Splunk Search

Splunk Search
Community Activity
samuelrey
The field extractor wizard came up with the following: (?=[^f]*(?:firewall:|f.*firewall:))^(?:[^"\n]*"){2}\s+(?P[^ ]...
by samuelrey New Member in Splunk Search 04-09-2015
0 2
0
2
otman01
Hi, I want to create a dashboard using these 2 searches: 1) the first one index='text' | count, will give a result...
by otman01 Communicator in Splunk Search 04-09-2015
1 9
1
9
skoelpin
I currently have a 4 different phrases which are between the fixed words "a:OrderMessage and a/:OrderMessage" . I hav...
by SplunkTrust SplunkTrust in Splunk Search 04-09-2015
0 10
0
10
Splunk2016
I would appreciate any comments: 1) Added "Total" as one of my Selected Fields from the following search (this worke...
by Splunk2016 Path Finder in Splunk Search 04-09-2015
0 2
0
2
bshelton_soleo
I have a set of XML logs that were all consumed by Splunk at the same time. I believe I have the timestamps from the ...
by bshelton_soleo Engager in Splunk Search 04-09-2015
0 2
0
2
jizzmaster
I want to perform a CIDR match on a list of IPs and a list of subnets. In a lookup table I have a list of subnets in...
by jizzmaster Path Finder in Splunk Search 04-09-2015
0 3
0
3
sushmitha_mj
Hi, I want to a graph to check the amount of data indexed by my app on each day for a certain time period. I have m...
by sushmitha_mj Communicator in Splunk Search 04-09-2015
0 4
0
4
deanilol
So I have the columns "Values" and "Status" and I only want to count Values where the status is zero. How can I do th...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
eyaler
i have data of the form: day, hour, seller, buyer i want to find all instances where a seller appears only on a sing...
by eyaler Explorer in Splunk Search 04-09-2015
1 5
1
5
rob3770
Hi, Looking to start using Splunk to do trending and forecasting (predict). index=os sourcetype=cpu host=ukdc1-x...
by rob3770 Explorer in Splunk Search 04-09-2015
0 2
0
2
deanilol
So I'd like to add the _time attribute to a base search object. As I understand it, I can't use the linear pivot diag...
by deanilol Explorer in Splunk Search 04-09-2015
0 2
0
2
HeinzWaescher
Hi, is it possible to split-up/expand an event like this? field1=xyz field2=xyz action: [ [-] { [-] act...
by HeinzWaescher Motivator in Splunk Search 04-09-2015
0 5
0
5
jjc42
Hi, I'm new to Splunk, so please bear with me. I'm trying to get a count of a field with multiple values by day. A...
by jjc42 Explorer in Splunk Search 04-09-2015
1 4
1
4
dmacgillivray
Hello Splunk, I am Trying to write an eval statement that would allow a development team push data to a csv that con...
by dmacgillivray Communicator in Splunk Search 04-09-2015
0 2
0
2
chimell
Hi everyone, I want to extract a record of values: I tried with this regex, but it is only extracting the first rec...
by chimell Motivator in Splunk Search 04-09-2015
1 1
1
1
crt89
Is it possible to put search inside an eval if statement ? I am making a search that if the count of the field is gre...
by crt89 Communicator in Splunk Search 04-09-2015
0 3
0
3
moiezuddin
Hi when i searched with the below query index=casm_prod sourcetype=smtrace ........REGULAR EXP..................... ...
by moiezuddin Explorer in Splunk Search 04-09-2015
0 7
0
7
ten_yard_fight
I've read most (if not all) of the questions/answers related to getting an average count of hits per hour. I've exper...
by ten_yard_fight Path Finder in Splunk Search 04-09-2015
0 9
0
9
brutecat
Hi there, I am (very) new to this, so sorry for the lack of insight. I have loaded a data set with multiple event ...
by brutecat Path Finder in Splunk Search 04-09-2015
0 5
0
5
harshavmb
I have a file which gets created daily. My requirement is to get the size of the file using a splunk search. The file...
by harshavmb New Member in Splunk Search 04-08-2015
0 2
0
2
Ledion_Bitincka
I'm running into an issue with Hunk searches that spawn a MapReduce job in my EMR cluster. The MR job seems to be kil...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 3
0
3
jgcsco
I have this search: [search] | stats count by Status Errors | eventstats sum(count) as StatusCount by Status| events...
by jgcsco Path Finder in Splunk Search 04-08-2015
1 4
1
4
jgcsco
I have following event: <...>Status1, StateA<....> <...>Status2,<...> <...>Status3<...> <...>Status1, StateB<...> <....
by jgcsco Path Finder in Splunk Search 04-08-2015
3 3
3
3
AWED
With splunk 4.1.6 : a user has defined a custom field extraction in the "search" app. As as admin, I have changed the...
by AWED Engager in Splunk Search 04-08-2015
1 5
1
5
ndoshi
I have the following types of events in FIX format. This is what they look like in vi or emacs: M|219620|0|i|I|20100...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 10
0
10
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...