Splunk Search

Splunk Search
Community Activity
RVDowning
Trying to find the average PlanSize per hour per day. source="*\\myfile.*" Action="OpenPlan" | transaction Guid star...
by RVDowning Contributor in Splunk Search 08-19-2015
0 6
0
6
ltrand
So I'm trying to display what the timespan is from start to finish of a bucket and add it as a new field to the table...
by ltrand Contributor in Splunk Search 08-19-2015
0 2
0
2
cysplunk978
Hi Splunkers! Is there a way to chang the color of iframe chart ? i only find it can work on dashboard ty:)
by cysplunk978 New Member in Splunk Search 08-19-2015
0 1
0
1
splunkman341
Hey guys, So I am trying to create a search that fetches the top 10 most active OOIDs (Organization ID Folder) by th...
by splunkman341 Communicator in Splunk Search 08-19-2015
0 8
0
8
lwolter
My transactions consist of two fields named JOBID and SUBJOBID. A typical search result contains events like JOBID=9...
by lwolter Explorer in Splunk Search 08-19-2015
1 12
1
12
icyfeverr
I am trying to find the best way to get the duration (in seconds) on a multiline event, possibly having it captured d...
by icyfeverr Path Finder in Splunk Search 08-19-2015
0 6
0
6
Kabobgub
Hello, after researching a lot of information I still can not recorgnise how to solve this problem. I have an xml fil...
by Kabobgub Explorer in Splunk Search 08-19-2015
1 13
1
13
pmloikju
Hi, I need to extract attack names from Fortigate logs. All attack logs are the same, but only a few are correctly e...
by pmloikju Explorer in Splunk Search 08-19-2015
0 4
0
4
sunnyparmar
Hi, I am trying to display logs for last 24 hrs on Splunk. My search is: index=peppol sourcetype=peppol-outbound | ...
by sunnyparmar Communicator in Splunk Search 08-19-2015
0 1
0
1
jackywsy
Hi Everyone, I have uploaded a CSV file to the lookup table. Only one column of data is in the list. for e.g. I put ...
by jackywsy Explorer in Splunk Search 08-19-2015
0 2
0
2
amarish_vlabs
Hi Team, I have a field which takes values from 1 to 100. So I want use the bin command in such a way so the output ...
by amarish_vlabs New Member in Splunk Search 08-19-2015
0 3
0
3
curtisb1024
In the process of trying to verify some summary index data I've noticed that timechart does not seem to return expect...
by curtisb1024 Path Finder in Splunk Search 08-19-2015
2 4
2
4
sunnyparmar
Hi, Could somebody tell me a simple way to calculate age of a file in Splunk via search? Thanks Sunny
by sunnyparmar Communicator in Splunk Search 08-19-2015
0 5
0
5
tzack
I am a Splunk newbie so I am not great on all the syntax you can use for searches. Your add-on was pointed out to me...
by tzack New Member in Splunk Search 08-18-2015
0 3
0
3
subtrakt
rex "(?i)(?P<testERROR>(\:[^\:]*){2})$" output :test string 123:test test test123 I have to keep the the 2nd : ma...
by subtrakt Contributor in Splunk Search 08-18-2015
0 6
0
6
lmaclean
Hi, I have searched and haven't really found anything to parse Clearswift mail logs. The issue is that one email ma...
by lmaclean Path Finder in Splunk Search 08-18-2015
1 3
1
3
AlexMcDuffMille
I have a JSON object that has an array inside of it. The array is a list of objects, not just a list of values. See...
by AlexMcDuffMille Communicator in Splunk Search 08-18-2015
2 1
2
1
ltrand
I'm attempting to use a CSV list of IP subnets to scan through firewall logs for hits, but it's not working out well....
by ltrand Contributor in Splunk Search 08-18-2015
0 2
0
2
m_vivek
I am very new to splunk . Step 1: I want to run a splunk search on my local machine data and import the results into...
by m_vivek Path Finder in Splunk Search 08-18-2015
0 1
0
1
jlosee
Hi, I'm redoing a search to avoid using join as it was truncating results. I'm trying to get a count after searching ...
by jlosee Path Finder in Splunk Search 08-18-2015
0 13
0
13
ErikaE
I have a time in the following format: 2015-08-11 16:31:25.973 in a field called "Last Modified On". The data comes ...
by ErikaE Communicator in Splunk Search 08-18-2015
0 2
0
2
nmaiorana
We are running a CUSUM function where we do not want the value to run away either too high or too low (negative). Ide...
by nmaiorana Explorer in Splunk Search 08-18-2015
0 13
0
13
mcgeeaw
I have a log message that contains white space so it is logged with double quotes: reason="enter reason here" The pr...
by mcgeeaw Engager in Splunk Search 08-18-2015
0 1
0
1
ppaveld
Hi, I have a table like this: userID is_successful version userA true ...
by ppaveld Engager in Splunk Search 08-18-2015
1 4
1
4
otman01
Hi everyone, I want to make a table that gives me the quantity of purchases for each product for the last 3 days. I...
by otman01 Communicator in Splunk Search 08-18-2015
0 3
0
3
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...