Splunk Search

Splunk Search
Community Activity
diliptmonson
Hi, I need to search for an element A present in one of the fields let's say field 1. Some of the values present fo...
by diliptmonson Explorer in Splunk Search 02-18-2016
0 2
0
2
splunker9999
Hi, Can someone please advise, how we can set different colors in a dashboard for each single row? Our data looks ...
by splunker9999 Path Finder in Splunk Search 02-18-2016
0 3
0
3
johnraftery
We have certain source types where there is only data from months ago. When putting this into a timechart, the chart ...
by johnraftery Communicator in Splunk Search 02-18-2016
0 4
0
4
timgirgis
I want to create a stacked bar graph showing 2 columns stacked by department: 1 column is the total time and the seco...
by timgirgis Explorer in Splunk Search 02-18-2016
1 2
1
2
andrei1bc
My search : index=test | where Value>=95 | stats count(Value) as Events by Host The result : if there are ...
by andrei1bc Communicator in Splunk Search 02-18-2016
0 4
0
4
nikkkc
In my search, I calculate some values, but if I reach the 10000 result limit, I get wrong results. I would like chang...
by nikkkc Path Finder in Splunk Search 02-18-2016
0 6
0
6
dwin02
Hi Splunk Support, I'm trying to create a table based on certain fields from the Output Results: Search String: ...
by dwin02 Explorer in Splunk Search 02-17-2016
0 13
0
13
nickleli
Hi Everyone, Our setup is a universal forwarder --> heavy forwarder --> indexer. I am looking to modify a universal...
by nickleli New Member in Splunk Search 02-17-2016
0 5
0
5
MichaelCohen829
Hello, Could someone please delineate the difference between these two earliest commands: earliest=-2d earliest=-2...
by MichaelCohen829 Explorer in Splunk Search 02-17-2016
0 8
0
8
athorat
Want to extract only /ubi-v2/api/scoresummary from the below mentioned event in a field. Rex used: `| rex "(?<remo...
by athorat Communicator in Splunk Search 02-17-2016
0 1
0
1
angelo_fazzina
This is my search so far. sourcetype="spam" |eventstats count as total|search block_code="*" |eventstats count as b...
by angelo_fazzina Engager in Splunk Search 02-17-2016
0 6
0
6
jhayIV
I have the following string 2016-02-17 field and I would like to extract the 02 between the hyphens. Does someone hav...
by jhayIV Engager in Splunk Search 02-17-2016
0 3
0
3
splunker12er
|metadata type=hosts earliest=-1d latest=now This displays the overall eventcounts for the available hosts but not ...
by splunker12er Motivator in Splunk Search 02-17-2016
1 3
1
3
Securitas
I'm trying to search for some IPs of interest within the Rapid 7 App for Splunk Enterprise. Is there a way to do that...
by Securitas Engager in Splunk Search 02-17-2016
0 1
0
1
fisuser1
Is there a way to create a transforms for separate values while not breaking current regex instances that are working...
by fisuser1 Contributor in Splunk Search 02-17-2016
0 5
0
5
jshellman
I have a search, something like this: search stuff | rex "extract cat" | rex "extract field2" | rex "ext...
by jshellman Engager in Splunk Search 02-17-2016
0 3
0
3
rainerzufall
Hello, We would like to match all sources except the ones including /splunk/ in props.conf. Example: No match for /...
by rainerzufall Path Finder in Splunk Search 02-17-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the search below to extract the date when Splu...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 7
0
7
IRHM73
Hi, I wonder whether someone may be able to help me please. I've put together the following form. <form> <lab...
by IRHM73 Motivator in Splunk Search 02-17-2016
0 3
0
3
max_y0586
I have two searches with the result as displayed below. Here I want to find the service related to each activity base...
by max_y0586 New Member in Splunk Search 02-17-2016
0 2
0
2
taraksinha
Hello, How can i display latest dates of searches with time frame, I need to filter top search in a month, any optio...
by taraksinha New Member in Splunk Search 02-17-2016
0 16
0
16
taraksinha
A user no longer exists in Splunk, but their reports and dashboards are still there. Is there a search to fix this?
by taraksinha New Member in Splunk Search 02-17-2016
0 2
0
2
szabados
I want to replace the * character in a string with the replace command. How do I apply the * by escaping it, not to r...
by szabados Communicator in Splunk Search 02-17-2016
0 2
0
2
greich
I need to trace the data from the originating forwarder through intermediate forwarders or directly onto indexers. I ...
by greich Communicator in Splunk Search 02-17-2016
0 5
0
5
rck
How can I compare the result by a particular week or date for this search? sourcetype="rum" u=* |stats count,avg(t_d...
by rck New Member in Splunk Search 02-17-2016
0 6
0
6
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors