Splunk Search

Splunk Search
Community Activity
akawacz
Hi, Can FOREACH commnad can read text value ? I am having issue to create new columns foreach IM_* [eval TYPE='<<F...
by akawacz Path Finder in Splunk Search 10-27-2015
0 6
0
6
niqbal
I want to verify the correctness of my searches without using the Splunk server. It will be good enough if I can copy...
by niqbal Engager in Splunk Search 10-27-2015
0 1
0
1
mydog8it
I am searching through the router and switch syslog data trying to find spanning tree state changes for a given time ...
by mydog8it Builder in Splunk Search 10-26-2015
0 2
0
2
raby1996
Hi all, Currently I have the following search- | eval nowstring=strftime(now(), "%Y-%m-%d") | eval nowstring2=strpti...
by raby1996 Path Finder in Splunk Search 10-26-2015
0 2
0
2
siddhu_93
Hi, I need a better search than this: index=shop sourcetype="source1" | chart count by action,productId | append [s...
by siddhu_93 Engager in Splunk Search 10-26-2015
0 4
0
4
bruno_eduardo
Hi Everyone, I would like to add a row, about a total (sum), for each segment list (see the picture), and if a list ...
by bruno_eduardo Path Finder in Splunk Search 10-26-2015
0 5
0
5
reswob4
I have logs that have the following two formats 1. Oct 26 13:22:55 1.2.3.4 1 2015-10-26T13:22:51.480-04:00 Device.do...
by reswob4 Builder in Splunk Search 10-26-2015
0 3
0
3
peterdawood
A noob here, but I have a need that I cannot seem to figure out. Due to some internal politics that are slow in gett...
by peterdawood New Member in Splunk Search 10-26-2015
0 2
0
2
vtsguerrero
Hey folks, sup? Can anyone tell me if this is something about software licensing or sorta? I have just extracted li...
by vtsguerrero Contributor in Splunk Search 10-26-2015
0 6
0
6
anushareddy6767
I'm learning splunk and I would like to write Regex commands. Can anyone suggest best way to master Regex commands. ...
by anushareddy6767 Explorer in Splunk Search 10-26-2015
1 3
1
3
jclemons7
Hello, I'm trying to create an eval statement that evaluates if a string exists OR another string exists. For exam...
by jclemons7 Path Finder in Splunk Search 10-26-2015
1 2
1
2
n_young
Using splunk to look at some auth data, and want to get search results that show the number of countries each user ha...
by n_young New Member in Splunk Search 10-26-2015
0 2
0
2
deanamite91
I have the following search: index="commercial_performance" $month_token$ $Customer_token$ Cat1="Efficiency *" OR C...
by deanamite91 Explorer in Splunk Search 10-26-2015
1 1
1
1
splunksurekha
I am using below query : `linux-cpu` | search application=pc4_BizX host=* sub_module=* | stats avg(pctIdle) AS pctLo...
by splunksurekha Path Finder in Splunk Search 10-26-2015
1 2
1
2
jsven7
Hi I'm using field extractor for messages like the one below. The first message is fine. For some reason the extract...
by jsven7 Communicator in Splunk Search 10-26-2015
0 2
0
2
joea9
I want to be able to enrich my Splunk search results using data in a MySQL database. Where the 'hostname' field in m...
by joea9 Explorer in Splunk Search 10-25-2015
0 4
0
4
hylam
Can I real-time search for the last 48 hours and hide the results in the last 24 hours? How about now-30d to now-29d?...
by hylam Contributor in Splunk Search 10-25-2015
0 21
0
21
akhanVG
Apologies for the confusing title We have 1 search that gives us Revenue To Date - (*s are to mask sensitrive info) ...
by akhanVG Path Finder in Splunk Search 10-24-2015
0 2
0
2
dhavamanis
Need your help, Can you please help me to get the maximum totalresponsetime for the top 5 URL grouped by testtime? C...
by dhavamanis Builder in Splunk Search 10-24-2015
0 4
0
4
aartist
I like to find out how a particular field is extracted from a given sourcetype. Can I find this via splunk front end ...
by aartist New Member in Splunk Search 10-24-2015
0 2
0
2
hlarimer
I have a search that tells me when a system doesn't report into splunk after a threshold of an hour: |metadata index...
by hlarimer Communicator in Splunk Search 10-23-2015
1 7
1
7
runiyal
In my log file, I have lot of messages saying upload or search got completed in x seconds. Like - Search Completed s...
by runiyal Path Finder in Splunk Search 10-23-2015
0 1
0
1
dhavamanis
We have filed "status' and it will capture the http status code like 200, 301,302,404,503..etc. We want to setup aler...
by dhavamanis Builder in Splunk Search 10-23-2015
0 1
0
1
GeorgeStarkey
I have dashboards that show various metrics over a time window. It appears that in 6.3 the timecharting display is se...
by GeorgeStarkey Path Finder in Splunk Search 10-23-2015
0 1
0
1
gesman
We have data set which aggregated sessions with it's eventcount for each event. We are looking at setting up an alert...
by gesman Communicator in Splunk Search 10-23-2015
0 2
0
2
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...