Splunk Search

Splunk Search
Community Activity
deenadp
Hi, I am unable to add two timestamps in a column using | addcoltotals or | stats. Can you please help me with this...
by deenadp Explorer in Splunk Search 02-10-2016
0 4
0
4
bleinfelder
Hi there, I struggled quite a time to make db-connect work with my splunk 6.0.3 installation. Error Message in dbx....
by bleinfelder Path Finder in Splunk Search 02-10-2016
5 7
5
7
HattrickNZ
I have this search: ...| timechart span=d sum(kpi1) as "kpi1" sum(kpi2) as "kpi2" by userLabel which gives the fol...
by HattrickNZ Motivator in Splunk Search 02-10-2016
0 5
0
5
DEAD_BEEF
I am trying to group three sets of indexes' logs when all three have the same source and destination IP address withi...
by DEAD_BEEF Builder in Splunk Search 02-10-2016
0 2
0
2
Mitchellsch
I'm new in writing searches with a lookup table and need help knowing what's wrong with my logic. Here's my search so...
by Mitchellsch Explorer in Splunk Search 02-10-2016
0 1
0
1
packet_hunter
Scenario: I have a search that evaluates email events (given a specific subject) to count the number of recipients pe...
by packet_hunter Contributor in Splunk Search 02-10-2016
0 2
0
2
c0mrade
What is the default duration time unit for splunk? is it seconds?
by c0mrade Explorer in Splunk Search 02-10-2016
0 3
0
3
dperry
Splunk Instance running on Linux I recently restored frozen buckets to my thawed bucket as follows: cp -r * /opt/sp...
by dperry Communicator in Splunk Search 02-10-2016
2 6
2
6
arrowecssupport
I need to find list of serial numbers that have been extracted as a field value where they have not been seen in over...
by arrowecssupport Communicator in Splunk Search 02-10-2016
0 5
0
5
pandeyashish
I am trying to make a search for outbound traffic flow. i.e. source, destination IP and destination port. Is there an...
by pandeyashish New Member in Splunk Search 02-10-2016
0 3
0
3
daniel333
Should be easy enough, but not working for me. I am trying to pull a hostname of a log. I am terrible at regex and tr...
by daniel333 Builder in Splunk Search 02-10-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to create a search which identifies inactive users ove...
by IRHM73 Motivator in Splunk Search 02-10-2016
0 6
0
6
dkeck
Hi, I have this code: |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0...
by dkeck Influencer in Splunk Search 02-10-2016
0 5
0
5
sunrise
Hi Splukers, I cannot get a search to produce what I want. Please help me. I tried the following search and got resu...
by sunrise Contributor in Splunk Search 02-09-2016
0 4
0
4
mookiie2005
We have a lot of searches that run to ensure we are receiving data from a Splunk forwarder and that it is still runni...
by mookiie2005 Communicator in Splunk Search 02-09-2016
0 2
0
2
LWilliamson1
Search: index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id) When swit...
by LWilliamson1 Explorer in Splunk Search 02-09-2016
0 1
0
1
sat94541
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by sat94541 Communicator in Splunk Search 02-09-2016
2 5
2
5
splunker9999
Hi, I have events with the below format: "phone":{"areaCode":"732","prefix":"986","lineNumber":"0245", Is there a...
by splunker9999 Path Finder in Splunk Search 02-09-2016
0 4
0
4
maclun
Hi, There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other eve...
by maclun New Member in Splunk Search 02-09-2016
0 1
0
1
chaseto
Hello Experts, I have 2 different sources source 1 has hostname, ip address source 2 has hostname, os, os version...
by chaseto Explorer in Splunk Search 02-09-2016
0 8
0
8
zabarai
Hi, I'm pretty new to spluk, I'm looking for some help with malware detection. What would the search expression l...
by zabarai Engager in Splunk Search 02-09-2016
2 1
2
1
mattholt
We need to find the most talkative indexers within Splunk for the last 24 hour period.
by mattholt New Member in Splunk Search 02-09-2016
0 1
0
1
lyndac
I am indexing JSON data. I need to be able to do stats based "by patches" and "by admin". I can't get spath or mv...
by lyndac Contributor in Splunk Search 02-09-2016
2 3
2
3
diliptmonson
Hi All, I am trying to link 2 indexes using join. I have tried the following code: index=index1| join Id[index=in...
by diliptmonson Explorer in Splunk Search 02-09-2016
0 3
0
3
jambajuice
I need to create an outputlookup file with more than 10,000 results. I've looked through the limits.conf examples an...
by jambajuice Communicator in Splunk Search 02-09-2016
3 5
3
5
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors