Splunk Search

Splunk Search
Community Activity
melonman
Hi I am looking for a sample external lookup script or custom command that takes one field value from evens and co...
by melonman Motivator in Splunk Search 04-10-2015
0 4
0
4
samuelrey
The field extractor wizard came up with the following: (?=[^f]*(?:firewall:|f.*firewall:))^(?:[^"\n]*"){2}\s+(?P[^ ]...
by samuelrey New Member in Splunk Search 04-09-2015
0 2
0
2
otman01
Hi, I want to create a dashboard using these 2 searches: 1) the first one index='text' | count, will give a result...
by otman01 Communicator in Splunk Search 04-09-2015
1 9
1
9
skoelpin
I currently have a 4 different phrases which are between the fixed words "a:OrderMessage and a/:OrderMessage" . I hav...
by SplunkTrust SplunkTrust in Splunk Search 04-09-2015
0 10
0
10
Splunk2016
I would appreciate any comments: 1) Added "Total" as one of my Selected Fields from the following search (this worke...
by Splunk2016 Path Finder in Splunk Search 04-09-2015
0 2
0
2
bshelton_soleo
I have a set of XML logs that were all consumed by Splunk at the same time. I believe I have the timestamps from the ...
by bshelton_soleo Engager in Splunk Search 04-09-2015
0 2
0
2
jizzmaster
I want to perform a CIDR match on a list of IPs and a list of subnets. In a lookup table I have a list of subnets in...
by jizzmaster Path Finder in Splunk Search 04-09-2015
0 3
0
3
sushmitha_mj
Hi, I want to a graph to check the amount of data indexed by my app on each day for a certain time period. I have m...
by sushmitha_mj Communicator in Splunk Search 04-09-2015
0 4
0
4
deanilol
So I have the columns "Values" and "Status" and I only want to count Values where the status is zero. How can I do th...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
eyaler
i have data of the form: day, hour, seller, buyer i want to find all instances where a seller appears only on a sing...
by eyaler Explorer in Splunk Search 04-09-2015
1 5
1
5
rob3770
Hi, Looking to start using Splunk to do trending and forecasting (predict). index=os sourcetype=cpu host=ukdc1-x...
by rob3770 Explorer in Splunk Search 04-09-2015
0 2
0
2
deanilol
So I'd like to add the _time attribute to a base search object. As I understand it, I can't use the linear pivot diag...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
HeinzWaescher
Hi, is it possible to split-up/expand an event like this? field1=xyz field2=xyz action: [ [-] { [-] act...
by HeinzWaescher Motivator in Splunk Search 04-09-2015
0 5
0
5
jjc42
Hi, I'm new to Splunk, so please bear with me. I'm trying to get a count of a field with multiple values by day. A...
by jjc42 Explorer in Splunk Search 04-09-2015
1 4
1
4
dmacgillivray
Hello Splunk, I am Trying to write an eval statement that would allow a development team push data to a csv that con...
by dmacgillivray Communicator in Splunk Search 04-09-2015
0 2
0
2
chimell
Hi everyone, I want to extract a record of values: I tried with this regex, but it is only extracting the first rec...
by chimell Motivator in Splunk Search 04-09-2015
1 1
1
1
crt89
Is it possible to put search inside an eval if statement ? I am making a search that if the count of the field is gre...
by crt89 Communicator in Splunk Search 04-09-2015
0 3
0
3
moiezuddin
Hi when i searched with the below query index=casm_prod sourcetype=smtrace ........REGULAR EXP..................... ...
by moiezuddin Explorer in Splunk Search 04-09-2015
0 7
0
7
ten_yard_fight
I've read most (if not all) of the questions/answers related to getting an average count of hits per hour. I've exper...
by ten_yard_fight Path Finder in Splunk Search 04-09-2015
0 9
0
9
brutecat
Hi there, I am (very) new to this, so sorry for the lack of insight. I have loaded a data set with multiple event ...
by brutecat Path Finder in Splunk Search 04-09-2015
0 5
0
5
harshavmb
I have a file which gets created daily. My requirement is to get the size of the file using a splunk search. The file...
by harshavmb New Member in Splunk Search 04-08-2015
0 2
0
2
Ledion_Bitincka
I'm running into an issue with Hunk searches that spawn a MapReduce job in my EMR cluster. The MR job seems to be kil...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 3
0
3
jgcsco
I have this search: [search] | stats count by Status Errors | eventstats sum(count) as StatusCount by Status| events...
by jgcsco Path Finder in Splunk Search 04-08-2015
1 4
1
4
jgcsco
I have following event: <...>Status1, StateA<....> <...>Status2,<...> <...>Status3<...> <...>Status1, StateB<...> <....
by jgcsco Path Finder in Splunk Search 04-08-2015
3 3
3
3
AWED
With splunk 4.1.6 : a user has defined a custom field extraction in the "search" app. As as admin, I have changed the...
by AWED Engager in Splunk Search 04-08-2015
1 5
1
5
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...