Splunk Search

Splunk Search
Community Activity
chadman
I would like to create a pie chart for the following search. sourcetype="my_sort" earliest=-30d| dedup host | table ...
by chadman Path Finder in Splunk Search 06-06-2015
0 1
0
1
woodcock
We have a system that generates user-level start and stop event logs. Assume all events have a userID and sessionID ...
by Esteemed Legend in Splunk Search 06-05-2015
0 3
0
3
chadman
I would like the max number of my Y axis to be 60. I so have some numbers that are higher than 60 in my data, but I ...
by chadman Path Finder in Splunk Search 06-05-2015
0 7
0
7
lzellmer_splunk
After realizing the hostname of a Blue Coat appliance was at the end of the incoming events, we created a host name e...
by lzellmer_splunk Splunk Employee Splunk Employee in Splunk Search 06-05-2015
1 2
1
2
andra_pietraru
Hi all, I indexed a XML file and I am trying to extract some fields at search-time. What I'm trying to do is extra...
by andra_pietraru Path Finder in Splunk Search 06-05-2015
1 17
1
17
mrcportillo
Hi there, I'm working on this query: index=checkin host="prod" earliest=-0d@d latest=now (description="Intento de c...
by mrcportillo Engager in Splunk Search 06-05-2015
0 2
0
2
cedmarjls32
I’d like to compare 1) the number of events received in the last 30 minutes with 2) the average number of events rece...
by cedmarjls32 New Member in Splunk Search 06-05-2015
0 2
0
2
SanthoshSreshta
Hi Splunkers, Can it be possible to create a Tree Map using Splunk. If yes, Can any one please guide me in doing tha...
by SanthoshSreshta Contributor in Splunk Search 06-05-2015
0 1
0
1
kuga_mbsd
Hi there, I want to extract only global IP addresses of destination from the internet access logs. Our server segment...
by kuga_mbsd New Member in Splunk Search 06-05-2015
0 8
0
8
markwymer
Hi all, 'fraid I'm still a newbie, so I am probably trying to do too much or the impossible but I'll try and explain...
by markwymer Path Finder in Splunk Search 06-05-2015
2 4
2
4
tenyang
Hi all, I am a new one to splunk. Now i am facing some problem to get the data as I want. I have more than 250 serv...
by tenyang New Member in Splunk Search 06-04-2015
0 5
0
5
sp1711
So, I have a search with a regex that has pulled 2 different fields- lets say user and client. the url is something ...
by sp1711 Path Finder in Splunk Search 06-04-2015
0 12
0
12
viswanathsd
Sample: 1234/rani/abc1234/dfh Need to get output as */rani/*/dfh
by viswanathsd Path Finder in Splunk Search 06-04-2015
1 6
1
6
geetanjali
I have total 100 host data. But i am displaying 20 hosts in my pie chart with sort 20 command. I want other option to...
by geetanjali Path Finder in Splunk Search 06-04-2015
0 1
0
1
chrisboy68
HI, Can't seem to get this working. This is what I want, so I can do a multi stacked bar chart. Columns: Place, Sub...
by chrisboy68 Contributor in Splunk Search 06-04-2015
0 7
0
7
chadman
I have a search that finds computers that have not checked in for the last couple min. It seems to give the results ...
by chadman Path Finder in Splunk Search 06-04-2015
0 2
0
2
jr_arzuaga
I'm trying to get the time difference of two dates on a table but when my user has multiple values for the end_date a...
by jr_arzuaga Explorer in Splunk Search 06-04-2015
2 7
2
7
lawndart
I'm trying to set my "host" field to a portion of each event (it's traffic logs aggregated from a number of places) a...
by lawndart New Member in Splunk Search 06-04-2015
0 4
0
4
skoelpin
I have a web service called CreateOrder.. This has a request and response which has a unique identifier called a GUID...
by SplunkTrust SplunkTrust in Splunk Search 06-04-2015
0 6
0
6
andra_pietraru
Hello, Is it possible to create custom lookup files names and then use them in lookup command in a query? My events ...
by andra_pietraru Path Finder in Splunk Search 06-04-2015
0 5
0
5
antlefebvre
When I have an event where there is selected fields that I want to eliminate, if I ALT-click on the value in the sele...
by antlefebvre Communicator in Splunk Search 06-04-2015
3 7
3
7
sunnyparmar
Hello, In the below given search, I want to show data by "host", so please could anybody suggest me how to do this? ...
by sunnyparmar Communicator in Splunk Search 06-04-2015
0 2
0
2
chadman
I have a search that looks like: sourcetype="_sort" earliest=-30d | dedup host | where encrypt_c =2 | eval encryp...
by chadman Path Finder in Splunk Search 06-04-2015
0 4
0
4
HY
Do I need to create a .csv file for the lookup field section of a saved search for CPU,memory by myself or I just nee...
by HY Explorer in Splunk Search 06-04-2015
0 2
0
2
giovere
Hi All Logged events look something like this: 10:00 ComponentA: 3 ComponentB: 5 ComponentC: 8 10:01 ComponentA: 3...
by giovere Path Finder in Splunk Search 06-04-2015
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...