Splunk Search

Splunk Search
Community Activity
raju4244
Dear All, I have one question. I have the data like below: field1: itema itemb itemb itemc itemd iteme iteme fiel...
by raju4244 Explorer in Splunk Search 08-12-2015
0 3
0
3
xueshanf
I am following this documentation: http://wiki.splunk.com/Community:BestPracticesForBackingUp to try to force a hot-t...
by xueshanf Explorer in Splunk Search 08-12-2015
0 2
0
2
a212830
Hi, I need to show a customer that their logs are appearing in Splunk, and want to list the host, sourcetype, and so...
by a212830 Champion in Splunk Search 08-12-2015
0 2
0
2
mattbirk
I am trying to figure out a way in Splunk to have the results highlighted if my if statement is true. For example, ...
by mattbirk Explorer in Splunk Search 08-12-2015
0 4
0
4
arkonner
I am using the following search to analyze which web pages have been visited. index="access_combined_apache" Sourc...
by arkonner Path Finder in Splunk Search 08-12-2015
0 6
0
6
hortonew
I'm trying to do something similar to what I have below, where I gather the latest transaction for when splunk was sh...
by hortonew Builder in Splunk Search 08-12-2015
0 4
0
4
wysmith
I have a table with users and various fields relating to each event. Here is an example: user | City | State user1 | ...
by wysmith Engager in Splunk Search 08-12-2015
0 1
0
1
dhavamanis
Need your help, We have the search below to display a bar chart and it shows the total numbers, but how do we displa...
by dhavamanis Builder in Splunk Search 08-12-2015
0 2
0
2
MarkSplunker
Question 1: Is there a centralized place to search for all Splunk error messages? Searching answers.splunk.com I've n...
by MarkSplunker Explorer in Splunk Search 08-12-2015
0 8
0
8
cbeard604
Hi Everyone, We recently installed the R app in order to do some analysis with R expressions. We ran into an issue w...
by cbeard604 Explorer in Splunk Search 08-12-2015
0 1
0
1
aseid
Out of concern for performance, I need to put more than one search queries within same <query> and </query> block. O...
by aseid New Member in Splunk Search 08-12-2015
0 5
0
5
pmloikju
Hi, I project to realize a map of all attack on fortinet firewall like kaspersky cyber attack map. I receive log by...
by pmloikju Explorer in Splunk Search 08-12-2015
0 9
0
9
a212830
Hi, I need to run a report for specific indexes and hosts that show the number of sourcetypes being collected for a ...
by a212830 Champion in Splunk Search 08-12-2015
0 7
0
7
Murali2888
Hi, I would like to how we can pass a field as a parameter to the rex expression in Splunk. I am using the below whi...
by Murali2888 Communicator in Splunk Search 08-12-2015
0 4
0
4
snehalk
Hello All, I want to have one report/search string which states how much data was indexed for particular eventcode s...
by snehalk Communicator in Splunk Search 08-12-2015
0 1
0
1
snehalk
Hello All, I have one requirement where an alert needs to be triggered after three continuous search results reach a...
by snehalk Communicator in Splunk Search 08-12-2015
0 5
0
5
ramani2383
index="logmon_logs" |top useother=f limit=10 CHKOUTErrorMSG by _time|timechart count by CHKOUTErrorMSG |inputlookup ...
by ramani2383 New Member in Splunk Search 08-12-2015
0 1
0
1
wojtek_emca
Main search lists all events from sourcetype=A, there is a field CID. The second search list all events from sourcety...
by wojtek_emca New Member in Splunk Search 08-12-2015
0 3
0
3
ohlafl
The following query... index=os host=* (source=cpu NOT cpu="all") OR source=vmstat OR source=df | stats max(cpu) as ...
by ohlafl Communicator in Splunk Search 08-12-2015
0 6
0
6
Federica_92
Hi everyone, I'm struggling with this rex expression: query | rex field=source "/var/syslog*(?<remote_source>\w+...
by Federica_92 Communicator in Splunk Search 08-12-2015
0 4
0
4
DanPederEriksen
Hi, Stats count does not count all instances of variables when I use it with transactions. Search string: index=a...
by DanPederEriksen New Member in Splunk Search 08-12-2015
0 6
0
6
josefa123
Here is my search manager: var search1 = new SearchManager({ id: "rtCPUDaySearch", earliest_...
by josefa123 Explorer in Splunk Search 08-11-2015
0 1
0
1
thechivalrous
I have this specific issue where I'm trying to calculate percentage of online time for a set of devices. I created ...
by thechivalrous New Member in Splunk Search 08-11-2015
0 4
0
4
romedome
How can I take a value from the base search an pass it to a map search like so: <base search> | map "search index=a ...
by romedome Path Finder in Splunk Search 08-11-2015
0 5
0
5
chustar
I'm currently trying to generate a report describing "what's changed" since the last report. Currently, my idea is to...
by chustar Path Finder in Splunk Search 08-11-2015
0 6
0
6
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

If you are designing a Splunk forwarding architecture, it can be tempting to place a Universal Forwarder (UF) ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...