Splunk Search

Splunk Search
Community Activity
wysmith
I have a table with users and various fields relating to each event. Here is an example: user | City | State user1 | ...
by wysmith Engager in Splunk Search 08-12-2015
0 1
0
1
dhavamanis
Need your help, We have the search below to display a bar chart and it shows the total numbers, but how do we displa...
by dhavamanis Builder in Splunk Search 08-12-2015
0 2
0
2
MarkSplunker
Question 1: Is there a centralized place to search for all Splunk error messages? Searching answers.splunk.com I've n...
by MarkSplunker Explorer in Splunk Search 08-12-2015
0 8
0
8
cbeard604
Hi Everyone, We recently installed the R app in order to do some analysis with R expressions. We ran into an issue w...
by cbeard604 Explorer in Splunk Search 08-12-2015
0 1
0
1
aseid
Out of concern for performance, I need to put more than one search queries within same <query> and </query> block. O...
by aseid New Member in Splunk Search 08-12-2015
0 5
0
5
pmloikju
Hi, I project to realize a map of all attack on fortinet firewall like kaspersky cyber attack map. I receive log by...
by pmloikju Explorer in Splunk Search 08-12-2015
0 9
0
9
a212830
Hi, I need to run a report for specific indexes and hosts that show the number of sourcetypes being collected for a ...
by a212830 Champion in Splunk Search 08-12-2015
0 7
0
7
Murali2888
Hi, I would like to how we can pass a field as a parameter to the rex expression in Splunk. I am using the below whi...
by Murali2888 Communicator in Splunk Search 08-12-2015
0 4
0
4
snehalk
Hello All, I want to have one report/search string which states how much data was indexed for particular eventcode s...
by snehalk Communicator in Splunk Search 08-12-2015
0 1
0
1
snehalk
Hello All, I have one requirement where an alert needs to be triggered after three continuous search results reach a...
by snehalk Communicator in Splunk Search 08-12-2015
0 5
0
5
ramani2383
index="logmon_logs" |top useother=f limit=10 CHKOUTErrorMSG by _time|timechart count by CHKOUTErrorMSG |inputlookup ...
by ramani2383 New Member in Splunk Search 08-12-2015
0 1
0
1
wojtek_emca
Main search lists all events from sourcetype=A, there is a field CID. The second search list all events from sourcety...
by wojtek_emca New Member in Splunk Search 08-12-2015
0 3
0
3
ohlafl
The following query... index=os host=* (source=cpu NOT cpu="all") OR source=vmstat OR source=df | stats max(cpu) as ...
by ohlafl Communicator in Splunk Search 08-12-2015
0 6
0
6
Federica_92
Hi everyone, I'm struggling with this rex expression: query | rex field=source "/var/syslog*(?<remote_source>\w+...
by Federica_92 Communicator in Splunk Search 08-12-2015
0 4
0
4
DanPederEriksen
Hi, Stats count does not count all instances of variables when I use it with transactions. Search string: index=a...
by DanPederEriksen New Member in Splunk Search 08-12-2015
0 6
0
6
josefa123
Here is my search manager: var search1 = new SearchManager({ id: "rtCPUDaySearch", earliest_...
by josefa123 Explorer in Splunk Search 08-11-2015
0 1
0
1
thechivalrous
I have this specific issue where I'm trying to calculate percentage of online time for a set of devices. I created ...
by thechivalrous New Member in Splunk Search 08-11-2015
0 4
0
4
romedome
How can I take a value from the base search an pass it to a map search like so: <base search> | map "search index=a ...
by romedome Path Finder in Splunk Search 08-11-2015
0 5
0
5
chustar
I'm currently trying to generate a report describing "what's changed" since the last report. Currently, my idea is to...
by chustar Path Finder in Splunk Search 08-11-2015
0 6
0
6
edroche3rd
Hello All I am looking to search a number of fields (31) that may have the same value then count the number of times...
by edroche3rd Explorer in Splunk Search 08-11-2015
0 14
0
14
rakeshcse2
I have some .xml files at a location say: C/test/logs How can I configure Splunk to fetch those xml files and show ...
by rakeshcse2 New Member in Splunk Search 08-11-2015
0 11
0
11
hartfoml
OK this one might be a challenge I 7 services that restart at midnight. I have a report that comes out at 7 AM that ...
by hartfoml Motivator in Splunk Search 08-11-2015
0 4
0
4
splunkman341
Hi guys, So I currently have a search which has "the five most active OOID's by folder activity". The OOID (Organiza...
by splunkman341 Communicator in Splunk Search 08-11-2015
0 5
0
5
jizzmaster
I have a csv file as a lookup, named "resources.csv." Looking at the actual file, it has about 30,000 lines. In the S...
by jizzmaster Path Finder in Splunk Search 08-11-2015
0 11
0
11
OldManEd
I am running the following search: index=_internal source=*metrics.log earliest=07/01/2015:00:00:0 latest=08/10/20...
by OldManEd Builder in Splunk Search 08-11-2015
0 2
0
2
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...