Splunk Search

Splunk Search
Community Activity
JJ_of_c9
I have managed to get our linux hosts' lastlog data in our Splunk> (version 5.0.2, build 149561) easily enough, but w...
by JJ_of_c9 Engager in Splunk Search 02-18-2016
1 4
1
4
att35
Hi, We have few appliances spread across various data centers feeding logs into Splunk. Each Data center has 2 or mo...
by att35 Builder in Splunk Search 02-18-2016
0 3
0
3
dbcase
I have a json object (see below). I need to take the value of payload.chan (15 in this case) and using 15 select pay...
by dbcase Motivator in Splunk Search 02-18-2016
0 5
0
5
packet_hunter
Scenario: I am extracting sender domains with the following code: index=mail sourcetype=xemail [search index=m...
by packet_hunter Contributor in Splunk Search 02-18-2016
0 1
0
1
diliptmonson
Hi, I need to search for an element A present in one of the fields let's say field 1. Some of the values present fo...
by diliptmonson Explorer in Splunk Search 02-18-2016
0 2
0
2
splunker9999
Hi, Can someone please advise, how we can set different colors in a dashboard for each single row? Our data looks ...
by splunker9999 Path Finder in Splunk Search 02-18-2016
0 3
0
3
johnraftery
We have certain source types where there is only data from months ago. When putting this into a timechart, the chart ...
by johnraftery Communicator in Splunk Search 02-18-2016
0 4
0
4
timgirgis
I want to create a stacked bar graph showing 2 columns stacked by department: 1 column is the total time and the seco...
by timgirgis Explorer in Splunk Search 02-18-2016
1 2
1
2
andrei1bc
My search : index=test | where Value>=95 | stats count(Value) as Events by Host The result : if there are ...
by andrei1bc Communicator in Splunk Search 02-18-2016
0 4
0
4
nikkkc
In my search, I calculate some values, but if I reach the 10000 result limit, I get wrong results. I would like chang...
by nikkkc Path Finder in Splunk Search 02-18-2016
0 6
0
6
dwin02
Hi Splunk Support, I'm trying to create a table based on certain fields from the Output Results: Search String: ...
by dwin02 Explorer in Splunk Search 02-17-2016
0 13
0
13
nickleli
Hi Everyone, Our setup is a universal forwarder --> heavy forwarder --> indexer. I am looking to modify a universal...
by nickleli New Member in Splunk Search 02-17-2016
0 5
0
5
MichaelCohen829
Hello, Could someone please delineate the difference between these two earliest commands: earliest=-2d earliest=-2...
by MichaelCohen829 Explorer in Splunk Search 02-17-2016
0 8
0
8
athorat
Want to extract only /ubi-v2/api/scoresummary from the below mentioned event in a field. Rex used: `| rex "(?<remo...
by athorat Communicator in Splunk Search 02-17-2016
0 1
0
1
angelo_fazzina
This is my search so far. sourcetype="spam" |eventstats count as total|search block_code="*" |eventstats count as b...
by angelo_fazzina Engager in Splunk Search 02-17-2016
0 6
0
6
jhayIV
I have the following string 2016-02-17 field and I would like to extract the 02 between the hyphens. Does someone hav...
by jhayIV Engager in Splunk Search 02-17-2016
0 3
0
3
splunker12er
|metadata type=hosts earliest=-1d latest=now This displays the overall eventcounts for the available hosts but not ...
by splunker12er Motivator in Splunk Search 02-17-2016
1 3
1
3
Securitas
I'm trying to search for some IPs of interest within the Rapid 7 App for Splunk Enterprise. Is there a way to do that...
by Securitas Engager in Splunk Search 02-17-2016
0 1
0
1
fisuser1
Is there a way to create a transforms for separate values while not breaking current regex instances that are working...
by fisuser1 Contributor in Splunk Search 02-17-2016
0 5
0
5
jshellman
I have a search, something like this: search stuff | rex "extract cat" | rex "extract field2" | rex "ext...
by jshellman Engager in Splunk Search 02-17-2016
0 3
0
3
rainerzufall
Hello, We would like to match all sources except the ones including /splunk/ in props.conf. Example: No match for /...
by rainerzufall Path Finder in Splunk Search 02-17-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the search below to extract the date when Splu...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 7
0
7
IRHM73
Hi, I wonder whether someone may be able to help me please. I've put together the following form. <form> <lab...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 3
0
3
max_y0586
I have two searches with the result as displayed below. Here I want to find the service related to each activity base...
by max_y0586 New Member in Splunk Search 02-17-2016
0 2
0
2
taraksinha
Hello, How can i display latest dates of searches with time frame, I need to filter top search in a month, any optio...
by taraksinha New Member in Splunk Search 02-17-2016
0 16
0
16
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors