Splunk Search

Splunk Search
Community Activity
pmcfadden91
Below is my query which list about 80 events grouped by a certain ID (488e5185-42d7-4eec-bcb5-43590ae751a0). The ev...
by pmcfadden91 Path Finder in Splunk Search 07-01-2015
0 1
0
1
kmccowen
Search: index=ctap host=sc58* sourcetype=gateway "CTIPOP CALL RECEIVED" acct="*" | stats count by acct | eventstats ...
by kmccowen Path Finder in Splunk Search 07-01-2015
0 16
0
16
rmorlen
Upgraded from Splunk 5.0.9 to 6.1.2. Can't search. Seeing the following message: "In handler 'jobs': Cannot perform...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 07-01-2015
1 3
1
3
alanxu
Right now I have two different scripts: report scripts and procedure scripts. They have a begin and finished time. I ...
by alanxu Communicator in Splunk Search 07-01-2015
0 4
0
4
zd00191
I have 2 searches :` index=os_windows Host="usatlb9*" object="Network Interface" counter="Bytes Total/sec" |timecha...
by zd00191 Communicator in Splunk Search 07-01-2015
0 1
0
1
daniel333
hello, Splunk 6.13/CentOS 6.4 I recently had a Splunk outage. My monitoring software showed, plenty of IO, CPU and...
by daniel333 Builder in Splunk Search 07-01-2015
0 1
0
1
joseph_trinidad
Hi Splunk Experts, I would like to ask, if there's a way to measure the data size (in bytes) for each counter? For e...
by joseph_trinidad New Member in Splunk Search 07-01-2015
0 1
0
1
20065945
For the below data I want to create fields highlighted in data. The problem while extracting is that the data is in m...
by 20065945 Explorer in Splunk Search 07-01-2015
0 1
0
1
jgcsco
How can I fill null value in the following result with desired value, e.g. 0: mysearch | stats count by host I woul...
by jgcsco Path Finder in Splunk Search 07-01-2015
0 6
0
6
ErraticIncome93
When I run the following search, I get 100+ results of src_ip 1.2.3.4 and signature X: index=http status=200 src_ip!...
by ErraticIncome93 Explorer in Splunk Search 07-01-2015
0 5
0
5
sympatiko
Hi Splunkers, Im having this serious problem. Is there any way to transform or modify a log coming to a certain inde...
by sympatiko Communicator in Splunk Search 07-01-2015
0 4
0
4
BITSIntern
Hi guys, I am having some trouble trying to do a search. I want to do a search that involves the tools count and if ...
by BITSIntern Path Finder in Splunk Search 07-01-2015
0 2
0
2
nilotpaldutta
Hi, I am using this query in splunk search - index="some_index" | dedup source | sort -source | dedup sourcetype...
by nilotpaldutta Explorer in Splunk Search 07-01-2015
0 4
0
4
user21041983
How can we get the scatter chart mentioned in the link http://www.splunk.com/view/SP-CAAACGB to work?
by user21041983 Explorer in Splunk Search 07-01-2015
0 4
0
4
mikylace
I have to send automated reports to a partner with logs and MSISDN that failed due to timeout. Logs are divided by st...
by mikylace Explorer in Splunk Search 07-01-2015
0 3
0
3
tyronetv
I managed to get the following report from Splunk (excuse the lines, trying to format it for viewing): mrSTATUS-----...
by tyronetv Communicator in Splunk Search 06-30-2015
0 1
0
1
shrirangphadke
Hi, I am having a tough time in creating overall sum and aggregate sum. Here is my issue: I have multiple values be...
by shrirangphadke Path Finder in Splunk Search 06-30-2015
0 4
0
4
cdo_splunk
I found this search | rest /services/data/indexes | table title | rename title as index_name | eval joinfield=if(sub...
by cdo_splunk Splunk Employee Splunk Employee in Splunk Search 06-30-2015
2 15
2
15
arubi2
I've read the docs and iterated many times to try to get a simple command to work which pipes events to it. Exampl...
by arubi2 Explorer in Splunk Search 06-30-2015
1 5
1
5
phagunbaya
Currently, the "Save As" option near search bar allows to store the result as Report or Dashboard Panel. I was wonde...
by phagunbaya Explorer in Splunk Search 06-30-2015
0 1
0
1
gunturu_nagasri
Case 1: index=xyz | rex "(?i)<ticketId>(?P<TICKETID>[^<;]+)" | stats values(TICKETID) as TICKETID by processname | ...
by gunturu_nagasri Explorer in Splunk Search 06-30-2015
0 2
0
2
rescobar713
I'm trying to add a field to my main search based on the values retrieved from a subsearch. More specifically, my ma...
by rescobar713 Path Finder in Splunk Search 06-30-2015
1 8
1
8
billycote
I have some data that I need to pull out. This data can be in one of any 3 fields (symbol, symbols or p1) and contai...
by billycote Path Finder in Splunk Search 06-30-2015
0 8
0
8
pkcbailey
I would like to "search |stats count over host by date` only for Midnight to 16:00 EST and I want to report a month o...
by pkcbailey New Member in Splunk Search 06-30-2015
0 1
0
1
frozensky401
why I see 404s when try rules link in karma contest popup?
by frozensky401 New Member in Splunk Search 06-30-2015
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...