Splunk Search

Splunk Search
Community Activity
anhtran
Hello i have index=sqltem with the sourcetype=temp-log with the following field : starttime, endtime, user_id, dbn...
by anhtran New Member in Splunk Search 05-01-2015
0 2
0
2
anhtrantech
Hello, I am working on this for a while but i can't make it work correctly. I hope someone can help me to do this I h...
by anhtrantech Engager in Splunk Search 04-30-2015
0 3
0
3
roberto_mendes
Hello everyone! I would like to know the percentage of growth of the field "wasted_MB" day by day, that is, the perc...
by roberto_mendes Explorer in Splunk Search 04-30-2015
0 7
0
7
cmamer
I'm attempting to consolidate records that share the same values in 3 fields, and I want to keep the event that has t...
by cmamer New Member in Splunk Search 04-30-2015
0 4
0
4
mmohiuddin
Is there a way to ignore splunk to read certain events: Here is a sample event that needs to be ignored: _!========...
by mmohiuddin Path Finder in Splunk Search 04-30-2015
0 4
0
4
Splunk2016
I would appreciate any comments. Search Case 1 host="HP" sourcetype="csv" Displays all fields for 8292 events S...
by Splunk2016 Path Finder in Splunk Search 04-30-2015
0 11
0
11
ulikabbq
I have a formating question. When I run this: index=userdata | eval platform=case(rl_user_agent like "%iPhone%", ...
by ulikabbq Path Finder in Splunk Search 04-30-2015
0 3
0
3
agthurber
I have come across a problem where the fields i have defined in my transforms.conf for a csv file are disappearing fr...
by agthurber Explorer in Splunk Search 04-30-2015
1 2
1
2
Cuyose
This seems easy but for some reason I guess I don't know how to ask the question. I want a table that looks like thi...
by Cuyose Builder in Splunk Search 04-30-2015
0 7
0
7
metersk
earliest=-60d@d latest=-0d@d msg=login_daily | eval time=strftime(_time, "%m/%d/%y") | where cadt>1421366400 |stats c...
by metersk Path Finder in Splunk Search 04-30-2015
2 3
2
3
tmarlette
I have created a dashboard in simple XML and I am attempting to make a dynamic drilldown leveraging the split by clau...
by tmarlette Motivator in Splunk Search 04-30-2015
1 3
1
3
satya2p
I have a raw event from where i want to capture a few specific fields already configured in splunk and want to create...
by satya2p Path Finder in Splunk Search 04-30-2015
0 1
0
1
kvsajay213
I have Event Output below RPT: /DailyTestReport I want to create a field as RPT and Field value as "/DailyOperatio...
by kvsajay213 New Member in Splunk Search 04-30-2015
0 4
0
4
bnasello
I only see 4 delimiter type available in plunk ( commas, tabs, pipes, and spaces) I have a file that has asterisks (...
by bnasello New Member in Splunk Search 04-30-2015
0 1
0
1
SilviaGebel
Hi, I am trying to create a new sourcetype in order to get the timestamp right. Year, month, day, hour, minute, sec...
by SilviaGebel Path Finder in Splunk Search 04-30-2015
0 5
0
5
ShaneF
So I looked on the answer for this question and could not find it. (Look at code and sample below.) So the input is f...
by ShaneF Explorer in Splunk Search 04-30-2015
1 5
1
5
jwalzerpitt
I have a .csv file that has a list of users I'd like to search against to see how many times they've logged in. The ....
by jwalzerpitt Influencer in Splunk Search 04-30-2015
0 2
0
2
a212830
Hi, Is there a report that will show me individuals that have run either a scheduled or interactive search? I see se...
by a212830 Champion in Splunk Search 04-30-2015
0 1
0
1
ngatchasandra
I want to retrieve a current user in splunk web by run a query. thanks!
by ngatchasandra Builder in Splunk Search 04-30-2015
0 3
0
3
fnazar
Hi, I am new to splunk so bear with me please. I am trying to display data by each day in a chart and then right at...
by fnazar New Member in Splunk Search 04-30-2015
0 6
0
6
john_howley
Yesterday morning SPLUNK was working fine. I added some alerts to it and suddenly it all started going wrong. At one ...
by john_howley Path Finder in Splunk Search 04-30-2015
0 10
0
10
jleppert
I'm trying to get a graph based on this: timechart span=1h count by src_ip However, I only want to display results...
by jleppert New Member in Splunk Search 04-30-2015
0 5
0
5
mayerda
Hello everyone, I am currently trying to get a list of mac addresses that can't authenticate within the cisco ise. ...
by mayerda Engager in Splunk Search 04-30-2015
0 2
0
2
HattrickNZ
if I have 20 columns on display in the stats tab view after my search, can I just remove the first 10? Instead of hav...
by HattrickNZ Motivator in Splunk Search 04-30-2015
0 6
0
6
tkadale
I have indexed data for Linux logs. I have created different sourcetypes for it in props.conf. Now I removed the conf...
by tkadale Path Finder in Splunk Search 04-29-2015
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...