Splunk Search

Splunk Search
Community Activity
harshal_chakran
Hi, I have used inputcsv to get the following table Parameter Value p1 1 p2 2 p3 3 p4 0 Is ther...
by harshal_chakran Builder in Splunk Search 07-02-2015
1 1
1
1
triest
When I run a search ( sourcetype="fieldtest"), I see that there are two events with a field called third and a value ...
by triest Communicator in Splunk Search 07-01-2015
0 4
0
4
vermicknid
Forgive my newbieness - I've tried doing this with: | metadata type=sourcetypes index="*" but the output is difficu...
by vermicknid New Member in Splunk Search 07-01-2015
0 5
0
5
alexl1
hi what is the syntax of the custom condition search I have a search like earliest=-5m heartbeat | stats count ...
by alexl1 Path Finder in Splunk Search 07-01-2015
0 1
0
1
pmcfadden91
Below is my query which list about 80 events grouped by a certain ID (488e5185-42d7-4eec-bcb5-43590ae751a0). The ev...
by pmcfadden91 Path Finder in Splunk Search 07-01-2015
0 1
0
1
kmccowen
Search: index=ctap host=sc58* sourcetype=gateway "CTIPOP CALL RECEIVED" acct="*" | stats count by acct | eventstats ...
by kmccowen Path Finder in Splunk Search 07-01-2015
0 16
0
16
rmorlen
Upgraded from Splunk 5.0.9 to 6.1.2. Can't search. Seeing the following message: "In handler 'jobs': Cannot perform...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 07-01-2015
1 3
1
3
alanxu
Right now I have two different scripts: report scripts and procedure scripts. They have a begin and finished time. I ...
by alanxu Communicator in Splunk Search 07-01-2015
0 4
0
4
zd00191
I have 2 searches :` index=os_windows Host="usatlb9*" object="Network Interface" counter="Bytes Total/sec" |timecha...
by zd00191 Communicator in Splunk Search 07-01-2015
0 1
0
1
daniel333
hello, Splunk 6.13/CentOS 6.4 I recently had a Splunk outage. My monitoring software showed, plenty of IO, CPU and...
by daniel333 Builder in Splunk Search 07-01-2015
0 1
0
1
joseph_trinidad
Hi Splunk Experts, I would like to ask, if there's a way to measure the data size (in bytes) for each counter? For e...
by joseph_trinidad New Member in Splunk Search 07-01-2015
0 1
0
1
20065945
For the below data I want to create fields highlighted in data. The problem while extracting is that the data is in m...
by 20065945 Explorer in Splunk Search 07-01-2015
0 1
0
1
jgcsco
How can I fill null value in the following result with desired value, e.g. 0: mysearch | stats count by host I woul...
by jgcsco Path Finder in Splunk Search 07-01-2015
0 6
0
6
ErraticIncome93
When I run the following search, I get 100+ results of src_ip 1.2.3.4 and signature X: index=http status=200 src_ip!...
by ErraticIncome93 Explorer in Splunk Search 07-01-2015
0 5
0
5
sympatiko
Hi Splunkers, Im having this serious problem. Is there any way to transform or modify a log coming to a certain inde...
by sympatiko Communicator in Splunk Search 07-01-2015
0 4
0
4
BITSIntern
Hi guys, I am having some trouble trying to do a search. I want to do a search that involves the tools count and if ...
by BITSIntern Path Finder in Splunk Search 07-01-2015
0 2
0
2
nilotpaldutta
Hi, I am using this query in splunk search - index="some_index" | dedup source | sort -source | dedup sourcetype...
by nilotpaldutta Explorer in Splunk Search 07-01-2015
0 4
0
4
user21041983
How can we get the scatter chart mentioned in the link http://www.splunk.com/view/SP-CAAACGB to work?
by user21041983 Explorer in Splunk Search 07-01-2015
0 4
0
4
mikylace
I have to send automated reports to a partner with logs and MSISDN that failed due to timeout. Logs are divided by st...
by mikylace Explorer in Splunk Search 07-01-2015
0 3
0
3
tyronetv
I managed to get the following report from Splunk (excuse the lines, trying to format it for viewing): mrSTATUS-----...
by tyronetv Communicator in Splunk Search 06-30-2015
0 1
0
1
shrirangphadke
Hi, I am having a tough time in creating overall sum and aggregate sum. Here is my issue: I have multiple values be...
by shrirangphadke Path Finder in Splunk Search 06-30-2015
0 4
0
4
cdo_splunk
I found this search | rest /services/data/indexes | table title | rename title as index_name | eval joinfield=if(sub...
by cdo_splunk Splunk Employee Splunk Employee in Splunk Search 06-30-2015
2 15
2
15
arubi2
I've read the docs and iterated many times to try to get a simple command to work which pipes events to it. Exampl...
by arubi2 Explorer in Splunk Search 06-30-2015
1 5
1
5
phagunbaya
Currently, the "Save As" option near search bar allows to store the result as Report or Dashboard Panel. I was wonde...
by phagunbaya Explorer in Splunk Search 06-30-2015
0 1
0
1
gunturu_nagasri
Case 1: index=xyz | rex "(?i)<ticketId>(?P<TICKETID>[^<;]+)" | stats values(TICKETID) as TICKETID by processname | ...
by gunturu_nagasri Explorer in Splunk Search 06-30-2015
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors