Splunk Search

Splunk Search
Community Activity
GeorgeStarkey
I have dashboards that show various metrics over a time window. It appears that in 6.3 the timecharting display is se...
by GeorgeStarkey Path Finder in Splunk Search 10-23-2015
0 1
0
1
gesman
We have data set which aggregated sessions with it's eventcount for each event. We are looking at setting up an alert...
by gesman Communicator in Splunk Search 10-23-2015
0 2
0
2
runiyal
In my log file, I have lot of messages saying upload or search got completed in x seconds. Like: Upload executed in ...
by runiyal Path Finder in Splunk Search 10-23-2015
0 4
0
4
rahmania
Hi, I want to find the IP address : 10.1.4.0 to 10.1.41.128 on Splunk Search. Is there an efficient query than OR ?...
by rahmania Engager in Splunk Search 10-23-2015
0 2
0
2
pepper_seattle
Hello, Splunk 6.3 allows you to set colors by ranges with a hard coded min and max setting that you can eval in your...
by pepper_seattle Path Finder in Splunk Search 10-23-2015
0 2
0
2
alemarzu
Hi guys, I'm trying to monitor command execution over certain directories in linux. To do that, I've made a report t...
by alemarzu Motivator in Splunk Search 10-23-2015
0 2
0
2
hhGA
Hi, I'm trying to import some CSV data into Splunk which is all on one line. The events are separated by a space an...
by hhGA Communicator in Splunk Search 10-23-2015
0 10
0
10
a5003976
Hello, thanks all in advance for your response. Can i merge events of windows, in particular field User_Name, when th...
by a5003976 Explorer in Splunk Search 10-23-2015
1 2
1
2
cheinlein
My search is simple: sourcetype=log_data | iplocation c_ip | geostats latfield=lat longfield=lon count but I have ...
by cheinlein Engager in Splunk Search 10-23-2015
0 1
0
1
Ricapar
I have a system for which I'd like to be able to report on how much time individual users spend logged in. However, ...
by Ricapar Communicator in Splunk Search 10-22-2015
0 3
0
3
sidekix24
Looking to switch the output from count to percentages on the search below. For example, they a looking to chart what...
by sidekix24 Path Finder in Splunk Search 10-22-2015
0 5
0
5
Lucas_K
I've found that my calculated fields are not behaving as expected. I have a search that uses a combination of fields...
by Lucas_K Motivator in Splunk Search 10-22-2015
0 3
0
3
jwalzerpitt
Running a query in Hunk against the firewall logs stored over the last 60 minutes and it appears to complete, but I s...
by jwalzerpitt Influencer in Splunk Search 10-22-2015
1 4
1
4
edrivera3
Hi I want to extract the field names and field values of my events. My event looks like this: Step: 1000 Result: b...
by edrivera3 Builder in Splunk Search 10-22-2015
0 8
0
8
john_glasscock
I need to extract a session ID out of events, but the special character is causing me problems. Example: Oct 22 08:...
by john_glasscock Path Finder in Splunk Search 10-22-2015
0 3
0
3
lennys26
I have a search that returns server events and would like to know when this event is NOT followed by a recovery messa...
by lennys26 Communicator in Splunk Search 10-22-2015
0 2
0
2
jeskandarian
Search: index=exp eventName="business:SelfServ-ChangeTrip" ChangeBookingEventType=ChangeBookingPayloadChunk hotelCha...
by jeskandarian Engager in Splunk Search 10-22-2015
0 3
0
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the the search below to return values in a tab...
by IRHM73 Motivator in Splunk Search 10-22-2015
0 20
0
20
THi
I have log lines stating service up/downtime in several slightly differing human readable formats where the hour and ...
by THi Explorer in Splunk Search 10-22-2015
0 1
0
1
jsven7
Working with the following: EventStarts.txt UserID, Start Date, Start Time SpecialEventStarts.txt UserID, Start Dat...
by jsven7 Communicator in Splunk Search 10-22-2015
0 11
0
11
Plotkowski
I have a CSV file with a lookup table for some Windows event codes. The description is in German and there are some ä...
by Plotkowski Path Finder in Splunk Search 10-22-2015
0 2
0
2
ruhjuh
Is it possible to remove an asterisk from the returned data for a table? I tried to use: rex "Data=(?<Message>[^C]...
by ruhjuh Explorer in Splunk Search 10-22-2015
0 7
0
7
jcorominas
Dear all, Data is indexed from a CSV file. I am trying to calculate the amount of seconds between a couple of times...
by jcorominas Explorer in Splunk Search 10-22-2015
0 6
0
6
ADTJedi
I am conducting the following search (account names have been hidden): sourcetype=WinEventLog:Security EventCode=474...
by ADTJedi Engager in Splunk Search 10-21-2015
0 7
0
7
adamtech1
I'm trying to query the event log and iis logs at the same time. I would like to correlate application pool crashes/...
by adamtech1 New Member in Splunk Search 10-21-2015
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...