Splunk Search

Splunk Search
Community Activity
JDukeSplunk
Hello, I have two different searches that return the data that I would like to see in one report. However, I am havi...
by JDukeSplunk Builder in Splunk Search 07-28-2015
0 2
0
2
chris1
Hello, When I search for some events (i.e index=main *password fail), I want to get the events with two lines before...
by chris1 Explorer in Splunk Search 07-28-2015
0 1
0
1
magicfletch
How can I have multiple splunk instances on linux and use boot-start? The command "./splunk enable boot-start" will ...
by magicfletch Engager in Splunk Search 07-28-2015
1 3
1
3
newbiesplunk
Hi, I have a file that contains the following format and I wish to only index information before the 1st two semi-co...
by newbiesplunk Path Finder in Splunk Search 07-28-2015
0 3
0
3
splunkman341
Hi guys, I am trying to edit a chart I have to have certain colors corresponding to the data inside. I have 5 server...
by splunkman341 Communicator in Splunk Search 07-28-2015
0 2
0
2
pkeller
Say I have a table ... host, IP, destinationHostname, Port, count host1 10.10.10.1 desthost1 9999, 33 host1 10.10.1...
by pkeller Contributor in Splunk Search 07-28-2015
0 4
0
4
mriley_cpmi
My question is similar to others around extracting new fields, but the answers I've tried to date haven't worked. Wh...
by mriley_cpmi Explorer in Splunk Search 07-28-2015
0 3
0
3
efrenette11
Hi, I try to extract fields fron this json. I've tried with jsonkv and spath and it looks like that ' does generate...
by efrenette11 Path Finder in Splunk Search 07-28-2015
0 5
0
5
Alan_Bradley
I am looking to read into SPLUNK a tab delimited file. But most of what I see is key based Field Extractions (, space...
by Alan_Bradley Path Finder in Splunk Search 07-28-2015
1 8
1
8
LuiesCui
Hi guys, I'm new to Splunk and I need ur help! I was trying to discard some specific events by regex and failed. He...
by LuiesCui Communicator in Splunk Search 07-28-2015
0 3
0
3
arber
Hi, we are using the SoS app, basically most of the searches are working. However we have noticed that the index sos...
by arber Communicator in Splunk Search 07-28-2015
0 1
0
1
valentin_bogdan
I have the following result from a simple search: I, [2015-07-23T15:30:39+02:00 (1437658239.654) #38640] INFO -- cc...
by valentin_bogdan Explorer in Splunk Search 07-28-2015
1 5
1
5
daniel_knights
We have Splunk running on all of our Windows Domain Controller servers (80 of them), but we seem to be missing events...
by daniel_knights New Member in Splunk Search 07-28-2015
0 1
0
1
jwquah
Hi Everyone, I'm testing a simple setup of a search head on a single 24 core host. The setup basically consists of 1...
by jwquah Path Finder in Splunk Search 07-27-2015
0 8
0
8
Ant1D
Hey, I have a column flashchart on a dashboard called dash_usage.xml. When I click on a bar(e.g. called User where v...
by Ant1D Motivator in Splunk Search 07-27-2015
2 5
2
5
mcvr
I wanted to extract the below values. Time TakenResponse code in the string - HTTP/1.1" 200 example, I need to know ...
by mcvr New Member in Splunk Search 07-27-2015
0 2
0
2
JohnSwansson
I have the following search: index=cashflow host=atm source=income OR source=outcome | eval accountStatus="Income: ...
by JohnSwansson Explorer in Splunk Search 07-27-2015
1 7
1
7
faramarz
Hey! I am trying to figure out how to aggregate a percentage of the total before another search like this: eventName...
by faramarz Path Finder in Splunk Search 07-27-2015
0 2
0
2
Madhan45
for example i have the string "update event from remote cache". i need to use NOT condition for this to capture ab ev...
by Madhan45 Path Finder in Splunk Search 07-27-2015
0 3
0
3
Shan
<messaging><messaging_id>data_range</messaging_id><currentTimeStamp>2015-06-11-090445569807</currentTimeStamp> <Trans...
by Shan Builder in Splunk Search 07-27-2015
0 4
0
4
splunkman341
Hi guys, I have this specific search that I want to edit: index="tablet_os" sourcetype="df" host=dc1* sda3 OR Data...
by splunkman341 Communicator in Splunk Search 07-27-2015
0 6
0
6
vtsguerrero
I have this indexed field which is read by splunk as a string, I need the average length, but the data has no Day, m...
by vtsguerrero Contributor in Splunk Search 07-27-2015
0 4
0
4
collier31200
Hello all, I'm trying to make a slippery transaction within 20 events. For example, my search return 40 events and ...
by collier31200 Explorer in Splunk Search 07-27-2015
0 2
0
2
pcorchary
I'm having trouble getting a Field Extraction that I need and hope for some advice. Below are three examples. Please ...
by pcorchary Explorer in Splunk Search 07-26-2015
0 1
0
1
jepoyyyy
Good day Splunkers. Splunk newbie here, I have been testing it for a few days already. I can now create searches and...
by jepoyyyy Explorer in Splunk Search 07-26-2015
0 2
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors