Splunk Search

Splunk Search
Community Activity
Laya123
Hi, I have some transactions which have taken 3 hours to complete. When I use maxspan=90m, my transaction is breakin...
by Laya123 Communicator in Splunk Search 11-02-2015
1 9
1
9
payal23
Column1 Column2 28 28 46 46-28 58 58-(28+46) 89 89-(28+46+58) Is this possible? ...
by payal23 Path Finder in Splunk Search 11-02-2015
0 2
0
2
keithyap
IS there a way I can create a new field with a cumulative count of a unique ID? For example, currently i have create...
by keithyap Path Finder in Splunk Search 11-01-2015
0 2
0
2
Bliide
I am trying to remove the header from a log file. I know that I need to put a stanza in props.conf on the forwarder ...
by Bliide Path Finder in Splunk Search 11-01-2015
0 3
0
3
jhayIV
How would I divide each value in this row by the count(CMDB SERVER) calc?
by jhayIV Engager in Splunk Search 10-31-2015
0 2
0
2
joarsvensson
I want to do an automatic lookup from a CSV file on index time, and add new fields to the event. I got this working, ...
by joarsvensson New Member in Splunk Search 10-31-2015
0 5
0
5
m_vivek
I am doing a simple search: index=pqr host=xyz* NOT TYPE="*ABCDE*" | fields X, Y | timechart limit=0 span=10m count,...
by m_vivek Path Finder in Splunk Search 10-31-2015
0 9
0
9
alaking
I am trying to audit bandwidth usage. The following search works as expected, except the URLS flood the URL field. I ...
by alaking Explorer in Splunk Search 10-31-2015
0 1
0
1
markwymer
Hi all, I'm trying to extract the filename and file ext of a windows path into to different fields. The sourcetype i...
by markwymer Path Finder in Splunk Search 10-30-2015
0 5
0
5
a212830
Hi, I need a detailed report on search concurrency, for both scheduled and interactive searches. How would I get th...
by a212830 Champion in Splunk Search 10-30-2015
0 2
0
2
mkatz
I have a search that results in an IP address as the result with the field name clientIP: host=hostname SSL=TLSv1.2 ...
by mkatz New Member in Splunk Search 10-30-2015
0 6
0
6
aashish_122001
Can we put or in 2 regex conditions? If no, is there any alternative? for example index = idx1 | regex name = ^Aa ...
by aashish_122001 Explorer in Splunk Search 10-30-2015
0 3
0
3
chlily
The abclogs index contains a field call "userid" and there is similar field "identity" in the file totalname.csv. Now...
by chlily New Member in Splunk Search 10-30-2015
0 3
0
3
gcusello
I have to identify processes not running on a list of hosts. To do this, I have a lookup table with all the processes...
by SplunkTrust SplunkTrust in Splunk Search 10-30-2015
0 1
0
1
dmccabe2
Hi, We have a large amount of data in the Apache log files, and we do not want images to be indexed. How do I match...
by dmccabe2 New Member in Splunk Search 10-30-2015
0 3
0
3
pmcfadden91
Hi, I posted this question before, but was unable to attach the picture later in the thread. I am looking to add a c...
by pmcfadden91 Path Finder in Splunk Search 10-29-2015
0 5
0
5
DDerck
I would like to know if search performance could be increased by moving buckets from warm to cold? My main index cont...
by DDerck New Member in Splunk Search 10-29-2015
0 1
0
1
reswob4
So after reviewing a number of Q&As on this site, I created the following search to track currently logged on VPN use...
by reswob4 Builder in Splunk Search 10-29-2015
0 2
0
2
HattrickNZ
How do i assign a value to a variable in a splunk search and then use that variable in the search? something like v...
by HattrickNZ Motivator in Splunk Search 10-29-2015
0 5
0
5
bharathkumarnec
Hello All, I have created a bar graph in Splunk, Is there a possibility to show count(numeric value) on top of each ...
by bharathkumarnec Contributor in Splunk Search 10-29-2015
0 1
0
1
omuelle1
Hi Splunk Users, I created an alert using a field that I created and I only want to receive alerts where that field ...
by omuelle1 Communicator in Splunk Search 10-29-2015
0 4
0
4
ProudDevil
Hello, I need your help in making a search where I can group lines before and after a matching event in Splunk, same...
by ProudDevil New Member in Splunk Search 10-29-2015
0 4
0
4
raby1996
Hello all, I have two searches (shown below) where in the first, I extract two fields Code and Serial, and in the se...
by raby1996 Path Finder in Splunk Search 10-29-2015
0 5
0
5
smudge797
We have a way of calculating the percentage of time the status is in the “OK” state by using transaction to find the ...
by smudge797 Path Finder in Splunk Search 10-29-2015
0 2
0
2
rncjq0
My search displays this, but I when I change my search to this to get a clearer picture, I miss the time stamps - thi...
by rncjq0 New Member in Splunk Search 10-29-2015
0 6
0
6
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...