Splunk Search

Splunk Search
Community Activity
km_sec
I want to filter out everything in my massive firewall logs except those events with event codes for a few important ...
by km_sec New Member in Splunk Search 11-12-2015
0 2
0
2
JohnBelliveau
I'm trying to create a dashboard panel with a statistics table, which needs to be populated with the results from mul...
by JohnBelliveau New Member in Splunk Search 11-12-2015
0 1
0
1
rakeshkumar_sah
Hi, I have logs followed with a structure like this: start Performance Logging: [txID=123456789-EJBClientf12345678...
by rakeshkumar_sah New Member in Splunk Search 11-12-2015
0 1
0
1
Bliide
I am battling a field extraction. I am trying to get the text extracted from an error message in a log that follows ...
by Bliide Path Finder in Splunk Search 11-12-2015
0 5
0
5
vtsguerrero
I have a simple search like index=main sourcetype=performance Status=* | eval Status = if(Status=="S","Success","Err...
by vtsguerrero Contributor in Splunk Search 11-12-2015
0 8
0
8
akhila_bonam
Hi, I have a case where I need to get the sum of values from neighboring events based on a search key. Example: A=...
by akhila_bonam Engager in Splunk Search 11-12-2015
0 2
0
2
bravon
I got a log containing "Step" values in order: Step=11001 , Step=11018 , Step=12302 , Step=12319 , Step=12800 , Step...
by bravon Communicator in Splunk Search 11-12-2015
0 3
0
3
tonifrommknecht
How can I split a string from a field? Example: url="https://www.google.de/images/hpp/ic_wahlberg_product_core_48.png...
by tonifrommknecht Engager in Splunk Search 11-12-2015
0 1
0
1
mjd555
Background So I have two date fields - Date_Created & Acknowledge_Date both in the format YYYY-MM-DD HH:MM:SS. I wis...
by mjd555 Path Finder in Splunk Search 11-12-2015
0 7
0
7
IRHM73
Hi, I wonder whether someone may be able to help me please I'm using the search below to produce the screenshot as s...
by IRHM73 Motivator in Splunk Search 11-12-2015
0 2
0
2
ryuch2002
Splunk Enterprise version: 6.3.1 earliest_time : "-5m", latest_time:"now" exec_mode:"blocking", search : "index= xxx...
by ryuch2002 Explorer in Splunk Search 11-11-2015
0 1
0
1
basanthp
I am running the following search to get events from Windows event logs for the past month. I want to restrict the se...
by basanthp Path Finder in Splunk Search 11-11-2015
1 4
1
4
andreasknutsso1
Hi, I am trying to write a search that seems a bit more tricky than it first looked like...  We have a scenario w...
by andreasknutsso1 Engager in Splunk Search 11-11-2015
1 3
1
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to put together a piece of a search which mul...
by IRHM73 Motivator in Splunk Search 11-11-2015
0 10
0
10
wweiland
I need to lookup the IP in a firewall log to a field in an inputcsv. The CSV file holds 50k results, so subsearches ...
by wweiland Contributor in Splunk Search 11-11-2015
0 4
0
4
m_vivek
My splunk search is something like this index=pqr host=xyz* NOT TYPE="*ABCDE*" | fields X, Y |timechart limit=0...
by m_vivek Path Finder in Splunk Search 11-11-2015
0 3
0
3
dasanner
What does it mean when there is a dash (blank/null?) server ip address for a site? Seeing this quite often in results...
by dasanner New Member in Splunk Search 11-11-2015
0 1
0
1
m_vivek
After a The splunk+R search , index=pqr host=xyz* NOT TYPE="*ABCDE*" | fields X, Y |timechart limit=0 span=10m c...
by m_vivek Path Finder in Splunk Search 11-11-2015
0 6
0
6
rrmavani
We have cluster environment in Splunk. We want to give access to Splunk CLI to users. They should be able to execute...
by rrmavani Engager in Splunk Search 11-11-2015
0 1
0
1
_dave_b
Hello. I'm trying to find the time delta between the most recent event and the event prior to it. Delta sounds lik...
by _dave_b Communicator in Splunk Search 11-11-2015
0 2
0
2
akdake
HI, I want to correlate two sourcetypes. The first sourcetype is VPN logged event. For example, userA logged event ...
by akdake Explorer in Splunk Search 11-11-2015
0 4
0
4
dcagatay
I am trying to write a custom reporting command that finds the top words. It seems to work, but I see some data isn't...
by dcagatay Explorer in Splunk Search 11-11-2015
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to run a search which looks at a value in col...
by IRHM73 Motivator in Splunk Search 11-11-2015
1 6
1
6
DMohn
Hi Splunkers, I have a question regarding the input extraction of XML fields (with inputs and transforms). I have t...
by DMohn Motivator in Splunk Search 11-11-2015
0 4
0
4
IRHM73
Hi, I wonder if someone may be able to help me please. I'm starting to learn more about the administration aspect of...
by IRHM73 Motivator in Splunk Search 11-10-2015
0 2
0
2
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

If you are designing a Splunk forwarding architecture, it can be tempting to place a Universal Forwarder (UF) ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...