Splunk Search

Splunk Search
Community Activity
aniketb
My logs have the following info: userid, version, timestamp What is the best way to get a report of what product ve...
by aniketb Path Finder in Splunk Search 11-16-2015
0 2
0
2
slatta
I have many events, but only want to select those that have the same docId in order to compare the Durations of 2 dif...
by slatta Explorer in Splunk Search 11-16-2015
0 1
0
1
pc1234
how can i determine which events contain values that are > the avg value for all the events? I'd also like to count ...
by pc1234 Explorer in Splunk Search 11-16-2015
0 1
0
1
vad34
Hello All, I have restricted search for each index for each user. When I try to search with user1, I can see events ...
by vad34 Path Finder in Splunk Search 11-16-2015
0 2
0
2
nik298
Hi Everyone, I want to create a custom table which contains 2 columns: one is the field parameter and other is the v...
by nik298 New Member in Splunk Search 11-16-2015
0 1
0
1
martin_smith
Can simple regular expressions be used in searches? I'm trying to capture a fairly simple pattern for the host fiel...
by martin_smith Engager in Splunk Search 11-16-2015
1 1
1
1
pkeller
I'm finding that timechart is returning null results if my number is less than 1. earliest=-3d latest=-1d sourcetype...
by pkeller Contributor in Splunk Search 11-16-2015
0 3
0
3
dmccabe2
Hi, I need to add two RegEx to transforms.conf and props.conf. If I add one block of code, testing each REGEX indep...
by dmccabe2 New Member in Splunk Search 11-16-2015
0 3
0
3
samir_silva
I need the event data from the "Data Summary" because I need to create a search to find when hosts stop sending logs ...
by samir_silva New Member in Splunk Search 11-16-2015
0 2
0
2
clorne
Hello, I have a set of data occurring randomly and I would like to have an event every second. I am able to get that...
by clorne Communicator in Splunk Search 11-16-2015
0 10
0
10
sumansah
Hi Experts, I have a field in a search i.e. Plugin 21156 189 17.68% 74427 60 5.613% 81262 41 3.835% 77572 ...
by SplunkTrust SplunkTrust in Splunk Search 11-16-2015
0 2
0
2
davespatz
Ok so just upgraded my F5 APM (VPN server) in order to support Windows 10. Asked IT people to test on their Windows 1...
by davespatz Explorer in Splunk Search 11-15-2015
0 1
0
1
malat_UoM
First attempt at creating a kvstore lookup to be used by the Search app - initially, at least; I've followed the docu...
by malat_UoM Explorer in Splunk Search 11-15-2015
0 4
0
4
rkdasari
hi, After doing a search, I am unable to see an option "Save As" -> Alert. I have logged in with my User Id. Could ...
by rkdasari New Member in Splunk Search 11-15-2015
0 2
0
2
pmcfadden91
Hi, I have a DB query as below which displays the results as shown in the attached picture: | dbquery "PB CSL" lim...
by pmcfadden91 Path Finder in Splunk Search 11-15-2015
0 8
0
8
splunker12er
More than Splunk, this question is related to firewall logs - any help is very much appreciated. Desc: Mapping Key-v...
by splunker12er Motivator in Splunk Search 11-15-2015
0 1
0
1
hylam
I have disabled the transform stanza in the GUI, but the regex field extractions are still effective. What's wrong? ...
by hylam Contributor in Splunk Search 11-15-2015
0 10
0
10
Masa
I'm curious about the limit of the multisearch command. subsearch has limits in limits.conf. Is there any limit fo...
by Masa Splunk Employee Splunk Employee in Splunk Search 11-14-2015
4 2
4
2
hylam
3*86400+5*3600+40*60+11=279611 The seconds part is always there. The minutes part exists when duration is at least ...
by hylam Contributor in Splunk Search 11-14-2015
1 10
1
10
hylam
One way is to loop thru 0-99 and mod. Are there any built-in command to support this? EDIT1 use case: I want to fill...
by hylam Contributor in Splunk Search 11-14-2015
0 2
0
2
hylam
In addition to $1 $2 $3..., does it support (?<namedField>...)? http://docs.splunk.com/Documentation/Splunk/6.3.1/Adm...
by hylam Contributor in Splunk Search 11-13-2015
0 3
0
3
hylam
Can I make this happen automatically? I know I can do it with the rex search command. eval newField=sed(oldField, "s...
by hylam Contributor in Splunk Search 11-13-2015
1 4
1
4
aputz
I previously had a query on grouping results from a search and I received a great deal of help in shaping this query....
by aputz Path Finder in Splunk Search 11-13-2015
2 1
2
1
splunkIT
For example, I have indexed the following six events and splunk has successfully extracted the fields quite nicely: ...
by splunkIT Splunk Employee Splunk Employee in Splunk Search 11-13-2015
3 4
3
4
jawebb
Maybe I'm not understanding the way this works, but I have other searches that use it just fine. The only difference...
by jawebb Explorer in Splunk Search 11-13-2015
0 5
0
5
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors