Splunk Search

Splunk Search
Community Activity
sushmitha_mj
Hi, I want to a graph to check the amount of data indexed by my app on each day for a certain time period. I have m...
by sushmitha_mj Communicator in Splunk Search 04-09-2015
0 4
0
4
deanilol
So I have the columns "Values" and "Status" and I only want to count Values where the status is zero. How can I do th...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
eyaler
i have data of the form: day, hour, seller, buyer i want to find all instances where a seller appears only on a sing...
by eyaler Explorer in Splunk Search 04-09-2015
1 5
1
5
rob3770
Hi, Looking to start using Splunk to do trending and forecasting (predict). index=os sourcetype=cpu host=ukdc1-x...
by rob3770 Explorer in Splunk Search 04-09-2015
0 2
0
2
deanilol
So I'd like to add the _time attribute to a base search object. As I understand it, I can't use the linear pivot diag...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
HeinzWaescher
Hi, is it possible to split-up/expand an event like this? field1=xyz field2=xyz action: [ [-] { [-] act...
by HeinzWaescher Motivator in Splunk Search 04-09-2015
0 5
0
5
jjc42
Hi, I'm new to Splunk, so please bear with me. I'm trying to get a count of a field with multiple values by day. A...
by jjc42 Explorer in Splunk Search 04-09-2015
1 4
1
4
dmacgillivray
Hello Splunk, I am Trying to write an eval statement that would allow a development team push data to a csv that con...
by dmacgillivray Communicator in Splunk Search 04-09-2015
0 2
0
2
chimell
Hi everyone, I want to extract a record of values: I tried with this regex, but it is only extracting the first rec...
by chimell Motivator in Splunk Search 04-09-2015
1 1
1
1
crt89
Is it possible to put search inside an eval if statement ? I am making a search that if the count of the field is gre...
by crt89 Communicator in Splunk Search 04-09-2015
0 3
0
3
moiezuddin
Hi when i searched with the below query index=casm_prod sourcetype=smtrace ........REGULAR EXP..................... ...
by moiezuddin Explorer in Splunk Search 04-09-2015
0 7
0
7
ten_yard_fight
I've read most (if not all) of the questions/answers related to getting an average count of hits per hour. I've exper...
by ten_yard_fight Path Finder in Splunk Search 04-09-2015
0 9
0
9
brutecat
Hi there, I am (very) new to this, so sorry for the lack of insight. I have loaded a data set with multiple event ...
by brutecat Path Finder in Splunk Search 04-09-2015
0 5
0
5
harshavmb
I have a file which gets created daily. My requirement is to get the size of the file using a splunk search. The file...
by harshavmb New Member in Splunk Search 04-08-2015
0 2
0
2
Ledion_Bitincka
I'm running into an issue with Hunk searches that spawn a MapReduce job in my EMR cluster. The MR job seems to be kil...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 3
0
3
jgcsco
I have this search: [search] | stats count by Status Errors | eventstats sum(count) as StatusCount by Status| events...
by jgcsco Path Finder in Splunk Search 04-08-2015
1 4
1
4
jgcsco
I have following event: <...>Status1, StateA<....> <...>Status2,<...> <...>Status3<...> <...>Status1, StateB<...> <....
by jgcsco Path Finder in Splunk Search 04-08-2015
3 3
3
3
AWED
With splunk 4.1.6 : a user has defined a custom field extraction in the "search" app. As as admin, I have changed the...
by AWED Engager in Splunk Search 04-08-2015
1 5
1
5
ndoshi
I have the following types of events in FIX format. This is what they look like in vi or emacs: M|219620|0|i|I|20100...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 10
0
10
mrfredman
Hi, I'm using postgres regex to pull two sets of values into my search. I've got all the data I want, but it seems t...
by mrfredman Path Finder in Splunk Search 04-08-2015
0 2
0
2
edrivera3
Hi I extracted a multivalue field called error_number which contains all errors in each event. I would like to make ...
by edrivera3 Builder in Splunk Search 04-08-2015
1 5
1
5
metersk
I am trying to get counts of all certain events that happened before a user purchased on our site and so far, I am wo...
by metersk Path Finder in Splunk Search 04-08-2015
1 4
1
4
alexl1
hi, how do I re-run a search that I typed in previously? Thanks,
by alexl1 Path Finder in Splunk Search 04-08-2015
0 5
0
5
jeffreyjewitt
Hi: This is an odd question, but it pops up every so often. Is it possible to have a dashboard that is populated with...
by jeffreyjewitt Explorer in Splunk Search 04-07-2015
0 3
0
3
venkatv1520
I have a csv file indexed containing the fields "Timestamp" and "Event1" Sample data is as follows Timestamp Eve...
by venkatv1520 Engager in Splunk Search 04-07-2015
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...