Splunk Search

Splunk Search
Community Activity
anwarmian
This is not a question. I just wanted to put two cents worth of my experience with a lookup table and a csv file. T...
by anwarmian Communicator in Splunk Search 05-02-2015
3 1
3
1
wpreston
Something strange is going on. I have fields extracted via regex in transforms.conf that have been working fine for ...
by wpreston Motivator in Splunk Search 05-02-2015
0 2
0
2
disha
HI, My search is index=aa sourcetype=windows_server_hourly | rex field=host "(?[a-z0-9-]+).*" | eval "Server Name"=...
by disha Contributor in Splunk Search 05-02-2015
0 1
0
1
couscousman
Hello, this search in the search bar of splunk: javaException=* earliest=-m@m | sort _time returns about 100 resu...
by couscousman New Member in Splunk Search 05-02-2015
0 2
0
2
kmattern
This is really strange. It appears that I can either rename _time or format _time but not both. Here are the searches...
by kmattern Builder in Splunk Search 05-02-2015
0 4
0
4
a212830
Hi, Is there a way to count the number of searches via app?
by a212830 Champion in Splunk Search 05-02-2015
0 3
0
3
sschuerger
Hi, I'm working with log data which contains MSISDNs (mobile numbers), which are in the form of "491701234567". It's ...
by sschuerger Engager in Splunk Search 05-02-2015
0 2
0
2
oscargarcia
I have some events, that are indexed with strange dates... 17:56:58,442: htsxml2|c6d1956a-d611-47a5-97df-df0d31e1dbc...
by oscargarcia Path Finder in Splunk Search 05-02-2015
0 3
0
3
dariusz_kwasny
Hello, I have following field extraction and eventtype related definitions: In props.conf: [eventtype::app_portal_...
by dariusz_kwasny Explorer in Splunk Search 05-02-2015
0 7
0
7
Splunker
Folks, Running Splunk 4.2.4 in a distributed setup (1 SH + 1 Indexer). In the Splunk for Cisco Firewall TA is defin...
by Splunker Communicator in Splunk Search 05-02-2015
0 4
0
4
sideview
OK. A bit of a journey here. I am searching for a good reliable method of bucketing numeric field values into cate...
by SplunkTrust SplunkTrust in Splunk Search 05-02-2015
4 3
4
3
gracemaher
Hi there. I basically have a data set with Support Cases in, i would like to find out the duration between the case b...
by gracemaher Explorer in Splunk Search 05-01-2015
0 3
0
3
yuelu
I am trying to group events with same fields and get a count for every 5 minutes interval. I used the following sear...
by yuelu Explorer in Splunk Search 05-01-2015
2 3
2
3
_gkollias
I would like to graph by month/day of the week how many times we have restarted two servers in particular. Rather th...
by _gkollias Builder in Splunk Search 05-01-2015
0 3
0
3
lanilim16
How do I add multiple cron jobs given 1 alert? I have to setup alert traffic by customer, if there are none for the l...
by lanilim16 Explorer in Splunk Search 05-01-2015
0 1
0
1
Venkat_16
Hi, Please help me sort this out. I have a single search like index=test sourcetype= test...| stats count, but the ...
by Venkat_16 Contributor in Splunk Search 05-01-2015
0 3
0
3
edrivera3
Hi In my events I have the following fields: 1. Initial_time (This is different than event's timestamp) (format=stri...
by edrivera3 Builder in Splunk Search 05-01-2015
0 3
0
3
ehoward
I noticed that my [WinEventLog:Security] does not appear to have the same date fields (date_hour, date_min, date_wday...
by ehoward Path Finder in Splunk Search 05-01-2015
0 2
0
2
anhtran
Hello i have index=sqltem with the sourcetype=temp-log with the following field : starttime, endtime, user_id, dbn...
by anhtran New Member in Splunk Search 05-01-2015
0 2
0
2
anhtrantech
Hello, I am working on this for a while but i can't make it work correctly. I hope someone can help me to do this I h...
by anhtrantech Engager in Splunk Search 04-30-2015
0 3
0
3
roberto_mendes
Hello everyone! I would like to know the percentage of growth of the field "wasted_MB" day by day, that is, the perc...
by roberto_mendes Explorer in Splunk Search 04-30-2015
0 7
0
7
cmamer
I'm attempting to consolidate records that share the same values in 3 fields, and I want to keep the event that has t...
by cmamer New Member in Splunk Search 04-30-2015
0 4
0
4
mmohiuddin
Is there a way to ignore splunk to read certain events: Here is a sample event that needs to be ignored: _!========...
by mmohiuddin Path Finder in Splunk Search 04-30-2015
0 4
0
4
Splunk2016
I would appreciate any comments. Search Case 1 host="HP" sourcetype="csv" Displays all fields for 8292 events S...
by Splunk2016 Path Finder in Splunk Search 04-30-2015
0 11
0
11
ulikabbq
I have a formating question. When I run this: index=userdata | eval platform=case(rl_user_agent like "%iPhone%", ...
by ulikabbq Path Finder in Splunk Search 04-30-2015
0 3
0
3
Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...