Splunk Search

Splunk Search
Community Activity
TCK101
I have a view set up in which there is a radio option list. e.g. select your zone 1 2 3 Now I have a second radio s...
by TCK101 New Member in Splunk Search 02-11-2016
0 1
0
1
splunkswede
Background: Once an asynchronous request has been triggered, a client starts to poll the system waiting for an object...
by splunkswede Explorer in Splunk Search 02-11-2016
0 5
0
5
JeToJedno
I want to create a timechart which has results: - count of distinct IP addresses - average of transaction response ...
by JeToJedno Explorer in Splunk Search 02-11-2016
0 3
0
3
silasbarnesva
Hi all, We have a field in Splunk that is populated with filenames (e.g.) G:/some_directory/somefile.txt Everythi...
by silasbarnesva Explorer in Splunk Search 02-10-2016
1 6
1
6
ifeldshteyn
I have an extraction that retrieves all the error_reason's in a long string that are separated by a substring err_sep...
by ifeldshteyn Communicator in Splunk Search 02-10-2016
0 2
0
2
pkeller
I have two data sources, each with a field named foo. Each data source has a different sourcetype, so I'd like to do ...
by pkeller Contributor in Splunk Search 02-10-2016
0 4
0
4
deenadp
Hi, I am unable to add two timestamps in a column using | addcoltotals or | stats. Can you please help me with this...
by deenadp Explorer in Splunk Search 02-10-2016
0 4
0
4
bleinfelder
Hi there, I struggled quite a time to make db-connect work with my splunk 6.0.3 installation. Error Message in dbx....
by bleinfelder Path Finder in Splunk Search 02-10-2016
5 7
5
7
HattrickNZ
I have this search: ...| timechart span=d sum(kpi1) as "kpi1" sum(kpi2) as "kpi2" by userLabel which gives the fol...
by HattrickNZ Motivator in Splunk Search 02-10-2016
0 5
0
5
DEAD_BEEF
I am trying to group three sets of indexes' logs when all three have the same source and destination IP address withi...
by DEAD_BEEF Builder in Splunk Search 02-10-2016
0 2
0
2
Mitchellsch
I'm new in writing searches with a lookup table and need help knowing what's wrong with my logic. Here's my search so...
by Mitchellsch Explorer in Splunk Search 02-10-2016
0 1
0
1
packet_hunter
Scenario: I have a search that evaluates email events (given a specific subject) to count the number of recipients pe...
by packet_hunter Contributor in Splunk Search 02-10-2016
0 2
0
2
c0mrade
What is the default duration time unit for splunk? is it seconds?
by c0mrade Explorer in Splunk Search 02-10-2016
0 3
0
3
dperry
Splunk Instance running on Linux I recently restored frozen buckets to my thawed bucket as follows: cp -r * /opt/sp...
by dperry Communicator in Splunk Search 02-10-2016
2 6
2
6
arrowecssupport
I need to find list of serial numbers that have been extracted as a field value where they have not been seen in over...
by arrowecssupport Communicator in Splunk Search 02-10-2016
0 5
0
5
pandeyashish
I am trying to make a search for outbound traffic flow. i.e. source, destination IP and destination port. Is there an...
by pandeyashish New Member in Splunk Search 02-10-2016
0 3
0
3
daniel333
Should be easy enough, but not working for me. I am trying to pull a hostname of a log. I am terrible at regex and tr...
by daniel333 Builder in Splunk Search 02-10-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to create a search which identifies inactive users ove...
by IRHM73 Motivator in Splunk Search 02-10-2016
0 6
0
6
dkeck
Hi, I have this code: |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0...
by dkeck Influencer in Splunk Search 02-10-2016
0 5
0
5
sunrise
Hi Splukers, I cannot get a search to produce what I want. Please help me. I tried the following search and got resu...
by sunrise Contributor in Splunk Search 02-09-2016
0 4
0
4
mookiie2005
We have a lot of searches that run to ensure we are receiving data from a Splunk forwarder and that it is still runni...
by mookiie2005 Communicator in Splunk Search 02-09-2016
0 2
0
2
LWilliamson1
Search: index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id) When swit...
by LWilliamson1 Explorer in Splunk Search 02-09-2016
0 1
0
1
sat94541
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by sat94541 Communicator in Splunk Search 02-09-2016
2 5
2
5
splunker9999
Hi, I have events with the below format: "phone":{"areaCode":"732","prefix":"986","lineNumber":"0245", Is there a...
by splunker9999 Path Finder in Splunk Search 02-09-2016
0 4
0
4
maclun
Hi, There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other eve...
by maclun New Member in Splunk Search 02-09-2016
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors