Splunk Search

Splunk Search
Community Activity
bleinfelder
Hi there, I struggled quite a time to make db-connect work with my splunk 6.0.3 installation. Error Message in dbx....
by bleinfelder Path Finder in Splunk Search 02-10-2016
5 7
5
7
HattrickNZ
I have this search: ...| timechart span=d sum(kpi1) as "kpi1" sum(kpi2) as "kpi2" by userLabel which gives the fol...
by HattrickNZ Motivator in Splunk Search 02-10-2016
0 5
0
5
DEAD_BEEF
I am trying to group three sets of indexes' logs when all three have the same source and destination IP address withi...
by DEAD_BEEF Builder in Splunk Search 02-10-2016
0 2
0
2
Mitchellsch
I'm new in writing searches with a lookup table and need help knowing what's wrong with my logic. Here's my search so...
by Mitchellsch Explorer in Splunk Search 02-10-2016
0 1
0
1
packet_hunter
Scenario: I have a search that evaluates email events (given a specific subject) to count the number of recipients pe...
by packet_hunter Contributor in Splunk Search 02-10-2016
0 2
0
2
c0mrade
What is the default duration time unit for splunk? is it seconds?
by c0mrade Explorer in Splunk Search 02-10-2016
0 3
0
3
dperry
Splunk Instance running on Linux I recently restored frozen buckets to my thawed bucket as follows: cp -r * /opt/sp...
by dperry Communicator in Splunk Search 02-10-2016
2 6
2
6
arrowecssupport
I need to find list of serial numbers that have been extracted as a field value where they have not been seen in over...
by arrowecssupport Communicator in Splunk Search 02-10-2016
0 5
0
5
pandeyashish
I am trying to make a search for outbound traffic flow. i.e. source, destination IP and destination port. Is there an...
by pandeyashish New Member in Splunk Search 02-10-2016
0 3
0
3
daniel333
Should be easy enough, but not working for me. I am trying to pull a hostname of a log. I am terrible at regex and tr...
by daniel333 Builder in Splunk Search 02-10-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to create a search which identifies inactive users ove...
by IRHM73 Motivator in Splunk Search 02-10-2016
0 6
0
6
dkeck
Hi, I have this code: |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0...
by dkeck Influencer in Splunk Search 02-10-2016
0 5
0
5
sunrise
Hi Splukers, I cannot get a search to produce what I want. Please help me. I tried the following search and got resu...
by sunrise Contributor in Splunk Search 02-09-2016
0 4
0
4
mookiie2005
We have a lot of searches that run to ensure we are receiving data from a Splunk forwarder and that it is still runni...
by mookiie2005 Communicator in Splunk Search 02-09-2016
0 2
0
2
LWilliamson1
Search: index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id) When swit...
by LWilliamson1 Explorer in Splunk Search 02-09-2016
0 1
0
1
sat94541
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by sat94541 Communicator in Splunk Search 02-09-2016
2 5
2
5
splunker9999
Hi, I have events with the below format: "phone":{"areaCode":"732","prefix":"986","lineNumber":"0245", Is there a...
by splunker9999 Path Finder in Splunk Search 02-09-2016
0 4
0
4
maclun
Hi, There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other eve...
by maclun New Member in Splunk Search 02-09-2016
0 1
0
1
chaseto
Hello Experts, I have 2 different sources source 1 has hostname, ip address source 2 has hostname, os, os version...
by chaseto Explorer in Splunk Search 02-09-2016
0 8
0
8
zabarai
Hi, I'm pretty new to spluk, I'm looking for some help with malware detection. What would the search expression l...
by zabarai Engager in Splunk Search 02-09-2016
2 1
2
1
mattholt
We need to find the most talkative indexers within Splunk for the last 24 hour period.
by mattholt New Member in Splunk Search 02-09-2016
0 1
0
1
lyndac
I am indexing JSON data. I need to be able to do stats based "by patches" and "by admin". I can't get spath or mv...
by lyndac Contributor in Splunk Search 02-09-2016
2 3
2
3
diliptmonson
Hi All, I am trying to link 2 indexes using join. I have tried the following code: index=index1| join Id[index=in...
by diliptmonson Explorer in Splunk Search 02-09-2016
0 3
0
3
jambajuice
I need to create an outputlookup file with more than 10,000 results. I've looked through the limits.conf examples an...
by jambajuice Communicator in Splunk Search 02-09-2016
3 5
3
5
SylviaB
Persistent queues are not available for splunktcp, I use several Forwarders on networks n, sending to a central forw...
by SylviaB New Member in Splunk Search 02-09-2016
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors