Splunk Search

Splunk Search
Community Activity
peamc
Struggling a bit to find an answer to this. Can anyone suggest a way to create a sharp, high-quality image export fr...
by peamc Explorer in Splunk Search 07-06-2015
6 2
6
2
ssaenger
Hi, I am having a problem extracting fields that have curly brackets {} I have the log file line; 2015.06.24 11:55:1...
by ssaenger Communicator in Splunk Search 07-06-2015
0 4
0
4
yumlu
I have a table that has long column headers. Can i make these headers multi-line formatted? old table headers: Servi...
by yumlu Engager in Splunk Search 07-05-2015
0 1
0
1
rmurthy
I am using transaction and sending the result to an external workflow. The combined results from transaction appear o...
by rmurthy Engager in Splunk Search 07-05-2015
0 2
0
2
rharrisssi
When using an API to enrich my data, for example running MD5 hashes in my logs against VirusTotal's API, how can I co...
by rharrisssi Path Finder in Splunk Search 07-05-2015
0 3
0
3
john
Hi, I want to run search queries depend on user input,ie what user selecting from dropdown. eg:if user choose 1...
by john Communicator in Splunk Search 07-05-2015
1 1
1
1
jrstear
In props.conf, I have a time-based auto-lookup: "LOOKUP-jobstart = jobstart host OUTPUT jobid, user", against a perio...
by jrstear Path Finder in Splunk Search 07-05-2015
1 2
1
2
rturk
Hi Splunkers  I have some variable length NAT translation events in the following format: Apr 12 11:42:23 1.2.3.4 ...
by rturk Builder in Splunk Search 07-05-2015
0 1
0
1
minkyuk
Hello Splunkians (?). I have a table of data with 2 fields : host / data_used_mb / _timestamp host data_u...
by minkyuk Explorer in Splunk Search 07-04-2015
0 5
0
5
nuttervm
Hi all, I have a saved search containing an eval and a subsearch that seems to work successfully: source="S2 Centr...
by nuttervm New Member in Splunk Search 07-04-2015
0 1
0
1
Akita881
Using the search below i get the results in the first table. I would like to show subtotals (in some fashion) like t...
by Akita881 New Member in Splunk Search 07-04-2015
0 3
0
3
xvxt006
I have this search, but I am not seeing any values for Requests: (status=200 OR status>399) | eval Type=if(status==2...
by xvxt006 Contributor in Splunk Search 07-04-2015
0 2
0
2
SonnyB
Can a macro be defined, that takes another string as the name of the macro, which gets ‘eval’ed first based on the ev...
by SonnyB Explorer in Splunk Search 07-04-2015
0 2
0
2
DrColombes
I want to compute a join of an extracted, multi-value SourceTypeA:field_a string variable with an extracted SourceTyp...
by DrColombes New Member in Splunk Search 07-04-2015
0 2
0
2
tven7
vmstat , net stat is captured every minute. While access_combined has entires whenever traffic comes in (every second...
by tven7 Path Finder in Splunk Search 07-04-2015
0 1
0
1
howyagoin
Hi, I've tried a few of the hints here to solve this one elegantly but can't quite get there. I have two sources of...
by howyagoin Contributor in Splunk Search 07-04-2015
0 1
0
1
criswebber
I have a search query that uses a regular expression to place values in a field/variable and then it aggregates value...
by criswebber New Member in Splunk Search 07-04-2015
0 1
0
1
splunker12er
What is the correct stats function to use to get the last event for a host in a specified time range? first(_raw) or ...
by splunker12er Motivator in Splunk Search 07-04-2015
1 2
1
2
SrinivasaC
I have a data in the below format: Date time column1 column2 03-07-2015 00:00 10 17 03-07-2015 00:30 ...
by SrinivasaC Path Finder in Splunk Search 07-03-2015
0 3
0
3
sympatiko
Hi, Is there a way on search query to resolve any IP result into hostname? Thanks
by sympatiko Communicator in Splunk Search 07-03-2015
0 4
0
4
felipesewaybric
Hey guys, i have | eval Date=strftime(strptime(data,"%Y/%m/%d"),"%m/%d") returning 07/02 07/01 06/30 06/29 06/28 bu...
by felipesewaybric Contributor in Splunk Search 07-03-2015
0 2
0
2
uayub
The following Search command: error OR failed OR severe OR ( sourcetype=access_* ( 404 OR 500 OR 503 ) ) results to...
by uayub Path Finder in Splunk Search 07-03-2015
3 8
3
8
Akita881
I have a search and subsearch. The search looks for an IP addresses occurring more than 50 times and returns the cou...
by Akita881 New Member in Splunk Search 07-03-2015
0 2
0
2
wojtek_swiatek
Hello, We have just upgraded a splunk instance to 6.0 and the searches which worked previously now display: In han...
by wojtek_swiatek Path Finder in Splunk Search 07-03-2015
3 4
3
4
jackiewkc
The results of my queries in Splunk are truncated ie, it only shows: source =/data/logs/sdf/sdfdsfds/f/sdf/dsf/dsf/d...
by jackiewkc Path Finder in Splunk Search 07-03-2015
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors