Splunk Search

Splunk Search
Community Activity
seanel
When creating a report of the max count/minute and average count/minute by host for a specific error there seems to ...
by seanel Path Finder in Splunk Search 06-08-2015
3 11
3
11
SasiB137
in,out,name 05-06-2015 11:37:04,05-06-2015 11:37:04 ,uid2 05-06-2015 11:36:06,,uid2 how do I do this, If out time is...
by SasiB137 Engager in Splunk Search 06-08-2015
0 3
0
3
Scan001
Below is an example of a log file I'm trying to analyse (thousands of entries). I wish to remove duplicate entries b...
by Scan001 Explorer in Splunk Search 06-08-2015
0 8
0
8
standias
Hi, What is the normal process count for splunkd? Am having two processes for splunkd both for my forwarder & serv...
by standias Explorer in Splunk Search 06-08-2015
0 3
0
3
rescobar713
I'm trying to filter out events from a search based on a list of strings retrieved from the results of another search...
by rescobar713 Path Finder in Splunk Search 06-08-2015
0 2
0
2
bwalden_splunk
This is related to http://answers.splunk.com/answers/136754/splunk-sdk-fields.html. I've tried searching via the SD...
by bwalden_splunk Splunk Employee Splunk Employee in Splunk Search 06-08-2015
3 4
3
4
gudavasr
Hi, I have a chart like this from a search: source="*.log" "Found TaskId" | | dedup source | eval FileFoundDate =...
by gudavasr Path Finder in Splunk Search 06-08-2015
0 2
0
2
OCIEL
I have a Prod and Non-Prod instances of Splunk running. A former admin installed DBX in both. In trying to setup the ...
by OCIEL Engager in Splunk Search 06-08-2015
0 2
0
2
ironfelya
I'm new to Splunk and I'm trying to add monitor to my logs as: ./splunk add monitor -auth admin:changeme /var/lib/my...
by ironfelya New Member in Splunk Search 06-08-2015
0 1
0
1
Navanitha
I have a search which gives the total count of emails sent out from 5 different mail ids. I use a scheduled report f...
by Navanitha Path Finder in Splunk Search 06-08-2015
0 7
0
7
lukas_loder
Hi! I'm trying to get Information from Google Places into our Splunk. We want to analyze how we get rated on social ...
by lukas_loder Communicator in Splunk Search 06-08-2015
1 3
1
3
martin_mueller
I have a search that basically looks like this: some source | stats earliest(_time) as _time latest(_time) as end by...
by SplunkTrust SplunkTrust in Splunk Search 06-08-2015
0 3
0
3
are0002
Hi, I have a log with this type of content: domain\\user. I have extracted this info with field extraction called sr...
by are0002 Path Finder in Splunk Search 06-08-2015
1 2
1
2
lctanlc
I am new to Splunk but am given a tight deadline to explore the possibility of using Splunk to extract information fr...
by lctanlc New Member in Splunk Search 06-07-2015
0 2
0
2
sheldonkooper
i have two searches: earliest=-10m index=perfmon server=web1 sourcetype="Perfmon:CPUTime" | stats avg(Value) as CPU...
by sheldonkooper Engager in Splunk Search 06-07-2015
0 2
0
2
jackson1990
Sample EventList for my scenario given below: ID=1 | Name=sankar | Age=20 | Dept=Computer science | Programming=60 |...
by jackson1990 Path Finder in Splunk Search 06-07-2015
0 10
0
10
tenyang
Hi all, I have an event sent with the information if a tablet downloaded app successfully or not. If it faces proble...
by tenyang New Member in Splunk Search 06-07-2015
0 2
0
2
igala123123
using splunk 6.2 and c# sdk 2.0 first sdk 2.0 wasn't compiling, there wasn't binaries bundled with it, also the async...
by igala123123 New Member in Splunk Search 06-07-2015
0 1
0
1
gfuente
Hello all, We have this Splunk 6.2.1 Architecture, on Linux VM machines: 3 SH in SHC 1 Master + Deployer 3 Cluster ...
by gfuente Motivator in Splunk Search 06-07-2015
0 2
0
2
lohit
Hi All, I am having a field which has content like below abc xyz sksk lsmlmlspmwmlmwpn wonmwm:29299 (abcxmmowmo.ws...
by lohit Path Finder in Splunk Search 06-06-2015
0 4
0
4
sp1711
I have the following query, index="index" tag=tag1 sourcetype=access_combined "def"|fields correlation_id|join corre...
by sp1711 Path Finder in Splunk Search 06-06-2015
1 10
1
10
angelia_zhong
hi everybody, I met very strange stiuation when I do the search. This is the code: ... |transaction id mvlist=t start...
by angelia_zhong Engager in Splunk Search 06-06-2015
0 3
0
3
paramagurukarth
My search shows results when it is executing.. But after 100% completion of the search all the listed records are dis...
by paramagurukarth Builder in Splunk Search 06-06-2015
1 5
1
5
mibaker_arrow_c
Invc Sales Order Number = Invoice # that will exist across multiple events Inv = $$ I need to sum the Inv for Each D...
by mibaker_arrow_c New Member in Splunk Search 06-06-2015
0 3
0
3
chadman
I would like to create a pie chart for the following search. sourcetype="my_sort" earliest=-30d| dedup host | table ...
by chadman Path Finder in Splunk Search 06-06-2015
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...