Splunk Search

Splunk Search
Community Activity
edrivera3
Hi I have a log file and I want to know how much time passed between HOST connection and disconnection. In the log, ...
by edrivera3 Builder in Splunk Search 07-15-2015
0 3
0
3
jorgeoa
Hello, I'm new with splunk and I'm trying to get all the different values of a field with stats values() command wit...
by jorgeoa Explorer in Splunk Search 07-15-2015
0 4
0
4
Shan
I have data in a log file as mentioned below. Can I split it using regex or any other options are available? 0010213...
by Shan Builder in Splunk Search 07-15-2015
0 6
0
6
theouhuios
Hello I have drop-down acting like a timepicker. So when a user selects "Current Month", the $time$ (token for the ...
by theouhuios Motivator in Splunk Search 07-15-2015
0 3
0
3
dkarthik16
I have a log like this 1000107KARTHIk100203YES I want to extract like this 1000 07 KARTHIK 1002 03 RITHVIK where ...
by dkarthik16 New Member in Splunk Search 07-15-2015
0 7
0
7
smashedpumpkins
I'm having trouble taking the results from a subsearch and joining them with the outer search. My goal is to take a s...
by smashedpumpkins Explorer in Splunk Search 07-15-2015
1 4
1
4
neilhiley
Hi. I want to display two figures of the total avg per day and display from previous day. With showing a percentage ...
by neilhiley Explorer in Splunk Search 07-15-2015
0 1
0
1
felipesewaybric
How can I use Chart Overlay with an epoch field converting the same in time? I have 2 fields, one is Intevalo with e...
by felipesewaybric Contributor in Splunk Search 07-15-2015
0 13
0
13
josefa123
I have a DeviceA that I am monitoring. There are cpu and ram. Metrics are on different event (cpu has its own event a...
by josefa123 Explorer in Splunk Search 07-15-2015
0 1
0
1
josefa123
Hi. I have this table. As you can see there are 2 storeA in both normal and critical. The latest record is on the ...
by josefa123 Explorer in Splunk Search 07-15-2015
0 7
0
7
ssaenger
Hi, i am again struggling with regex. I have the following lines in a log file, some of the text is constantly in th...
by ssaenger Communicator in Splunk Search 07-15-2015
0 3
0
3
IRHM73
Hi, I wonder whether someone could help me please. I have a string of fields in my raw data in exactly the same form...
by IRHM73 Motivator in Splunk Search 07-15-2015
0 12
0
12
josefa123
I have search string like this counter Write Copies | dedup counter | where Value < 50 | rename Value as values a...
by josefa123 Explorer in Splunk Search 07-15-2015
2 6
2
6
jeffland
I'm trying to work out some sourcetype settings. The events look like this: 2015.07.13 08:38:47: system,DEBUG: <<Som...
by SplunkTrust SplunkTrust in Splunk Search 07-15-2015
0 4
0
4
kkarthik2
Example: My dashboard looks like 1:00 2:00 3:00 4:00 1. foo 100 200 ...
by kkarthik2 Observer in Splunk Search 07-14-2015
0 3
0
3
geetanjali
Hello I have 3 guest and each guest has 10 hosts in it. i want to display data in pie chart. my query conditions ar...
by geetanjali Path Finder in Splunk Search 07-14-2015
0 2
0
2
splunknewby
I'm using cidrmatch() to determine whether a particular IP is on a local network, but when I query Splunk it returns ...
by splunknewby Path Finder in Splunk Search 07-14-2015
0 9
0
9
rana_nour
index=gasf uri_path="*.aspx" (( eventtype="Hub" ) AND eventtype=*) | iplocation clientip | timechart span=1hr c by...
by rana_nour Explorer in Splunk Search 07-14-2015
0 1
0
1
athorat
Hi , We have many dashboards where they have more than 10 panels and each panel has it own search string. The common...
by athorat Communicator in Splunk Search 07-14-2015
0 2
0
2
BWhisler2015
Hello, I am working on a search and eventually a dashboard that displays the count per field based on the characteri...
by BWhisler2015 New Member in Splunk Search 07-14-2015
0 3
0
3
joseph_trinidad
Hi Splunk Experts, Currently I am creating a dashboard panel wherein I have to filter the results in my table based ...
by joseph_trinidad New Member in Splunk Search 07-14-2015
0 3
0
3
cykuan
HI All, Query1: (FAILED) COM source="/home/test/test.log" | rex field=_raw "^(?:[^,\n]*,){3}(?P<sender>\+\d+)" | d...
by cykuan New Member in Splunk Search 07-14-2015
0 2
0
2
BrentRiva
I'm using stats values(series) to print a list of all the indexes of a specific line of business. Specifically the se...
by BrentRiva Explorer in Splunk Search 07-14-2015
0 2
0
2
neilhiley
Have field (secs) and have 12 events 11 of them being under the SLA of 51(secs) I want to achieve a report to show pe...
by neilhiley Explorer in Splunk Search 07-14-2015
0 4
0
4
Maheshparsi
Hi All, I have 2 searches of a log file to be merged as one. When I execute them separately, it is working. Please f...
by Maheshparsi Explorer in Splunk Search 07-14-2015
0 4
0
4
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...