Splunk Search

Splunk Search
Community Activity
sanjayamin
Hi, We have installed splunk free version and optic splunk app. We are not able to see the sample data available with...
by sanjayamin Engager in Splunk Search 11-20-2015
1 1
1
1
joydeep741
I wish to count the number of events and then use that value to calculate something else. I tried something like thi...
by joydeep741 Path Finder in Splunk Search 11-20-2015
1 4
1
4
HeinzWaescher
Hi, I've a timechart table for revenue grouped by product. _time | productA | product B | product C I would like t...
by HeinzWaescher Motivator in Splunk Search 11-20-2015
0 13
0
13
sylim_splunk
I have a configuration, maxHotSpanSecs = 86399 for an index namded board, expecting the buckets keep a day amount of ...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 11-20-2015
2 2
2
2
pjohnson1
I am creating a filter to only keep certain events which contain a specific country code (they are actually hostnames...
by pjohnson1 Path Finder in Splunk Search 11-20-2015
0 7
0
7
zcwang
Could anyone provide me a simple example for using REGEX with DELIMS? The event in my scenario is full of delimiter-s...
by zcwang New Member in Splunk Search 11-19-2015
0 2
0
2
magorinahory
Hello, I have defined api_names and calculating counts and sigma limits for alert based on uri stem. Example uri ste...
by magorinahory New Member in Splunk Search 11-19-2015
0 1
0
1
nl65
I have searches (accelerated) which have no owner, and have no delete option. How do I get rid of them?
by nl65 Explorer in Splunk Search 11-19-2015
0 1
0
1
epsplnkusr
In my logs, I capture application errors and the log includes the application version. I have figured out with the se...
by epsplnkusr New Member in Splunk Search 11-19-2015
0 1
0
1
dasveruckte
Search String index=myindex sourcetype=mysourcetype | rex "\.(?<host_domain>.+)$" field=host | lookup host_do...
by dasveruckte New Member in Splunk Search 11-19-2015
0 3
0
3
wadesworld
Given the following snippets of log statements: src=feed value=5 src=calc value=37 src=feed value=20 src=calc value=...
by wadesworld Engager in Splunk Search 11-19-2015
0 1
0
1
renems
I'm trying to create a new field based on the host field. The new field (hostname) should only contain the shortname....
by renems Communicator in Splunk Search 11-19-2015
0 2
0
2
lynchs61
I have results with field names A, B, C, D that will look something like this; A B C D 0 10 0 0 1 ...
by lynchs61 New Member in Splunk Search 11-19-2015
0 1
0
1
sankalpsah
I have a table like below: CPU0 CPU1 CPU2 CPU3 0: 1826872 0 0 ...
by sankalpsah New Member in Splunk Search 11-19-2015
0 6
0
6
suvamondal
I want to know how to determine if a user logged on to multiple machines within a certain time window, and also ident...
by suvamondal New Member in Splunk Search 11-19-2015
0 1
0
1
ldjamesl
Hello there, I know this question might be worded a little weird. I'm trying to create a report that shows the top wo...
by ldjamesl New Member in Splunk Search 11-19-2015
0 3
0
3
daveowens
I have a custom log file with entries like the one below, I want to pull 8 fields out at index time so I can graph an...
by daveowens Engager in Splunk Search 11-19-2015
2 7
2
7
madrum
I have an enterprise scale MVC website with 4 or 5 major modules/views that runs on a Windows server with full IIS lo...
by madrum Explorer in Splunk Search 11-18-2015
0 2
0
2
anoopambli
Is there a way I can generate a report with a list of deployed forwarders and its installation path on the remote ser...
by anoopambli Communicator in Splunk Search 11-18-2015
0 2
0
2
leotoa
Hello all, I've recently observed activity that smells like beaconing. After trying to modify the searches provided ...
by leotoa New Member in Splunk Search 11-18-2015
0 1
0
1
jamesmarlowww
Can I set a token using a field found in a lookup table? I've been researching online, but I haven't found a real sol...
by jamesmarlowww Path Finder in Splunk Search 11-18-2015
1 6
1
6
stanvv
Hi, I only want to index files containing the string #! in the first 5 characters of the file. Therefore, I created ...
by stanvv New Member in Splunk Search 11-18-2015
0 7
0
7
the_wolverine
Do these settings take effect on both SH and indexer? # the maximum number of concurrent searches per CPU max_search...
by the_wolverine Champion in Splunk Search 11-18-2015
1 1
1
1
track16
I have a search: sourcetype="my_data"| stats count by queue which aggregates data in a table by the field queue. ...
by track16 Engager in Splunk Search 11-18-2015
0 4
0
4
tmarlette
I have a long, that gets pretty long, and currently splunk is ingesting it as a whole. this log gets up a couple hund...
by tmarlette Motivator in Splunk Search 11-18-2015
0 8
0
8
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors