Splunk Search

Splunk Search
Community Activity
raindrop18
I have these 3 stats count searches, but I would like to combine them as one and create a table. host ="web*" sourc...
by raindrop18 Communicator in Splunk Search 09-15-2015
0 4
0
4
akawacz
Hi Could you help me with Ranking rows? I was trying to use streamstats, but the issue here is that I have a Date re...
by akawacz Path Finder in Splunk Search 09-15-2015
0 1
0
1
schu777
I'm fairly new to Splunk and I looked at the possible "Questions that may already have your answer?" and didn't find ...
by schu777 Explorer in Splunk Search 09-15-2015
0 1
0
1
Cuyose
Is there an easy way to do an addaverages instead of addtotals? I have the following and can't seem to use any provid...
by Cuyose Builder in Splunk Search 09-15-2015
0 2
0
2
gsawyer1
Windows Security Event Log eventid 4738 has multiple fields that Splunk extracts values for, which is great, but we'r...
by gsawyer1 Engager in Splunk Search 09-15-2015
0 3
0
3
ceedwlt
I have a search that uses a subsearch to filter out certain kinds of logs. I'm using the format command to create the...
by ceedwlt Explorer in Splunk Search 09-15-2015
0 5
0
5
blebit
Hi everyone I have this field: File_Size="File size (bytes): [byte_size]", where byte_size is nr; e.g File_Size="Fil...
by blebit Path Finder in Splunk Search 09-15-2015
1 2
1
2
skender27
Hi, I have an addinput drop-down selection which applies to my dashboard (as a token). Is it possible to put a Check...
by skender27 Contributor in Splunk Search 09-15-2015
0 2
0
2
cjaramilloc
Hello I want to estimate a project, but based in EPS (events per second) not GB/day. How can I calculate the max of ...
by cjaramilloc Explorer in Splunk Search 09-14-2015
0 1
0
1
jclemons7
Hello.. is there anyway to round a decimal UP to the nearest whole number? (e.g.. I would like 0.1 to be 1, 8.00001 ...
by jclemons7 Path Finder in Splunk Search 09-14-2015
3 2
3
2
raindrop18
I have this search and I want only the unique count. I'm getting the unique count for the id field, but not for Permi...
by raindrop18 Communicator in Splunk Search 09-14-2015
0 1
0
1
jaredlaney
I have a search where, if I change from fast to verbose mode, I get different results. I'm wondering what are some p...
by jaredlaney Contributor in Splunk Search 09-14-2015
2 2
2
2
idab
I am having problems calculating the average memory utilization over different time spans. Not sure if I'm doing thi...
by idab Path Finder in Splunk Search 09-14-2015
1 4
1
4
ektasiwani
Hi, I have a file in local directory with name myconf.conf . This file is create by setup form filled by user. I wan...
by ektasiwani Communicator in Splunk Search 09-14-2015
0 1
0
1
harish0557
I want to extract fields from the below string(JSON) for: eval time for each javascript (i.e require.min.js) Load ti...
by harish0557 Explorer in Splunk Search 09-14-2015
1 3
1
3
henrikg
Hi, I'm new to Splunk searches and need help. We currently have searches to filter out log messages with log level ...
by henrikg New Member in Splunk Search 09-14-2015
0 2
0
2
keishamtcs
Hi Guys, Need help on merging data. i have two columns ( first and second) which has the same value but instead of ...
by keishamtcs Explorer in Splunk Search 09-14-2015
0 1
0
1
clairebesson
Hi everyone, I have a file with serial numbers and purchase order numbers. In a first table, I display a serial numb...
by clairebesson Explorer in Splunk Search 09-14-2015
0 10
0
10
lisaac
I have setup a 6.2.5 SH cluster. The SH cluster consists of 3 SHs and an additional host functioning as a SH deployer...
by lisaac Path Finder in Splunk Search 09-13-2015
0 1
0
1
LWilliamson1
I have a field that contains a sentence such as "I love wonderful food!" I want to be able to check each word against...
by LWilliamson1 Explorer in Splunk Search 09-13-2015
0 4
0
4
marellasunil
Hi, A job needs to be completed by 04:45 AM, Can some one help me to extract time from the logs, compare 04:45 AM an...
by marellasunil Communicator in Splunk Search 09-13-2015
0 3
0
3
ipsitam
Hi, I am struggling with xml data in splunk and need help in mvzip /mvexpand command to store multi value pairs with...
by ipsitam New Member in Splunk Search 09-13-2015
0 1
0
1
splunkvickyloui
Hi, I have inputs.conf with below configuration details: [monitor:///data02/appserver/jboss2/prod-ABCD-domain/serve...
by splunkvickyloui Explorer in Splunk Search 09-12-2015
0 4
0
4
brahimmouhdi
Hi, I am playing with secure.log entries for sshd and am able to find transactions based on pid from below; Sep 12 ...
by brahimmouhdi New Member in Splunk Search 09-12-2015
0 1
0
1
jsiker
I have this rex with an assigned field: regex _raw="(?<total_GC_time>0?.\d+)" I'm searching lines like this: 20...
by jsiker Explorer in Splunk Search 09-12-2015
0 10
0
10
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...