Splunk Search

Splunk Search
Community Activity
deepthi5
Hi Team, Again an urgent requirement. I have got a couple csv files with source name c:\\budapest.csv, c:\\singapore...
by deepthi5 Path Finder in Splunk Search 07-13-2015
0 1
0
1
etaga
I installed and configured Universal Forwarder in AIX but it does not send data to splunk server. I configured index ...
by etaga New Member in Splunk Search 07-13-2015
0 2
0
2
rsathish47
Hi all, I found blogs on IIS logs and Spunk 6. I didn't use the INDEXED_EXTRACTIONS, but why are fields still gettin...
by rsathish47 Contributor in Splunk Search 07-13-2015
0 3
0
3
HeinzWaescher
Hi, My search looks like this: base search... | timechart span=1d dc(user_id) AS daily_customers | timechart span=...
by HeinzWaescher Motivator in Splunk Search 07-13-2015
0 5
0
5
vbumgarn
Given the events: 2012-03-06 01:02:00 a=1 b=2 2012-03-06 02:03:00 a=2 b=3 and the query: * | stats count latest(a...
by vbumgarn Path Finder in Splunk Search 07-12-2015
4 9
4
9
splunker12er
How does data model acceleration help in generating a report faster? Creating a new data model from a 'root event' -...
by splunker12er Motivator in Splunk Search 07-12-2015
0 4
0
4
marcoscala
Hi All, I'm trying to parse multiline structured tabular events like this: CPU Schedule Job ...
by marcoscala Builder in Splunk Search 07-12-2015
0 5
0
5
splunker12er
Search job Inspector: This search has completed and has returned 31232 results by scanning 434213123 events in 47.20...
by splunker12er Motivator in Splunk Search 07-12-2015
0 1
0
1
clomeli
This may be a silly question, but how does one manage memory while returning data from a search? The results are bei...
by clomeli Engager in Splunk Search 07-11-2015
0 1
0
1
hartfoml
I am doing a search from two databases and comparing data from both. I am using the appenccols command to get the da...
by hartfoml Motivator in Splunk Search 07-11-2015
0 2
0
2
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |eval x=substr(ResponseDisplay,1,3) |eval y=substr(AvailabilityDisplay,1,3)...
by zd00191 Communicator in Splunk Search 07-11-2015
0 1
0
1
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |rename ResponseDisplay AS "Application Response", AvailabilityDisplay AS ...
by zd00191 Communicator in Splunk Search 07-10-2015
0 5
0
5
Raghav2384
Experts, I am tired of trying to make this work  . We have two instances, one is a distributed search with (1SH and...
by Raghav2384 Motivator in Splunk Search 07-10-2015
1 6
1
6
kholleran
Hello, Disk space on a series of servers is monitored every 10 minutes. What I want to do is run a search that says...
by kholleran Communicator in Splunk Search 07-10-2015
0 4
0
4
purva13
I am new to Splunk and trying to know more about it. I have a dashboard where I am taking inputs from user in the for...
by purva13 Explorer in Splunk Search 07-10-2015
0 4
0
4
heilman
Hello, I am attempting to run a search that will only include data occurring before 6 AM or after 6 PM, then group t...
by heilman New Member in Splunk Search 07-10-2015
0 1
0
1
mikesangray
I was looking at the Data Summary information on the Search page and noticed that there doesn't seem to be a way to e...
by mikesangray Path Finder in Splunk Search 07-10-2015
0 3
0
3
Dallastek
sourcetype=mysource Name=web_access `myfilter` | stats count(Source_Host) as temp by Source_Host, Dest_Host | sort -t...
by Dallastek Explorer in Splunk Search 07-10-2015
0 6
0
6
lys1030
My stats contain an entry called "index". How to get the head K of each index type? For example I want the top 10 in ...
by lys1030 Explorer in Splunk Search 07-10-2015
0 2
0
2
xvxt006
Hi i have this query - sourcetype=access_combined_cookie uri="xxxxx" jsession!=- | bucket _time span=5m | stats c...
by xvxt006 Contributor in Splunk Search 07-10-2015
0 7
0
7
stephenlclarke
I have two queries that I want to merge into one. First query: <pre> sourcetype="sourceType1" rex "Application=...
by stephenlclarke New Member in Splunk Search 07-10-2015
0 5
0
5
kalua
I am trying to write a query which returns the values in myCol which have a count greater than 3 times the standard d...
by kalua New Member in Splunk Search 07-10-2015
0 1
0
1
nitingurram
I have a search index=* sourcetype=tsv Transaction=* Jmeter_measure="ok.pct90"| chart avg(Jmeter_RT_val) by Transact...
by nitingurram New Member in Splunk Search 07-10-2015
0 1
0
1
rsathish47
hi All, is their way alert(search query) can distinguish between weekdays, weekends, monthend? Thanks Sathish R
by rsathish47 Contributor in Splunk Search 07-10-2015
0 1
0
1
responsys_cm
I'm trying to figure out the smartest way to track vulnerability data over time and account for how DHCP may mean tha...
by responsys_cm Builder in Splunk Search 07-10-2015
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors