Splunk Search

Splunk Search
Community Activity
clorne
Hello, I have a set of data occurring randomly and I would like to have an event every second. I am able to get that...
by clorne Communicator in Splunk Search 11-16-2015
0 10
0
10
sumansah
Hi Experts, I have a field in a search i.e. Plugin 21156 189 17.68% 74427 60 5.613% 81262 41 3.835% 77572 ...
by SplunkTrust SplunkTrust in Splunk Search 11-16-2015
0 2
0
2
davespatz
Ok so just upgraded my F5 APM (VPN server) in order to support Windows 10. Asked IT people to test on their Windows 1...
by davespatz Explorer in Splunk Search 11-15-2015
0 1
0
1
malat_UoM
First attempt at creating a kvstore lookup to be used by the Search app - initially, at least; I've followed the docu...
by malat_UoM Explorer in Splunk Search 11-15-2015
0 4
0
4
rkdasari
hi, After doing a search, I am unable to see an option "Save As" -> Alert. I have logged in with my User Id. Could ...
by rkdasari New Member in Splunk Search 11-15-2015
0 2
0
2
pmcfadden91
Hi, I have a DB query as below which displays the results as shown in the attached picture: | dbquery "PB CSL" lim...
by pmcfadden91 Path Finder in Splunk Search 11-15-2015
0 8
0
8
splunker12er
More than Splunk, this question is related to firewall logs - any help is very much appreciated. Desc: Mapping Key-v...
by splunker12er Motivator in Splunk Search 11-15-2015
0 1
0
1
hylam
I have disabled the transform stanza in the GUI, but the regex field extractions are still effective. What's wrong? ...
by hylam Contributor in Splunk Search 11-15-2015
0 10
0
10
Masa
I'm curious about the limit of the multisearch command. subsearch has limits in limits.conf. Is there any limit fo...
by Masa Splunk Employee Splunk Employee in Splunk Search 11-14-2015
4 2
4
2
hylam
3*86400+5*3600+40*60+11=279611 The seconds part is always there. The minutes part exists when duration is at least ...
by hylam Contributor in Splunk Search 11-14-2015
1 10
1
10
hylam
One way is to loop thru 0-99 and mod. Are there any built-in command to support this? EDIT1 use case: I want to fill...
by hylam Contributor in Splunk Search 11-14-2015
0 2
0
2
hylam
In addition to $1 $2 $3..., does it support (?<namedField>...)? http://docs.splunk.com/Documentation/Splunk/6.3.1/Adm...
by hylam Contributor in Splunk Search 11-13-2015
0 3
0
3
hylam
Can I make this happen automatically? I know I can do it with the rex search command. eval newField=sed(oldField, "s...
by hylam Contributor in Splunk Search 11-13-2015
1 4
1
4
aputz
I previously had a query on grouping results from a search and I received a great deal of help in shaping this query....
by aputz Path Finder in Splunk Search 11-13-2015
2 1
2
1
splunkIT
For example, I have indexed the following six events and splunk has successfully extracted the fields quite nicely: ...
by splunkIT Splunk Employee Splunk Employee in Splunk Search 11-13-2015
3 4
3
4
jawebb
Maybe I'm not understanding the way this works, but I have other searches that use it just fine. The only difference...
by jawebb Explorer in Splunk Search 11-13-2015
0 5
0
5
aneaston
I have one sourcetype that contains an event for each request to my site. One of the fields (we'll call it 'api') in ...
by aneaston New Member in Splunk Search 11-13-2015
0 4
0
4
ashabc
I have web page logs that have several fields. The important ones for this are CDN locations x_edge_location and the ...
by ashabc Contributor in Splunk Search 11-13-2015
0 3
0
3
praneethkodali
Below search command is giving the results as below source="report1447097285313.csv" host="ca2indslogprd02" index="p...
by praneethkodali Explorer in Splunk Search 11-13-2015
0 6
0
6
gschr
Hi, The following dashboard contains a search that returns more than 1000 values (3600). I want to visualize all of ...
by gschr Path Finder in Splunk Search 11-13-2015
3 9
3
9
prategup1
Hi All My search results from Splunk look like below 2015-11-13 06:32:33,949|a.abcd|DAS|callabcd():getTime|0.296|SU...
by prategup1 New Member in Splunk Search 11-13-2015
0 1
0
1
ciir
Hi all, I'm currently trying to run a search within the CLI (which works perfectly on Splunk Web). The search is th...
by ciir Explorer in Splunk Search 11-13-2015
0 1
0
1
ErikaE
I am attempting to summarize data by a 12 hour reporting period. The reporting periods start/end at 8. My search l...
by ErikaE Communicator in Splunk Search 11-13-2015
0 1
0
1
jlim2003
Hello, I am trying to extract a field that is offset by one column: Event 1: [DT_2.0_REAL][0x80c00002] Event 2: [0x...
by jlim2003 New Member in Splunk Search 11-13-2015
0 2
0
2
edrivera3
Hi How can I extract these fieldnames and values from this event? Step: 0345 Result: Valid Step: 3345 Result: Valid...
by edrivera3 Builder in Splunk Search 11-13-2015
0 10
0
10
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...