tweaking to get something else that I want. So the current s...
by splunkman341 Communicator in Splunk Search 03-23-2016
0 4
0
4
the_wolverine
If you are using deny (NOT) in your srchFilter be aware that inheritance of multiple roles with negative filters will...
by the_wolverine Champion in Splunk Search 03-23-2016
1 1
1
1
vrmandadi
Hello Experts, I have the below two fields EML_REQUEST_TIME: 2016-01-19 15:44:00.749 +00:00 EML_RESPONSE_TIME: 2...
by vrmandadi Builder in Splunk Search 03-23-2016
0 13
0
13
JoeSco27
I am seeing logs in an instance of splunk, but i am unsure where the monitoring is set up. I checked my serverclass....
by JoeSco27 Communicator in Splunk Search 03-23-2016
0 4
0
4
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...