Splunk Search

Splunk Search
Community Activity
edrivera3
Hi I want to extract the field names and field values of my events. My event looks like this: Step: 1000 Result: b...
by edrivera3 Builder in Splunk Search 10-22-2015
0 8
0
8
john_glasscock
I need to extract a session ID out of events, but the special character is causing me problems. Example: Oct 22 08:...
by john_glasscock Path Finder in Splunk Search 10-22-2015
0 3
0
3
lennys26
I have a search that returns server events and would like to know when this event is NOT followed by a recovery messa...
by lennys26 Communicator in Splunk Search 10-22-2015
0 2
0
2
jeskandarian
Search: index=exp eventName="business:SelfServ-ChangeTrip" ChangeBookingEventType=ChangeBookingPayloadChunk hotelCha...
by jeskandarian Engager in Splunk Search 10-22-2015
0 3
0
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the the search below to return values in a tab...
by IRHM73 Motivator in Splunk Search 10-22-2015
0 20
0
20
THi
I have log lines stating service up/downtime in several slightly differing human readable formats where the hour and ...
by THi Explorer in Splunk Search 10-22-2015
0 1
0
1
jsven7
Working with the following: EventStarts.txt UserID, Start Date, Start Time SpecialEventStarts.txt UserID, Start Dat...
by jsven7 Communicator in Splunk Search 10-22-2015
0 11
0
11
Plotkowski
I have a CSV file with a lookup table for some Windows event codes. The description is in German and there are some ä...
by Plotkowski Path Finder in Splunk Search 10-22-2015
0 2
0
2
ruhjuh
Is it possible to remove an asterisk from the returned data for a table? I tried to use: rex "Data=(?<Message>[^C]...
by ruhjuh Explorer in Splunk Search 10-22-2015
0 7
0
7
jcorominas
Dear all, Data is indexed from a CSV file. I am trying to calculate the amount of seconds between a couple of times...
by jcorominas Explorer in Splunk Search 10-22-2015
0 6
0
6
ADTJedi
I am conducting the following search (account names have been hidden): sourcetype=WinEventLog:Security EventCode=474...
by ADTJedi Engager in Splunk Search 10-21-2015
0 7
0
7
adamtech1
I'm trying to query the event log and iis logs at the same time. I would like to correlate application pool crashes/...
by adamtech1 New Member in Splunk Search 10-21-2015
0 2
0
2
raby1996
Hi all I've been trying to separate the values of a stats table that looks similar to what i have below. I've used d...
by raby1996 Path Finder in Splunk Search 10-21-2015
0 2
0
2
Sampathu
Hi, When I run the searches below separately, they give me exact result, but when I tried joining them, it was not ...
by Sampathu Explorer in Splunk Search 10-21-2015
0 1
0
1
balach
How to write a regular expression for capturing elapsed time of requests, with a log in this format. .......status=[...
by balach New Member in Splunk Search 10-21-2015
0 4
0
4
mctester
Where do we actually get user ended search history from to fill the Search Assistant “My Search History”? (4.1) See ...
by mctester Communicator in Splunk Search 10-21-2015
1 2
1
2
clopes
Hi all, I'm trying to create a sum of fields inside a row, but I can't figure how to do it. This is my scenario: I ...
by clopes Engager in Splunk Search 10-21-2015
0 2
0
2
BlueSocket
Dear All, I am using the Splunk App for Windows and I am trying to get a chart out looking something like: Computer...
by BlueSocket Contributor in Splunk Search 10-21-2015
0 1
0
1
amljohnson
This is probably a very basic Splunk question, but as I move beyond basic searches, these are the kinds of use cases ...
by amljohnson Explorer in Splunk Search 10-21-2015
0 4
0
4
joxley
I have a sourcetype that represents transactions. On the sourcetype are 3 fields of importance to this question,:an ...
by joxley Path Finder in Splunk Search 10-21-2015
0 2
0
2
jsven7
Hello Data example: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MDDRJS) I have to int...
by jsven7 Communicator in Splunk Search 10-21-2015
0 4
0
4
rroberts
I upgraded to Splunk 6.3 and it's working beautifully, however, I no longer get "matching terms" as I type in the sea...
by rroberts Splunk Employee Splunk Employee in Splunk Search 10-21-2015
0 3
0
3
Murali2888
Hi All, I have a search query like below. [search A | fields B,C] | search (D OR E) | fields F | table, B,C,F. Sea...
by Murali2888 Communicator in Splunk Search 10-21-2015
0 3
0
3
gbronner_rbc
This command does not work. index=grb_test sourcetype=QServiceManagerFormat | source="\\\\netapp4\\Quants\\ST\logs\...
by gbronner_rbc Explorer in Splunk Search 10-21-2015
0 2
0
2
jawebb
I have a field of names from two indexes and wish to find the unique values between them. I thought I should have to ...
by jawebb Explorer in Splunk Search 10-21-2015
0 6
0
6
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...