Splunk Search

Splunk Search
Community Activity
mctester
I had to migrate a some indexes over from one instance to another. All worked but the 'os' index, and I'm seeing this...
by mctester Communicator in Splunk Search 11-25-2015
2 2
2
2
jyothishtj
Hi, I am trying to split an event to multiple events. I want to split after 12th character. The string contains spac...
by jyothishtj New Member in Splunk Search 11-25-2015
0 6
0
6
Laya123
hi, Is it possible to get subtotals? I have attached a file of how my output looks like. I want subtotals by Cluste...
by Laya123 Communicator in Splunk Search 11-25-2015
0 11
0
11
tdiestel
Hi All; Here's my issue. I'm trying to search data where a single event appears as below. When I use the search: in...
by tdiestel Path Finder in Splunk Search 11-25-2015
1 8
1
8
raghunand
Ex: /nfs/tibcosoftware/splunk/impactAnalysis/freight/ConwayServicesOMSEvents/1.01-49/AESchemas /nfs/tibcosoftware/s...
by raghunand Explorer in Splunk Search 11-25-2015
0 7
0
7
DimkoBilanko
I want to find exact events that point to a delete file event in Windows share. There are two events generated at th...
by DimkoBilanko Explorer in Splunk Search 11-25-2015
0 4
0
4
leochan
Is there a way to combine the following the following result into one line? Current Result: q2.example.com 26,575....
by leochan Explorer in Splunk Search 11-25-2015
0 4
0
4
skoelpin
I have 2 indexes which both have a common filed (JSESSIONID).. One index has an IndexOutOfBoundsException and another...
by SplunkTrust SplunkTrust in Splunk Search 11-25-2015
0 7
0
7
marina_rovira
Hi there! I have an issue. On one hand, I have an index with a lot of information and duplicated values. And on the...
by marina_rovira Contributor in Splunk Search 11-25-2015
1 2
1
2
Splunk_rocks
I have a events like below in my servers so I want write a search to extract tps(cur) value in a table format with _...
by Splunk_rocks Path Finder in Splunk Search 11-25-2015
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I've created this regex \"Surname\\":\\"(?<SName>[...
by IRHM73 Motivator in Splunk Search 11-25-2015
0 4
0
4
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to make changes to the partial script below t...
by IRHM73 Motivator in Splunk Search 11-25-2015
1 5
1
5
denisevw
I am trying to arrange some information received in a CSV file in a table format (as per example) The two searches I...
by denisevw Path Finder in Splunk Search 11-25-2015
0 3
0
3
bwalden_splunk
Some questions about indexed rt (http://docs.splunk.com/Documentation/Splunk/6.2.2/Search/Aboutrealtimesearches#Index...
by bwalden_splunk Splunk Employee Splunk Employee in Splunk Search 11-25-2015
1 4
1
4
josefa123
I need to know how to get temperature and power consumption of my linux pc. How can I do it? Thanks in advance.
by josefa123 Explorer in Splunk Search 11-25-2015
0 3
0
3
amirofmn
Just finished setting up a kvstore collection within the collections.conf and pushed it out through the deployer to o...
by amirofmn Explorer in Splunk Search 11-24-2015
0 1
0
1
mitchabaza
Given the Splunk result set in the attached screenshot, I'd like to formulate a search that finds all overlapping eve...
by mitchabaza Explorer in Splunk Search 11-24-2015
0 3
0
3
splunk24
I'm getting this error while executing |inputlookup kvstore_lookup kv store disabled in this splunk distribution i...
by splunk24 Path Finder in Splunk Search 11-24-2015
0 1
0
1
thisissplunk
I've got ifconfing reporting dropped packets every 10 minutes. Because that value never rolls over until the NIC goes...
by thisissplunk Builder in Splunk Search 11-24-2015
1 5
1
5
jp28
I'm trying to get the difference between two values that share the same field name from two different sourcetypes tha...
by jp28 New Member in Splunk Search 11-24-2015
0 1
0
1
wood1986
I have these events 2013-10-13T12:00:25+0000 {"id":1, "meta":["a", "b"]} 2013-10-13T12:10:11+0000 {"id":1, "meta":["...
by wood1986 Explorer in Splunk Search 11-24-2015
0 3
0
3
dvadithala
Hi, I'm completely new to Splunk and using Light version for evaluation. How can I add a date field into my search a...
by dvadithala New Member in Splunk Search 11-24-2015
0 3
0
3
vinay4444
I am struggling with the regex match on the below pattern. I need to capture major version name from below ( DB2 9.7,...
by vinay4444 Explorer in Splunk Search 11-24-2015
0 7
0
7
ErikaE
I have data from a sourcetype that I am searching with a map command like so: source=outersearch | map search="sear...
by ErikaE Communicator in Splunk Search 11-24-2015
0 2
0
2
shankaranantht
Find below mentioned data Applicationname |Partners | Servicename | status DEE | WEEEEE |Money Transfer|Suc...
by shankaranantht New Member in Splunk Search 11-24-2015
0 6
0
6
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...