Splunk Search

Splunk Search
Community Activity
rajadatta
Hi - I have two searches that have the same fields exactly but from different sources. I would like to join and sum...
by rajadatta New Member in Splunk Search 06-16-2015
0 5
0
5
kostasKats
The log is: 2015-06-15 15:50:29,381 ws prd 62 WARN JourneySearch # # # # Blocked Incoming Request 13360-PSA-LIS ...
by kostasKats Explorer in Splunk Search 06-16-2015
2 4
2
4
vitorvmiguel
Hi folks, I need a solution for counting one thing by extracting a list of ID's from the same index. My log archive ...
by vitorvmiguel Explorer in Splunk Search 06-16-2015
0 5
0
5
nmulm
Hi there, I have response time data in ms in a table field ElTime. I want to band this based on 1000ms second bracke...
by nmulm Explorer in Splunk Search 06-16-2015
0 7
0
7
Hartmannish
Okay, this is a bit difficult to explain, which is also why I'm not sure it hasn't already been answered, but here go...
by Hartmannish Explorer in Splunk Search 06-16-2015
1 16
1
16
ben_leung
Using REST API to call curl command, what is the exact endpoint to hit in order to create a scheduled search with all...
by ben_leung Builder in Splunk Search 06-16-2015
0 2
0
2
nilotpaldutta
Hi, I'm new to Splunk. I have a query that extracts the date and time from the name of a log file. Logfile names are ...
by nilotpaldutta Explorer in Splunk Search 06-16-2015
1 8
1
8
MikeBertelsen
Trying to get an alert from Splunk when an average for a specified time and number of documents > 1. Example taken fo...
by MikeBertelsen Communicator in Splunk Search 06-16-2015
0 2
0
2
sunnyparmar
Hi, I am using where clause but it is not giving any result. It showing the result as (0) in counts section. My quer...
by sunnyparmar Communicator in Splunk Search 06-16-2015
0 5
0
5
musgrape
I'd like to create a search that allows me to filter out all the old results and only give me back the latest result ...
by musgrape Engager in Splunk Search 06-15-2015
0 3
0
3
imanpoeiri
Hi Experts, Currently I have my index data as below order_id, order_status 12345, Submitted and currently I have o...
by imanpoeiri Communicator in Splunk Search 06-15-2015
0 7
0
7
mcrawford44
My specific example is regarding an Active Directory index. This is my basic query; index="ad_test" objectClass="*c...
by mcrawford44 Communicator in Splunk Search 06-15-2015
1 9
1
9
splunknewby
I have set up a forwarder on my machine to send netflow data from a directory into splunk. The setup is as follows: ...
by splunknewby Path Finder in Splunk Search 06-15-2015
0 5
0
5
Moon629
Hi, Now, we have the following use case, but I don't know how to write the search. Please help~ In application log,...
by Moon629 Explorer in Splunk Search 06-15-2015
0 5
0
5
andykuhn
Like the example here (http://docs.splunk.com/Documentation/Splunk/6.2.3/Viz/Chartcontrols), I need to assign a param...
by andykuhn Path Finder in Splunk Search 06-15-2015
0 1
0
1
kkas
The sourceType I was told to mess with has a "Name" field. The field sometimes holds the value of a users Network ID ...
by kkas Path Finder in Splunk Search 06-15-2015
0 1
0
1
DanielFordWA
Hi, I keep getting the following error in DB connect 1. I have setup the External Database and can use it for lookup...
by DanielFordWA Contributor in Splunk Search 06-15-2015
0 3
0
3
hokieb
I am trying to pull distinct counts of failed and successful usernames used in login transactions grouped by IP addre...
by hokieb New Member in Splunk Search 06-15-2015
0 2
0
2
ayenumula
My XML tree has null values for certain fields. I am using "table" command to display fields in a tabular format. I a...
by ayenumula Explorer in Splunk Search 06-15-2015
0 4
0
4
rune_hellem
We have three environments test, stage and prod where we run a script that creates a log file that pr. event lists na...
by rune_hellem Contributor in Splunk Search 06-15-2015
0 5
0
5
achetreanu
How can I match 2 lines of the same file that have a random number of other lines between them? 1111 Start Sub Trans...
by achetreanu New Member in Splunk Search 06-15-2015
0 1
0
1
vganjare
HI, I have a field which has a lot of leading zeros. Currently, this field is getting extracted as a string field. I...
by vganjare Builder in Splunk Search 06-15-2015
0 2
0
2
rafiqul_ahsan
From following search result - I want to extract User-Name and Calling-Station-Id, and both fields have multiple valu...
by rafiqul_ahsan New Member in Splunk Search 06-15-2015
0 4
0
4
Arminder_Bhalla
Hi, The default behavior of Splunk is to show a pie chart in a map, but my requirement is to show a bar chart instea...
by Arminder_Bhalla New Member in Splunk Search 06-15-2015
0 1
0
1
abovebeyond
Hello, I'm trying to order specific events from our application log for visualization. search string : index="a...
by abovebeyond Communicator in Splunk Search 06-15-2015
0 2
0
2
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors