Splunk Search

Splunk Search
Community Activity
skoelpin
I have an index which processes around 10 million events per day. I did a few field extractions which had lookaheads ...
by SplunkTrust SplunkTrust in Splunk Search 08-11-2015
0 4
0
4
vbarna
Hi all, I am going to simplify my problem. I have two indexes with the following variables: index 1: time_in user_i...
by vbarna Engager in Splunk Search 08-11-2015
0 4
0
4
knielsen
Hello, Since we upgraded from Splunk 5 to Splunk 6.2.4, some of our searches run 10 to 20 times slower than before. ...
by knielsen Contributor in Splunk Search 08-11-2015
0 6
0
6
abovebeyond
Hello, My data looks like: I currently have this search: source=myapp test123 | stats count by type The resul...
by abovebeyond Communicator in Splunk Search 08-11-2015
0 4
0
4
pdjhh
Hi guys, I am ingesting Windows event logs including event code 5156 which is chewing up a lot of license. I have ha...
by pdjhh Communicator in Splunk Search 08-11-2015
0 13
0
13
antifreke
Good afternoon and happy monday! I'm working on trying to figure out a way to do the following : Count of vulnerabi...
by antifreke Path Finder in Splunk Search 08-11-2015
0 2
0
2
pinzer
Hi all, i need to change the destination of a report when clicking on the pie slice of a pie report. the query that ...
by pinzer Path Finder in Splunk Search 08-11-2015
0 1
0
1
brieucjulou
Hello everyone, I have been looking for an answer all over the forum and documentation, but it still won't work.. I...
by brieucjulou Engager in Splunk Search 08-11-2015
0 2
0
2
Federica_92
Hi everyone, I have a problem building an SPL query with the regular expression: This is an example of my data: Th...
by Federica_92 Communicator in Splunk Search 08-11-2015
0 6
0
6
splunked38
Hi, I've got two distinct searches producing tables for each, and I'd like to know if I can combine the two in one t...
by splunked38 Communicator in Splunk Search 08-11-2015
0 4
0
4
antonyhan
I am trying to order the bars within each time segment from largest to smallest? is there a way of doing it?
by antonyhan Path Finder in Splunk Search 08-10-2015
0 5
0
5
meenal901
Hi, I have a data of the form: Source,Date,Time Source1,20120904,000000 Source3,20120904,000000 Source1,20120904,000...
by meenal901 Communicator in Splunk Search 08-10-2015
0 4
0
4
changux
Hi all. I have two fields, in with values like 2015-08-04 05:52:42 and out with values like "2015-08-04 06:18:30" in...
by changux Builder in Splunk Search 08-10-2015
0 5
0
5
sameeripro
I am using the transaction command, but the events are not collated when they took place at the same time and directo...
by sameeripro Path Finder in Splunk Search 08-10-2015
0 1
0
1
eriklenaerts
Hey, I'm a first time user and I'd like to use splunk for observing performance issues in an application. We want t...
by eriklenaerts New Member in Splunk Search 08-10-2015
0 1
0
1
mgpspr
Hello community, I have a string .net clearing cache request for user took this many miliseconds: and .net clearing ...
by mgpspr New Member in Splunk Search 08-10-2015
0 8
0
8
msalaverry
Hi, I hope you can help me with this, I have 2 search results and I want to get the difference between both in the ...
by msalaverry New Member in Splunk Search 08-10-2015
0 11
0
11
mikaelbje
Just wondering if anybody's succeeded in creating an IP version agnostic regular expression? I'd like one regex to m...
by mikaelbje Motivator in Splunk Search 08-10-2015
1 2
1
2
slatta
Trying to use the sum of "docCount" in a transaction and use that value for the range and then run statistics by the ...
by slatta Explorer in Splunk Search 08-10-2015
0 3
0
3
Roopaul
What is the difference between search and real-time search? Doesn't the search provide the real-time data?
by Roopaul Explorer in Splunk Search 08-10-2015
0 2
0
2
SilviaGebel
Hi, currently I am trying to figure out how to chart the temperature by failures. The search I am creating is this:...
by SilviaGebel Path Finder in Splunk Search 08-10-2015
0 5
0
5
kmcarrol
Can someone explain to me how Search A can have 0 results, but the refined Search B has multiple results? They are ex...
by kmcarrol Path Finder in Splunk Search 08-10-2015
0 4
0
4
collier31200
Hello, I try to use the latest() option of eventstats in the following way: | eventstats latest(Status) AS Status_l...
by collier31200 Explorer in Splunk Search 08-10-2015
0 4
0
4
elekanne
I want to have the (sub)title of a pie chart changed to something like "value since 29 July 2015 21:58". That timesta...
by elekanne Explorer in Splunk Search 08-10-2015
0 4
0
4
faramarz
Hi! I am trying to run a search where it counts the number of new users who have made purchases in the previous day,...
by faramarz Path Finder in Splunk Search 08-09-2015
0 12
0
12
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors