Splunk Search

Splunk Search
Community Activity
HeinzWaescher
Hi, I'm wondering why Splunk starts rounding to the next integer in the second row. The command behind this is just:...
by HeinzWaescher Motivator in Splunk Search 10-27-2015
0 9
0
9
a212830
Hi, I had a customer complaining that the Universal Forwarder on their server was running very hot. I checked, and l...
by a212830 Champion in Splunk Search 10-27-2015
0 1
0
1
lmaclean
What I am trying to do is write a report on bandwidth from firewall logs based upon different sites and work out the ...
by lmaclean Path Finder in Splunk Search 10-27-2015
0 1
0
1
splunksurekha
When I run the search below, I get correct results without any decimal value in it. `linux-cpu` | search applicatio...
by splunksurekha Path Finder in Splunk Search 10-27-2015
1 1
1
1
irhen
I have a numeric field. For example: 123 2356 35896 24569 0052 00201 0053 82300521 8350053 I need to convert a value...
by irhen New Member in Splunk Search 10-27-2015
0 4
0
4
akawacz
Hi, Can FOREACH commnad can read text value ? I am having issue to create new columns foreach IM_* [eval TYPE='<<F...
by akawacz Path Finder in Splunk Search 10-27-2015
0 6
0
6
niqbal
I want to verify the correctness of my searches without using the Splunk server. It will be good enough if I can copy...
by niqbal Engager in Splunk Search 10-27-2015
0 1
0
1
mydog8it
I am searching through the router and switch syslog data trying to find spanning tree state changes for a given time ...
by mydog8it Builder in Splunk Search 10-26-2015
0 2
0
2
raby1996
Hi all, Currently I have the following search- | eval nowstring=strftime(now(), "%Y-%m-%d") | eval nowstring2=strpti...
by raby1996 Path Finder in Splunk Search 10-26-2015
0 2
0
2
siddhu_93
Hi, I need a better search than this: index=shop sourcetype="source1" | chart count by action,productId | append [s...
by siddhu_93 Engager in Splunk Search 10-26-2015
0 4
0
4
bruno_eduardo
Hi Everyone, I would like to add a row, about a total (sum), for each segment list (see the picture), and if a list ...
by bruno_eduardo Path Finder in Splunk Search 10-26-2015
0 5
0
5
reswob4
I have logs that have the following two formats 1. Oct 26 13:22:55 1.2.3.4 1 2015-10-26T13:22:51.480-04:00 Device.do...
by reswob4 Builder in Splunk Search 10-26-2015
0 3
0
3
peterdawood
A noob here, but I have a need that I cannot seem to figure out. Due to some internal politics that are slow in gett...
by peterdawood New Member in Splunk Search 10-26-2015
0 2
0
2
vtsguerrero
Hey folks, sup? Can anyone tell me if this is something about software licensing or sorta? I have just extracted li...
by vtsguerrero Contributor in Splunk Search 10-26-2015
0 6
0
6
anushareddy6767
I'm learning splunk and I would like to write Regex commands. Can anyone suggest best way to master Regex commands. ...
by anushareddy6767 Explorer in Splunk Search 10-26-2015
1 3
1
3
jclemons7
Hello, I'm trying to create an eval statement that evaluates if a string exists OR another string exists. For exam...
by jclemons7 Path Finder in Splunk Search 10-26-2015
1 2
1
2
n_young
Using splunk to look at some auth data, and want to get search results that show the number of countries each user ha...
by n_young New Member in Splunk Search 10-26-2015
0 2
0
2
deanamite91
I have the following search: index="commercial_performance" $month_token$ $Customer_token$ Cat1="Efficiency *" OR C...
by deanamite91 Explorer in Splunk Search 10-26-2015
1 1
1
1
splunksurekha
I am using below query : `linux-cpu` | search application=pc4_BizX host=* sub_module=* | stats avg(pctIdle) AS pctLo...
by splunksurekha Path Finder in Splunk Search 10-26-2015
1 2
1
2
jsven7
Hi I'm using field extractor for messages like the one below. The first message is fine. For some reason the extract...
by jsven7 Communicator in Splunk Search 10-26-2015
0 2
0
2
joea9
I want to be able to enrich my Splunk search results using data in a MySQL database. Where the 'hostname' field in m...
by joea9 Explorer in Splunk Search 10-25-2015
0 4
0
4
hylam
Can I real-time search for the last 48 hours and hide the results in the last 24 hours? How about now-30d to now-29d?...
by hylam Contributor in Splunk Search 10-25-2015
0 21
0
21
akhanVG
Apologies for the confusing title We have 1 search that gives us Revenue To Date - (*s are to mask sensitrive info) ...
by akhanVG Path Finder in Splunk Search 10-24-2015
0 2
0
2
dhavamanis
Need your help, Can you please help me to get the maximum totalresponsetime for the top 5 URL grouped by testtime? C...
by dhavamanis Builder in Splunk Search 10-24-2015
0 4
0
4
aartist
I like to find out how a particular field is extracted from a given sourcetype. Can I find this via splunk front end ...
by aartist New Member in Splunk Search 10-24-2015
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...

GA: S3 Promote for Historical Data Ingestion in Splunk Cloud

Ingest Historical S3 Data On-Demand: Announcing the General Availability of S3 Promote We’re excited to share ...