Splunk Search

Splunk Search
Community Activity
hartfoml
I am doing a search from two databases and comparing data from both. I am using the appenccols command to get the da...
by hartfoml Motivator in Splunk Search 07-11-2015
0 2
0
2
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |eval x=substr(ResponseDisplay,1,3) |eval y=substr(AvailabilityDisplay,1,3)...
by zd00191 Communicator in Splunk Search 07-11-2015
0 1
0
1
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |rename ResponseDisplay AS "Application Response", AvailabilityDisplay AS ...
by zd00191 Communicator in Splunk Search 07-10-2015
0 5
0
5
Raghav2384
Experts, I am tired of trying to make this work  . We have two instances, one is a distributed search with (1SH and...
by Raghav2384 Motivator in Splunk Search 07-10-2015
1 6
1
6
kholleran
Hello, Disk space on a series of servers is monitored every 10 minutes. What I want to do is run a search that says...
by kholleran Communicator in Splunk Search 07-10-2015
0 4
0
4
purva13
I am new to Splunk and trying to know more about it. I have a dashboard where I am taking inputs from user in the for...
by purva13 Explorer in Splunk Search 07-10-2015
0 4
0
4
heilman
Hello, I am attempting to run a search that will only include data occurring before 6 AM or after 6 PM, then group t...
by heilman New Member in Splunk Search 07-10-2015
0 1
0
1
mikesangray
I was looking at the Data Summary information on the Search page and noticed that there doesn't seem to be a way to e...
by mikesangray Path Finder in Splunk Search 07-10-2015
0 3
0
3
Dallastek
sourcetype=mysource Name=web_access `myfilter` | stats count(Source_Host) as temp by Source_Host, Dest_Host | sort -t...
by Dallastek Explorer in Splunk Search 07-10-2015
0 6
0
6
lys1030
My stats contain an entry called "index". How to get the head K of each index type? For example I want the top 10 in ...
by lys1030 Explorer in Splunk Search 07-10-2015
0 2
0
2
xvxt006
Hi i have this query - sourcetype=access_combined_cookie uri="xxxxx" jsession!=- | bucket _time span=5m | stats c...
by xvxt006 Contributor in Splunk Search 07-10-2015
0 7
0
7
stephenlclarke
I have two queries that I want to merge into one. First query: <pre> sourcetype="sourceType1" rex "Application=...
by stephenlclarke New Member in Splunk Search 07-10-2015
0 5
0
5
kalua
I am trying to write a query which returns the values in myCol which have a count greater than 3 times the standard d...
by kalua New Member in Splunk Search 07-10-2015
0 1
0
1
nitingurram
I have a search index=* sourcetype=tsv Transaction=* Jmeter_measure="ok.pct90"| chart avg(Jmeter_RT_val) by Transact...
by nitingurram New Member in Splunk Search 07-10-2015
0 1
0
1
rsathish47
hi All, is their way alert(search query) can distinguish between weekdays, weekends, monthend? Thanks Sathish R
by rsathish47 Contributor in Splunk Search 07-10-2015
0 1
0
1
responsys_cm
I'm trying to figure out the smartest way to track vulnerability data over time and account for how DHCP may mean tha...
by responsys_cm Builder in Splunk Search 07-10-2015
0 5
0
5
kavyaa
Hi, I have Transaction date format as below. I want to find yearlly,monthly, weekly wise data using single date value...
by kavyaa Explorer in Splunk Search 07-10-2015
0 7
0
7
kumina
How do I extract the string from MSG: till EL from the sample log below using the rex command? BL: | LL: ERROR | TS:...
by kumina New Member in Splunk Search 07-10-2015
0 2
0
2
justgovind30198
Hi, I was working with Splunk and XML data from past 1 month, and found that Splunk is not very friendly with XML as...
by justgovind30198 Explorer in Splunk Search 07-10-2015
0 3
0
3
doksu
How could the number of elements in a tuple of fields be counted after performing a set difference against the other ...
by doksu Contributor in Splunk Search 07-10-2015
1 3
1
3
deepthi5
Hi team, I have got a csv files indexed into splunk with names SOURCE= C:\Netwrokanalysis\germany.csv ,c:\networkan...
by deepthi5 Path Finder in Splunk Search 07-10-2015
0 4
0
4
chandanjaisal
I have couples of host and each host has multiple source type, I want to list down host and source type which are not...
by chandanjaisal Explorer in Splunk Search 07-10-2015
0 2
0
2
Cuyose
I'm still going through the myriad of answers relating to this, but as of yet, have not found my answer. I am doing ...
by Cuyose Builder in Splunk Search 07-10-2015
1 6
1
6
muguniya
Hi All, We have 2 different sourcetype master and child need to join/append the source type on identity column maste...
by muguniya Explorer in Splunk Search 07-09-2015
0 1
0
1
splunknewby
I have the following fields within splunk: srcaddr and dstaddr, and I would like to map the number of internal to int...
by splunknewby Path Finder in Splunk Search 07-09-2015
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...