Splunk Search

Splunk Search
Community Activity
rbal_splunk
A Splunk environment in one data center configured with multiple indexers became completely unresponsive to the data ...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 07-06-2015
7 2
7
2
felipesewaybric
How can i have those 2 stats? | dbquery PROD-UOL7-MANUT-MONITORACAO "select dat_collect_transaction as \"data\", T...
by felipesewaybric Contributor in Splunk Search 07-06-2015
0 3
0
3
sg5258
i have search query that seperate multivalue and expand them into various result. It work for entry that has data but...
by sg5258 Explorer in Splunk Search 07-06-2015
1 1
1
1
splunkman341
Hi guys, So I have a query which displays elapsedTime values for three different actions which are browse, view, and...
by splunkman341 Communicator in Splunk Search 07-06-2015
0 13
0
13
dbryan
I'm trying to collate result sets from two different, slightly similar subsearches. I have one search like this: `s...
by dbryan Path Finder in Splunk Search 07-06-2015
0 3
0
3
l-mss-n3
Hi, I am trying to create an alert that I need check if status "work in progress" was opened for more than 1 hour, i...
by l-mss-n3 New Member in Splunk Search 07-06-2015
0 2
0
2
cameo_cameo
I have the following data. The count field is calculated based on the method, status and date (I would also have the ...
by cameo_cameo New Member in Splunk Search 07-06-2015
0 2
0
2
peamc
Struggling a bit to find an answer to this. Can anyone suggest a way to create a sharp, high-quality image export fr...
by peamc Explorer in Splunk Search 07-06-2015
6 2
6
2
ssaenger
Hi, I am having a problem extracting fields that have curly brackets {} I have the log file line; 2015.06.24 11:55:1...
by ssaenger Communicator in Splunk Search 07-06-2015
0 4
0
4
yumlu
I have a table that has long column headers. Can i make these headers multi-line formatted? old table headers: Servi...
by yumlu Engager in Splunk Search 07-05-2015
0 1
0
1
rmurthy
I am using transaction and sending the result to an external workflow. The combined results from transaction appear o...
by rmurthy Engager in Splunk Search 07-05-2015
0 2
0
2
rharrisssi
When using an API to enrich my data, for example running MD5 hashes in my logs against VirusTotal's API, how can I co...
by rharrisssi Path Finder in Splunk Search 07-05-2015
0 3
0
3
john
Hi, I want to run search queries depend on user input,ie what user selecting from dropdown. eg:if user choose 1...
by john Communicator in Splunk Search 07-05-2015
1 1
1
1
jrstear
In props.conf, I have a time-based auto-lookup: "LOOKUP-jobstart = jobstart host OUTPUT jobid, user", against a perio...
by jrstear Path Finder in Splunk Search 07-05-2015
1 2
1
2
rturk
Hi Splunkers  I have some variable length NAT translation events in the following format: Apr 12 11:42:23 1.2.3.4 ...
by rturk Builder in Splunk Search 07-05-2015
0 1
0
1
minkyuk
Hello Splunkians (?). I have a table of data with 2 fields : host / data_used_mb / _timestamp host data_u...
by minkyuk Explorer in Splunk Search 07-04-2015
0 5
0
5
nuttervm
Hi all, I have a saved search containing an eval and a subsearch that seems to work successfully: source="S2 Centr...
by nuttervm New Member in Splunk Search 07-04-2015
0 1
0
1
Akita881
Using the search below i get the results in the first table. I would like to show subtotals (in some fashion) like t...
by Akita881 New Member in Splunk Search 07-04-2015
0 3
0
3
xvxt006
I have this search, but I am not seeing any values for Requests: (status=200 OR status>399) | eval Type=if(status==2...
by xvxt006 Contributor in Splunk Search 07-04-2015
0 2
0
2
SonnyB
Can a macro be defined, that takes another string as the name of the macro, which gets ‘eval’ed first based on the ev...
by SonnyB Explorer in Splunk Search 07-04-2015
0 2
0
2
DrColombes
I want to compute a join of an extracted, multi-value SourceTypeA:field_a string variable with an extracted SourceTyp...
by DrColombes New Member in Splunk Search 07-04-2015
0 2
0
2
tven7
vmstat , net stat is captured every minute. While access_combined has entires whenever traffic comes in (every second...
by tven7 Path Finder in Splunk Search 07-04-2015
0 1
0
1
howyagoin
Hi, I've tried a few of the hints here to solve this one elegantly but can't quite get there. I have two sources of...
by howyagoin Contributor in Splunk Search 07-04-2015
0 1
0
1
criswebber
I have a search query that uses a regular expression to place values in a field/variable and then it aggregates value...
by criswebber New Member in Splunk Search 07-04-2015
0 1
0
1
splunker12er
What is the correct stats function to use to get the last event for a host in a specified time range? first(_raw) or ...
by splunker12er Motivator in Splunk Search 07-04-2015
1 2
1
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors