Splunk Search

Splunk Search
Community Activity
jwalzerpitt
I have events in which Field1 contains multiple values, but I only need to look for two values (foo AND bar) and tie ...
by jwalzerpitt Influencer in Splunk Search 02-24-2016
0 5
0
5
ahmedhassanean
Hi all, May I know please if it possible to poll events timestamp from File name, and if it's, possible how to do th...
by ahmedhassanean Explorer in Splunk Search 02-24-2016
0 1
0
1
cmerriman
If I'm looking at Last 30 Days of data for one event and doing a timechart, a couple of days come up with 0 as result...
by cmerriman Super Champion in Splunk Search 02-24-2016
0 8
0
8
ctaf
Hello, I have two existing fields: mailto, mailfrom. I also have a lookup with 2 fields: Mail and Country I would l...
by ctaf Contributor in Splunk Search 02-24-2016
0 17
0
17
smart_r
I would like to extract data per month, but only within a certain time frame. Say: Extract all data from January, b...
by smart_r New Member in Splunk Search 02-24-2016
0 2
0
2
EricLloyd79
According to the documentation here, http://docs.splunk.com/Documentation/Splunk/6.0.2/Knowledge/Designdatamodelobjec...
by EricLloyd79 Builder in Splunk Search 02-23-2016
1 9
1
9
vrmandadi
link textHello Experts, Attached is the sample JSON file which I am trying to upload to Splunk.I have uploaded it by...
by vrmandadi Builder in Splunk Search 02-23-2016
0 12
0
12
Stevelim
I have a set of time series data that looks like this: Date Type Data ================== 12 A 1 12 B 2 12 ...
by Stevelim Communicator in Splunk Search 02-23-2016
1 6
1
6
bentuit
I've been experimenting with a number of different settings, but here are my current search args: JobExportArgs sear...
by bentuit New Member in Splunk Search 02-23-2016
0 1
0
1
cesar_tomas
Hello everyone, I have a problem with my timestamp fields. Splunk doesn't recognize the timestamp because it comes f...
by cesar_tomas Explorer in Splunk Search 02-23-2016
0 3
0
3
alex1895
Sample given from Splunk: ... | eval wd=lower(Day) | eval sort_field=case(wd=="monday",1, wd=="tuesday",2, wd=="w...
by alex1895 Path Finder in Splunk Search 02-23-2016
0 1
0
1
SQservicedesk
How do I sort a column of time in 12 hour format with AM / PM on the end? I have tried using eval with the _time fie...
by SQservicedesk Explorer in Splunk Search 02-23-2016
0 4
0
4
jmedved
I am trying to report on user web activity to a particular category as well as list the URLs in that category. I have...
by jmedved Explorer in Splunk Search 02-23-2016
0 4
0
4
rbushman
I am trying to add to the search below so that I can get a cumulative total of the elapsed time calculation. I want o...
by rbushman New Member in Splunk Search 02-23-2016
0 4
0
4
rgsage
We have a search like this: ... | eval week_start=relative_time(_time,"@w") | eval week_label=strftime(week_start, ...
by rgsage Path Finder in Splunk Search 02-23-2016
0 2
0
2
kamal_jagga
I am searching for a particular sourcetype on a Search Head. I am getting this error in intermittent pages. Page 1 t...
by kamal_jagga Contributor in Splunk Search 02-23-2016
0 2
0
2
HeinzWaescher
Hi, my goal is to calculate the number of retained customers per month. So let's say our timerange starts in 2015-1...
by HeinzWaescher Motivator in Splunk Search 02-23-2016
0 2
0
2
alauri
Hi guys, What is the most popular field name for an IP? I'd like to apply a workflow_action for all the possible IPs...
by alauri Explorer in Splunk Search 02-23-2016
0 3
0
3
jaho_splunk
Why is time formatting not working with the following search: index=_internal sourcetype=splunkd "Ignoring" AND "bi...
by jaho_splunk Engager in Splunk Search 02-22-2016
0 3
0
3
lsolberg
Both myself and other people using the same Splunk search head as I see this. The default charting.axisY2.maximumNumb...
by lsolberg Path Finder in Splunk Search 02-22-2016
0 5
0
5
ashokapex
I have created 2 extracted fields. The 1st I have created from a main list which is RFQ_Request, and the second one i...
by ashokapex Explorer in Splunk Search 02-22-2016
0 5
0
5
sidekix24
Hi, I have the search below that displays an availability percentage for me, but now I'm looking to time chart that ...
by sidekix24 Path Finder in Splunk Search 02-22-2016
0 2
0
2
matt4321
I am using a search to get the average Sessions Duration for my Windows security event logs. I want to take the below...
by matt4321 Explorer in Splunk Search 02-22-2016
0 2
0
2
marina_rovira
Hello all, I have a field called Type with three values and I want a chart of the percentage of these three values. ...
by marina_rovira Contributor in Splunk Search 02-22-2016
0 6
0
6
NimrodSky
Hi For some reason, Splunk is not parsing data anymore - whenever I load new files or forward syslog, while I see th...
by NimrodSky Explorer in Splunk Search 02-22-2016
0 3
0
3
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...