Splunk Search

Splunk Search
Community Activity
syx093
Say I have one field called member_id and another a multi-value field with the IP Addresses of the member_id. (Rough...
by syx093 Communicator in Splunk Search 06-22-2015
0 2
0
2
Norling80
Hi guys. I want to be able to calculate downtime based on the amount of requests that an Application server processes...
by Norling80 Path Finder in Splunk Search 06-22-2015
0 5
0
5
domenico_perre
Hi All, Having issues with trying to get a search to work. Below is the sample data after I write the following que...
by domenico_perre Path Finder in Splunk Search 06-22-2015
0 2
0
2
rickyholland87
I've set up Splunk to monitor a single folder which contains an archive of log files from multiple source hosts. The ...
by rickyholland87 Engager in Splunk Search 06-21-2015
0 7
0
7
_gkollias
I'm trying to find the best way to join the results of one search, and essentially feed that result set to match with...
by _gkollias Builder in Splunk Search 06-21-2015
0 2
0
2
mjshoaf
I would like to group network devices types in some way so that I can easily view all events for a particular type of...
by mjshoaf New Member in Splunk Search 06-21-2015
0 1
0
1
klynn89
Hey, I am trying to verify we are getting failed login attempt at a specific time on some of our mac systems in Spl...
by klynn89 New Member in Splunk Search 06-21-2015
0 1
0
1
p2splunk2015
Can Splunk read database files such as .sdf or other files like .xls and .xlsx ? If not, are there any way to convert...
by p2splunk2015 New Member in Splunk Search 06-21-2015
0 1
0
1
arnabsen1234
I have a field named httpUrl. This field has values with slashes like "/document/import/upload/reload/". I want to re...
by arnabsen1234 New Member in Splunk Search 06-21-2015
0 2
0
2
syx093
I want to create a query that is like a nested for loop. IP Addresses 10.10.10.10 11.11.11.11 12.12.12.12 13.1...
by syx093 Communicator in Splunk Search 06-21-2015
1 8
1
8
afieffe
Hello, I am a little bit confused by the functions latest() and earliest(). Running this search: index=myindex sour...
by afieffe Engager in Splunk Search 06-21-2015
0 1
0
1
woodcock
Why does this not work (v6.2.3)? index=* | stats count by host | transpose | transpose | fields - row* The work-a...
by Esteemed Legend in Splunk Search 06-21-2015
0 6
0
6
tleyden
Is it possible to take raw netstat input like this: Proto Recv-Q Send-Q Local Address Foreign Address ...
by tleyden Explorer in Splunk Search 06-20-2015
1 1
1
1
smlrwd
Hello everyone, All of our service desk tickets are collected by Splunk. I want to create a search that finds trends...
by smlrwd Explorer in Splunk Search 06-19-2015
0 1
0
1
reillysg
I have 2 searches that are working but I would like to do the following. If search 1 generates a result, I would lik...
by reillysg Engager in Splunk Search 06-19-2015
1 1
1
1
SonnyB
Creating a deduped-union of 1-to-N mapped pairs We need to create a deduped-union of pairs in the data, to create t...
by SonnyB Explorer in Splunk Search 06-19-2015
0 6
0
6
Cuyose
I need to create a regex field extraction to deal with odd events where the same string exists multiple times before ...
by Cuyose Builder in Splunk Search 06-19-2015
0 6
0
6
gelica
Hi, I'm using props.conf and transforms.conf to extract my fields but I have some issues with MV_ADD. My data looks ...
by gelica Communicator in Splunk Search 06-19-2015
1 1
1
1
rene847
Hi, I have not been able to find a good query with all my trying.... I need help please! Can anyone tell how I can: ...
by rene847 Path Finder in Splunk Search 06-19-2015
0 8
0
8
brianpreston
I'm trying to list the last logged event for each permutation of my two logged fields (columns). If the last event w...
by brianpreston Path Finder in Splunk Search 06-19-2015
1 9
1
9
arkadyz1
I've just read this link: Are custom search commands truly 'streaming'? The author there claimed he created a much mo...
by arkadyz1 Builder in Splunk Search 06-19-2015
0 1
0
1
lbogle
Hi Splunkers, I'm trying to work through a search where I have a base query delivering usernames and some correspondi...
by lbogle Contributor in Splunk Search 06-19-2015
1 5
1
5
pepper_seattle
I have a search which pulls from two different sourcetypes on the same index. In this search I specifically call out ...
by pepper_seattle Path Finder in Splunk Search 06-19-2015
0 3
0
3
jsmith39
I've extracted a field called QR from a sourcetype, and it's working perfectly, but is returning numerical data, and ...
by jsmith39 Path Finder in Splunk Search 06-19-2015
0 8
0
8
akazarov
Hello, In my chart command, I'd like to select events satisfying some criteria. For example I can do: chart count(...
by akazarov Path Finder in Splunk Search 06-19-2015
0 4
0
4
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...
Top Solution Authors