Splunk Search

Splunk Search
Community Activity
sushmitha_mj
I created a data model "Aggregate". I added an object which is a root search object named "usage". There is a search ...
by sushmitha_mj Communicator in Splunk Search 07-17-2015
0 6
0
6
ismarslomic
I have the following log statement, which uses semicolon delimiter and where i want to extract columns as specific fi...
by ismarslomic Path Finder in Splunk Search 07-17-2015
0 13
0
13
sieutruc
Hello, When i did a search on my SQL data, there are a lot of empty-value fields, which don't contain anything, i wa...
by sieutruc Contributor in Splunk Search 07-17-2015
1 4
1
4
gonzalogasca
Splunk Version 6.2.0 Splunk Build 237341 (MacOSX Yosemite) This is the line I'm looking to extract fields using rege...
by gonzalogasca New Member in Splunk Search 07-17-2015
0 3
0
3
roguepacket
I need help with a REGEX that needs to match multiple conditions in a log event. The event looks like this: 02:02:0...
by roguepacket Engager in Splunk Search 07-17-2015
2 4
2
4
sunnyparmar
Hi, My question is divided into 2 parts - 1.) I have a log file in which there are about 20-22 columns but i want t...
by sunnyparmar Communicator in Splunk Search 07-17-2015
0 7
0
7
vinchakov_a
Why splunk adds the date and time to the beginning of a log. How to clean it? Jul 15 09:27:20 172.16.19.1 Jul 15 201...
by vinchakov_a Path Finder in Splunk Search 07-16-2015
0 5
0
5
mistergreen28
I've got a KeywordList.csv lookup table with 3 columns (URI, URI_Keyword, URI_KeywordType). URI is a pre-existing fi...
by mistergreen28 New Member in Splunk Search 07-16-2015
0 3
0
3
RVDowning
I have a file: racf_username.csv located in /opt/splunk/etc/system/lookups which looks like; racf,username A123456,A ...
by RVDowning Contributor in Splunk Search 07-16-2015
0 4
0
4
BITSIntern
Hi guys, I need to have multiple searches running that pull up a word from the same field and replace it with anothe...
by BITSIntern Path Finder in Splunk Search 07-16-2015
0 10
0
10
mgianola
Is there any way to run Splunk queries from the RStudio IDE rather than from within the search bar?
by mgianola Explorer in Splunk Search 07-16-2015
0 1
0
1
lys1030
I have a field "F1" with values as following: I want to add a filed "F2" with value 'a' to all 'a*', with value 'b'...
by lys1030 Explorer in Splunk Search 07-16-2015
0 2
0
2
cjosephson
We have a set of hosts that all begin with the letter 'm' and we want to set DATETIME_CONFIG = CURRENT for them. If ...
by cjosephson Engager in Splunk Search 07-16-2015
0 4
0
4
Blackninja5431
I have a log containing memory usage over a period of time. How can I plot a line graph where the x-axis is the time,...
by Blackninja5431 New Member in Splunk Search 07-16-2015
0 2
0
2
jeastman
We have a key value pair where the value begins with a newline '\n'. It used to not have that newline and old search...
by jeastman Path Finder in Splunk Search 07-16-2015
1 3
1
3
alexlomas
Fairly new to Splunk so forgive the, what must be, fairly obvious question. We have an alert setup to email us if we...
by alexlomas Path Finder in Splunk Search 07-16-2015
0 2
0
2
clairebesson
Hi guys, Thanks for reading this question. I have a dashboard on which I display several fields in a table as you can...
by clairebesson Explorer in Splunk Search 07-16-2015
0 5
0
5
octavian_i
Hi, I am trying to pull some statistics on what is the most recent time a value in a lookuptable appeared in my Splu...
by octavian_i New Member in Splunk Search 07-16-2015
0 1
0
1
ssaenger
I would like to extract from my log file user details on how many time they have had a request to the SGW where the n...
by ssaenger Communicator in Splunk Search 07-16-2015
0 1
0
1
ambujhbti
Hello , I am trying to calculate time diff between two fields in a single event. My current search: sourcetype="XX...
by ambujhbti New Member in Splunk Search 07-16-2015
0 4
0
4
isedrof
Hey everybody, I'm making a comparison between two files: one uploaded as an index and the second as a lookup file. ...
by isedrof Engager in Splunk Search 07-16-2015
0 8
0
8
Ahmedkhalil
Can transaction be used with endswith only without use of startswith? I read that transaction is processing events fr...
by Ahmedkhalil Communicator in Splunk Search 07-16-2015
0 10
0
10
borgy95
I am writing a query to lookup processed web domains against a lookup list. I have defined a lookup named ss3url_loo...
by borgy95 Path Finder in Splunk Search 07-16-2015
0 5
0
5
big_twilde
Hi, I have a simple report/saved search with fixed time (-8@w1 to +1@w1) that calculates a timechart from a long lis...
by big_twilde Engager in Splunk Search 07-16-2015
0 1
0
1
Madhan45
delivery.csv contains the fields- key,name,product,priceorder.csv contains the fields- key,shipdate,location,delivery...
by Madhan45 Path Finder in Splunk Search 07-16-2015
0 3
0
3
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...