Splunk Search

Splunk Search
Community Activity
cevans99
I am fairly new to Splunk so forgive me if this is a simple question. I have a lookup table with the following data: ...
by cevans99 New Member in Splunk Search 10-20-2015
0 2
0
2
keithcoyle
Hey everyone We updated to Splunk 6.2.6 and now some of our searches don't work anymore, and I was wondering if som...
by keithcoyle New Member in Splunk Search 10-20-2015
0 6
0
6
HeinzWaescher
Hi, I would like to group the daily users by their number of active days during the last 2 weeks. My current search ...
by HeinzWaescher Motivator in Splunk Search 10-20-2015
0 10
0
10
bworrellZP
Yesterday I was asked if I can swap out time chart, so that the time is on the top, and user name is on the left. Ba...
by bworrellZP Communicator in Splunk Search 10-20-2015
0 2
0
2
hartfoml
I have this search host=MyIndeders sourcetype=cpu | multikv fields CPU pctUser | timechart span=5m avg(pctUser) AS "...
by hartfoml Motivator in Splunk Search 10-20-2015
1 10
1
10
IRHM73
Hi, I wonder whether someone could help me please. I'm extracting a time stamp in the format 2015-01-31T23:59:55.281...
by IRHM73 Motivator in Splunk Search 10-20-2015
0 2
0
2
clorne
Hello, I have the following data (this is the result of a transaction): Date Hour Paypload ev...
by clorne Communicator in Splunk Search 10-20-2015
0 9
0
9
msudhindra
Hello, I have a CURL script that generates a CSV file, and I would like to use that CSV file as a lookup for some se...
by msudhindra Path Finder in Splunk Search 10-19-2015
2 1
2
1
jamesar
Hi Splunkers, I’m having problems with slow queries when returning a fixed number of events starting from a specifie...
by jamesar Explorer in Splunk Search 10-19-2015
0 1
0
1
peetchow
I have dbdump from my vulnerability software RetinaCS and dbdump from McAfee. I want to compare the assetNames field...
by peetchow Loves-to-Learn Lots in Splunk Search 10-19-2015
0 1
0
1
tmarlette
So I have a search that I am building, though the results must be output into a table, due to not all fields being pr...
by tmarlette Motivator in Splunk Search 10-19-2015
0 6
0
6
splunknewbieste
Assume each event includes 2 fields: path and duration among other fields. Path can have values: (i) type1 = /x/y/,...
by splunknewbieste New Member in Splunk Search 10-19-2015
0 3
0
3
a212830
Hi, Is it possible to get the data of the most recent event per sourcetype when using tstats? I have a search - |ts...
by a212830 Champion in Splunk Search 10-19-2015
0 2
0
2
OMohi
What does normalized search in the job inspector do. How is it different from an actual search? Please let me know. ...
by OMohi Path Finder in Splunk Search 10-19-2015
0 1
0
1
harish_ka
After the transaction command, I got a set of events as one event. Now I want to filter the logs from this transactio...
by harish_ka Communicator in Splunk Search 10-19-2015
0 10
0
10
matt4321
Are there any issues with Splunk 6.3 and the top command? I am trying to run a query that works fine in 6.2 and belo...
by matt4321 Explorer in Splunk Search 10-19-2015
0 1
0
1
mitchabaza
I've created a summary index that counts transactions by customer, transaction type, and hour. I'd like to create we...
by mitchabaza Explorer in Splunk Search 10-19-2015
0 4
0
4
spetzd1
So, I have a very basic report I am trying to generate that takes an extracted field called MatchesFound and sums up ...
by spetzd1 Engager in Splunk Search 10-19-2015
0 2
0
2
lovenyberg
Connecting to the mobile server via a web browser works, but not from within the Splunk Mobile IOS app. We are getti...
by lovenyberg New Member in Splunk Search 10-19-2015
0 2
0
2
rjuliani
Hi everyone! I'm trying to get some useful stats on my logged data. I have 3 attributes in each log entry, HARVEST_D...
by rjuliani New Member in Splunk Search 10-19-2015
0 10
0
10
yasaracar
I need to see which questions a user answered. It is a multiple value field. Possible values: question="1" or questi...
by yasaracar Explorer in Splunk Search 10-19-2015
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I've put together this regex which works perfectly in Re...
by IRHM73 Motivator in Splunk Search 10-19-2015
0 3
0
3
clorne
Hello, I would like to define a MACRO that converts hexadecimal field into a binary fields because I often have to p...
by clorne Communicator in Splunk Search 10-19-2015
0 3
0
3
hemalalli
I need to insert some records to lookup table and make sure that the lookup table should not allow the duplicate inse...
by hemalalli Explorer in Splunk Search 10-18-2015
0 1
0
1
sankalpsah
I am extracting the type of node: "namenode" or "workernode". Then I get the value of another field say "idle time" f...
by sankalpsah New Member in Splunk Search 10-18-2015
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...