Splunk Search

Splunk Search
Community Activity
packet_hunter
Scenario: I am extracting sender domains with the following code: index=mail sourcetype=xemail [search index=m...
by packet_hunter Contributor in Splunk Search 02-18-2016
0 1
0
1
diliptmonson
Hi, I need to search for an element A present in one of the fields let's say field 1. Some of the values present fo...
by diliptmonson Explorer in Splunk Search 02-18-2016
0 2
0
2
splunker9999
Hi, Can someone please advise, how we can set different colors in a dashboard for each single row? Our data looks ...
by splunker9999 Path Finder in Splunk Search 02-18-2016
0 3
0
3
johnraftery
We have certain source types where there is only data from months ago. When putting this into a timechart, the chart ...
by johnraftery Communicator in Splunk Search 02-18-2016
0 4
0
4
timgirgis
I want to create a stacked bar graph showing 2 columns stacked by department: 1 column is the total time and the seco...
by timgirgis Explorer in Splunk Search 02-18-2016
1 2
1
2
andrei1bc
My search : index=test | where Value>=95 | stats count(Value) as Events by Host The result : if there are ...
by andrei1bc Communicator in Splunk Search 02-18-2016
0 4
0
4
nikkkc
In my search, I calculate some values, but if I reach the 10000 result limit, I get wrong results. I would like chang...
by nikkkc Path Finder in Splunk Search 02-18-2016
0 6
0
6
dwin02
Hi Splunk Support, I'm trying to create a table based on certain fields from the Output Results: Search String: ...
by dwin02 Explorer in Splunk Search 02-17-2016
0 13
0
13
nickleli
Hi Everyone, Our setup is a universal forwarder --> heavy forwarder --> indexer. I am looking to modify a universal...
by nickleli New Member in Splunk Search 02-17-2016
0 5
0
5
MichaelCohen829
Hello, Could someone please delineate the difference between these two earliest commands: earliest=-2d earliest=-2...
by MichaelCohen829 Explorer in Splunk Search 02-17-2016
0 8
0
8
athorat
Want to extract only /ubi-v2/api/scoresummary from the below mentioned event in a field. Rex used: `| rex "(?<remo...
by athorat Communicator in Splunk Search 02-17-2016
0 1
0
1
angelo_fazzina
This is my search so far. sourcetype="spam" |eventstats count as total|search block_code="*" |eventstats count as b...
by angelo_fazzina Engager in Splunk Search 02-17-2016
0 6
0
6
jhayIV
I have the following string 2016-02-17 field and I would like to extract the 02 between the hyphens. Does someone hav...
by jhayIV Engager in Splunk Search 02-17-2016
0 3
0
3
splunker12er
|metadata type=hosts earliest=-1d latest=now This displays the overall eventcounts for the available hosts but not ...
by splunker12er Motivator in Splunk Search 02-17-2016
1 3
1
3
Securitas
I'm trying to search for some IPs of interest within the Rapid 7 App for Splunk Enterprise. Is there a way to do that...
by Securitas Engager in Splunk Search 02-17-2016
0 1
0
1
fisuser1
Is there a way to create a transforms for separate values while not breaking current regex instances that are working...
by fisuser1 Contributor in Splunk Search 02-17-2016
0 5
0
5
jshellman
I have a search, something like this: search stuff | rex "extract cat" | rex "extract field2" | rex "ext...
by jshellman Engager in Splunk Search 02-17-2016
0 3
0
3
rainerzufall
Hello, We would like to match all sources except the ones including /splunk/ in props.conf. Example: No match for /...
by rainerzufall Path Finder in Splunk Search 02-17-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the search below to extract the date when Splu...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 7
0
7
IRHM73
Hi, I wonder whether someone may be able to help me please. I've put together the following form. <form> <lab...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 3
0
3
max_y0586
I have two searches with the result as displayed below. Here I want to find the service related to each activity base...
by max_y0586 New Member in Splunk Search 02-17-2016
0 2
0
2
taraksinha
Hello, How can i display latest dates of searches with time frame, I need to filter top search in a month, any optio...
by taraksinha New Member in Splunk Search 02-17-2016
0 16
0
16
taraksinha
A user no longer exists in Splunk, but their reports and dashboards are still there. Is there a search to fix this?
by taraksinha New Member in Splunk Search 02-17-2016
0 2
0
2
szabados
I want to replace the * character in a string with the replace command. How do I apply the * by escaping it, not to r...
by szabados Communicator in Splunk Search 02-17-2016
0 2
0
2
greich
I need to trace the data from the originating forwarder through intermediate forwarders or directly onto indexers. I ...
by greich Communicator in Splunk Search 02-17-2016
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...