Splunk Search

Splunk Search
Community Activity
Venkat_16
I have a log in the following format: username=nan time=09:00 operation=login username=ver time=10:00 opertiaon=logo...
by Venkat_16 Contributor in Splunk Search 08-24-2015
0 3
0
3
wang
I have stats output some numbers like min, max, avg. The numbers are left justifed and make it really hard to read. ...
by wang Path Finder in Splunk Search 08-24-2015
2 2
2
2
nickhills
I am looking to correlate events from two different sources whereby a rare event in source A, (in a 1 hour window) se...
by nickhills Ultra Champion in Splunk Search 08-24-2015
0 5
0
5
leonheart78
Below is the search which I'm trying: index=p_data sourcetype="p_sourcetype" | xmlkv | where EventId!="" | table sou...
by leonheart78 Explorer in Splunk Search 08-24-2015
0 10
0
10
Genti
say i am running a search like this: | metadata type=hosts | eval FirstSeen=firstTime | eval RecentSeen=recentTime |...
by Genti Splunk Employee Splunk Employee in Splunk Search 08-24-2015
1 2
1
2
nawneel
I am trying to use predict command from Splunk for predictive analysis. I would like to know certain details about di...
by nawneel Communicator in Splunk Search 08-24-2015
0 2
0
2
lakromani
I have a log some like this: Aug 23 19:22:19 server1 Peter logged in from 192.168.1.20 Aug 23 19:22:15 server1 Oleg ...
by lakromani Builder in Splunk Search 08-23-2015
0 6
0
6
liorfink
Hi all! I'm new to Splunk and I'm having trouble making my search correct. I've tried searching but found no case exa...
by liorfink Engager in Splunk Search 08-23-2015
0 2
0
2
tondapi
Hi, The search below is retrieving start time (due to transaction), but I need to pull end time and I don't know the...
by tondapi New Member in Splunk Search 08-23-2015
0 1
0
1
gmark
We have a single data simulator sending records to a socket, and a Splunk instance on a different server using that d...
by gmark Explorer in Splunk Search 08-23-2015
1 2
1
2
leonheart78
Hi, I'm trying to ingest multiple files with the below format: <?xml version="1.0" encoding="UTF-8"?> <BroadcastDa...
by leonheart78 Explorer in Splunk Search 08-23-2015
0 1
0
1
nadid
Hi all, I'm trying to create a query that gets the number of occurrences of certain Event per month. For that i get ...
by nadid Path Finder in Splunk Search 08-23-2015
0 3
0
3
amarish_vlabs
Could you please explain how joins work? Please give me some examples
by amarish_vlabs New Member in Splunk Search 08-23-2015
0 1
0
1
DrFedtke
Hi all, We want to compare "today" values in real-time with some aggregatedvalues of yesterday ("day -1"), "day -2",...
by DrFedtke Explorer in Splunk Search 08-22-2015
0 3
0
3
_gkollias
My use case is to find out how many transactions went out to a customer for a particular day. The results will inclu...
by _gkollias Builder in Splunk Search 08-22-2015
0 1
0
1
Laya123
Hi, Can anyone help how to calculate percentage for the report below for '%Act_fail_G_Total' host Ac...
by Laya123 Communicator in Splunk Search 08-21-2015
0 9
0
9
noybin
Hi, I have 2 sourcetypes: wineventlog:security and WinEventLog:Microsoft-Windows-Sysmon/Operational. I have extracte...
by noybin Communicator in Splunk Search 08-21-2015
0 1
0
1
ltrand
So, fun problem: We're wanting to do some data enrichment so that we can build good reports. What we want to do is ...
by ltrand Contributor in Splunk Search 08-21-2015
0 2
0
2
wragabrr
Is there a way to use the google map app or something similar in splunk 6? I have syslogs containing latitude and lo...
by wragabrr Engager in Splunk Search 08-21-2015
1 9
1
9
0range
How can I get more then 4 marks on x axis using timechart? In a search like this: earliest=-1d@d latest=-0d@d source...
by 0range Communicator in Splunk Search 08-21-2015
0 6
0
6
clairebesson
Hey everyone, Here is my problem: I have two sources (Source1 and Source2): * In source1 I have the field "device nu...
by clairebesson Explorer in Splunk Search 08-21-2015
0 3
0
3
ohlafl
I have a query that overlays the value of one date with the value of another date, it is put together as this: ... e...
by ohlafl Communicator in Splunk Search 08-21-2015
0 5
0
5
htkwan
Hello, I'm new to splunk. I need to evaluate result = sum(set A events) / sum (set B events). I've tried: sourcetyp...
by htkwan Path Finder in Splunk Search 08-21-2015
0 5
0
5
fredclown
So, the title says it all. I was looking in the db connect documentation and didn't see anything that answered this q...
by fredclown Builder in Splunk Search 08-20-2015
1 4
1
4
FritzWittwer_ol
I'm trying to build a form with a base search and post processing search as below. The panel gets loaded from a drill...
by FritzWittwer_ol Contributor in Splunk Search 08-20-2015
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...