Splunk Search

Splunk Search
Community Activity
maheshh
Pretty new to this - Is there a way to compare log results between two timeframes ? Consider the following scenario ...
by maheshh New Member in Splunk Search 05-30-2015
0 1
0
1
jdunlea_splunk
I have a search like the following: "index=index_A | " If i distribute this to an indexer which does NOT have an in...
by jdunlea_splunk Splunk Employee Splunk Employee in Splunk Search 05-30-2015
0 1
0
1
healthtrans
I'm trying to build 1 regex to capture multiple sets of data. Below is a sample: 1. 20110221124637|21410|SENT:0.646...
by healthtrans Explorer in Splunk Search 05-30-2015
2 1
2
1
anirbanukil
My Search query: source="test source" "AggCd" AND "test2# " AND "TransTypeCd " AND (NOT ("test2# null")) | rex "tes...
by anirbanukil Explorer in Splunk Search 05-30-2015
0 3
0
3
Christian
i have several events which look like this one (this is one event, repeating with varios values after Txxxx,) DISKB...
by Christian Path Finder in Splunk Search 05-30-2015
0 1
0
1
fdi01
hello I would like to configure splunk like so: When a user is inactive for 15 minutes, the session shoulds Origin Lo...
by fdi01 Motivator in Splunk Search 05-30-2015
0 4
0
4
iamniks
Hi, we have csv file in below format. PROJECT_NAME USER_NAME STATUS WEB_xxxx David PA...
by iamniks Explorer in Splunk Search 05-29-2015
0 2
0
2
rtadams89
Every day, a script runs on my Windows boxs that sends an event to Splunk. I'm looking for a search that will return ...
by rtadams89 Contributor in Splunk Search 05-29-2015
0 4
0
4
vaijpc
I want to run a timechart 'overnight'... e.g. getting the minimum values of a field between midday and midday... 12-1...
by vaijpc Communicator in Splunk Search 05-29-2015
0 1
0
1
mldaplin
Hi, I'm having this error logs on my search heard splunkd. 01-15-2011 00:22:06.346 WARN NetUtils - Bad select for ...
by mldaplin Engager in Splunk Search 05-29-2015
2 1
2
1
rahiparikh
Hi, I have two fields. Let's say they are field1 and field2. I extract field2 from field1. I also remove some part o...
by rahiparikh Explorer in Splunk Search 05-29-2015
0 1
0
1
kmcarrol
I'm slowly digesting the posts that describe how to use stats to retrieve aligned data from multiple sources but I'm ...
by kmcarrol Path Finder in Splunk Search 05-29-2015
0 6
0
6
aviadr1
I am trying the field tranformation feature. using the "Manager » Fields » Field transformations" UI I have defined t...
by aviadr1 Explorer in Splunk Search 05-29-2015
0 1
0
1
vhwang
I have a log containing some commands like so: SWFCMD_DNLK_LOG: WHICHLOG = CMD_LOG_IMDCMD, TIMERANGESTRT = 0, TIMER...
by vhwang New Member in Splunk Search 05-29-2015
0 1
0
1
whistj
I have a transaction that includes a MAC address which doesn't change and an IP address which changes during the tran...
by whistj Explorer in Splunk Search 05-29-2015
0 1
0
1
freephoneid
Hi, I've column chart which uses below query: index=test | stats last(_time) AS time by customerid | convert timefo...
by freephoneid Path Finder in Splunk Search 05-29-2015
1 1
1
1
freephoneid
Hi, I'm displaying Pie chart with below query. index=my_index sourcetype="my_log" keyword1 keyword2 "errorValue=" |...
by freephoneid Path Finder in Splunk Search 05-29-2015
0 1
0
1
sushmitha_mj
I have a field that captures the usage of every user. I want to write a case to get the usage of each user in that ho...
by sushmitha_mj Communicator in Splunk Search 05-29-2015
0 13
0
13
bcatwork
I need some assistance in calculating latency values. I have many hosts, logging transformation latency in different ...
by bcatwork Path Finder in Splunk Search 05-29-2015
0 4
0
4
hartfoml
I have this search that is a very sparse search over 7 days and takes a long time to complete (more than ten hours) ....
by hartfoml Motivator in Splunk Search 05-29-2015
0 2
0
2
rahiparikh
Hi, I tried to tansform unix app's data something like this -- [transforms.conf] [df] REGEX = ([^\s]+)\s+([^\s]+)\...
by rahiparikh Explorer in Splunk Search 05-29-2015
0 6
0
6
msettipane
I am attempting to round my currency figures to two decimal places whether or not the amount ends with zeros (e.g., $...
by msettipane Splunk Employee Splunk Employee in Splunk Search 05-29-2015
1 2
1
2
mrchariybrown
I have a bunch of events and within the events, I have the following: "Back Garage took Time In MilliSeconds: 1621 ...
by mrchariybrown New Member in Splunk Search 05-29-2015
0 2
0
2
tlagatta_splunk
Sometimes Splunk has extra null fields floating around (e.g., after fields nosuchfield *). Is there a command which a...
by tlagatta_splunk Splunk Employee Splunk Employee in Splunk Search 05-29-2015
0 3
0
3
lokival
Good Day, New to splunk, using version 4.2.3 Imported some zipped log files into splunk. I can search them just fin...
by lokival Explorer in Splunk Search 05-29-2015
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors