Splunk Search

Splunk Search
Community Activity
szabados
I want to replace the * character in a string with the replace command. How do I apply the * by escaping it, not to r...
by szabados Communicator in Splunk Search 02-17-2016
0 2
0
2
greich
I need to trace the data from the originating forwarder through intermediate forwarders or directly onto indexers. I ...
by greich Communicator in Splunk Search 02-17-2016
0 5
0
5
rck
How can I compare the result by a particular week or date for this search? sourcetype="rum" u=* |stats count,avg(t_d...
by rck New Member in Splunk Search 02-17-2016
0 6
0
6
taraksinha
Hi All, I need to remove users from splunk, which they are no longer exist in company but user is still exists in sp...
by taraksinha New Member in Splunk Search 02-17-2016
0 4
0
4
kpavan
Hi All, My use case to find out 1st search user logon time in AD and same user logon time in 2nd search with his act...
by kpavan Path Finder in Splunk Search 02-17-2016
0 9
0
9
shaker_ali
Hi Guys, I would like to be able to extract fields from the sample log below. In bold I have highlighted IP address ...
by shaker_ali Engager in Splunk Search 02-16-2016
0 3
0
3
suryaavinash
I would like to hide the SPL search query when we drill down on a chart or a graph. I tried MACRO's and saved searc...
by suryaavinash Explorer in Splunk Search 02-16-2016
0 3
0
3
alex1895
I want to build a table with different fields depending on the search result. If a certain tag or another tag is fou...
by alex1895 Path Finder in Splunk Search 02-16-2016
0 4
0
4
HattrickNZ
I have the following search ... | stats dc() | transpose | which gives me this: column row 1 dc(ID) 273 dc(SBC) 2...
by HattrickNZ Motivator in Splunk Search 02-16-2016
0 10
0
10
x2xj
Hi there, I have two searches that work great independently, however, I now have a need to combine them both. The ...
by x2xj New Member in Splunk Search 02-16-2016
0 1
0
1
tgiles
Hi, all. I'm trying to fix some optimization issues I'm having with Splunk indexes and wanted some input on a propos...
by tgiles Path Finder in Splunk Search 02-16-2016
0 4
0
4
raby1996
Hello, I'm using the search below to collect errors that have occurred on specific machines, however, I need to use ...
by raby1996 Path Finder in Splunk Search 02-16-2016
0 5
0
5
dj_madeira_opow
I am attempting to find out the elapsed time between two log statements as a percentage of the duration of the full r...
by dj_madeira_opow New Member in Splunk Search 02-16-2016
0 1
0
1
acirulli
I have several servers sending me log. For each log I have a field called X if X=100 for two consecutive times I hav...
by acirulli Engager in Splunk Search 02-16-2016
0 8
0
8
splunker9999
Hi , We are looking for a search for server uptime and downtime. Server is up from last 20days, and results will be...
by splunker9999 Path Finder in Splunk Search 02-16-2016
0 9
0
9
Kukkadapu
Hi, How do I get the stats for the last week/month for different time frames based on the day of the week? Monday ...
by Kukkadapu Path Finder in Splunk Search 02-16-2016
0 4
0
4
stevepraz
I have an environment that has two indexers. I recently added an additional two indexers and added them as search pe...
by stevepraz Path Finder in Splunk Search 02-16-2016
0 8
0
8
renems
Hi There! I have an issue with a field extraction. I have a Windows CSV file, that has several fields that have comm...
by renems Communicator in Splunk Search 02-16-2016
0 10
0
10
packet_hunter
Scenario: I am trying to list all incoming sender domains and tlds. For example, sender@blah.domain.tld, looking fo...
by packet_hunter Contributor in Splunk Search 02-16-2016
0 6
0
6
rwiley
I would like to create a text search so a user can look for his or her own stats. There will be a drop-down with the ...
by rwiley Explorer in Splunk Search 02-16-2016
0 1
0
1
vrmandadi
I am trying to calculate the average response time for the below field ENDPOINT_LOG{}.EML_RESPONSE_TIME: 2016-01-...
by vrmandadi Builder in Splunk Search 02-16-2016
0 9
0
9
chrisboy68
Hi, This search below is working great.... index=logs AND (sourcetype=eMetrics) | JOIN type=outer OrderNumber [ s...
by chrisboy68 Contributor in Splunk Search 02-16-2016
0 5
0
5
klsio
I have this search | eval max = round(max, 2) | eval avg = round(avg, 2) | eval median = round(median,2) | eval min ...
by klsio Explorer in Splunk Search 02-16-2016
0 2
0
2
tkomatsubara_sp
緯度や軽度の情報を数多く含んだデータがあるのですが、これらを地図上に細かくマップしたいです。 geostats count などとすると、大きな丸が地図に点々と表示されるのですが、これだと荒すぎてこまっています。 なにかいい方法はない...
by tkomatsubara_sp Splunk Employee Splunk Employee in Splunk Search 02-16-2016
0 1
0
1
johnraftery
Hi, I have a search in my dashboard that is quiet expensive - it can take over a minute to complete. The result is ...
by johnraftery Communicator in Splunk Search 02-16-2016
0 9
0
9
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...
Top Solution Authors