Splunk Search

Splunk Search
Community Activity
crt89
Is it possible to put search inside an eval if statement ? I am making a search that if the count of the field is gre...
by crt89 Communicator in Splunk Search 04-09-2015
0 3
0
3
moiezuddin
Hi when i searched with the below query index=casm_prod sourcetype=smtrace ........REGULAR EXP..................... ...
by moiezuddin Explorer in Splunk Search 04-09-2015
0 7
0
7
ten_yard_fight
I've read most (if not all) of the questions/answers related to getting an average count of hits per hour. I've exper...
by ten_yard_fight Path Finder in Splunk Search 04-09-2015
0 9
0
9
brutecat
Hi there, I am (very) new to this, so sorry for the lack of insight. I have loaded a data set with multiple event ...
by brutecat Path Finder in Splunk Search 04-09-2015
0 5
0
5
harshavmb
I have a file which gets created daily. My requirement is to get the size of the file using a splunk search. The file...
by harshavmb New Member in Splunk Search 04-08-2015
0 2
0
2
Ledion_Bitincka
I'm running into an issue with Hunk searches that spawn a MapReduce job in my EMR cluster. The MR job seems to be kil...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 3
0
3
jgcsco
I have this search: [search] | stats count by Status Errors | eventstats sum(count) as StatusCount by Status| events...
by jgcsco Path Finder in Splunk Search 04-08-2015
1 4
1
4
jgcsco
I have following event: <...>Status1, StateA<....> <...>Status2,<...> <...>Status3<...> <...>Status1, StateB<...> <....
by jgcsco Path Finder in Splunk Search 04-08-2015
3 3
3
3
AWED
With splunk 4.1.6 : a user has defined a custom field extraction in the "search" app. As as admin, I have changed the...
by AWED Engager in Splunk Search 04-08-2015
1 5
1
5
ndoshi
I have the following types of events in FIX format. This is what they look like in vi or emacs: M|219620|0|i|I|20100...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 10
0
10
mrfredman
Hi, I'm using postgres regex to pull two sets of values into my search. I've got all the data I want, but it seems t...
by mrfredman Path Finder in Splunk Search 04-08-2015
0 2
0
2
edrivera3
Hi I extracted a multivalue field called error_number which contains all errors in each event. I would like to make ...
by edrivera3 Builder in Splunk Search 04-08-2015
1 5
1
5
metersk
I am trying to get counts of all certain events that happened before a user purchased on our site and so far, I am wo...
by metersk Path Finder in Splunk Search 04-08-2015
1 4
1
4
alexl1
hi, how do I re-run a search that I typed in previously? Thanks,
by alexl1 Path Finder in Splunk Search 04-08-2015
0 5
0
5
jeffreyjewitt
Hi: This is an odd question, but it pops up every so often. Is it possible to have a dashboard that is populated with...
by jeffreyjewitt Explorer in Splunk Search 04-07-2015
0 3
0
3
venkatv1520
I have a csv file indexed containing the fields "Timestamp" and "Event1" Sample data is as follows Timestamp Eve...
by venkatv1520 Engager in Splunk Search 04-07-2015
0 3
0
3
HattrickNZ
I have the following search And I add this column row to show the row numbers but it positions in as the right most c...
by HattrickNZ Motivator in Splunk Search 04-07-2015
0 5
0
5
HattrickNZ
I have the following search | inputlookup msckpr_test_trunkgroups95_lookup_define | stats values(TG_NAME) as TG_NAM...
by HattrickNZ Motivator in Splunk Search 04-07-2015
0 3
0
3
mohitab
This could be a premature question and a bit hypothetical too. I have a visual analytics based webapp based on Splu...
by mohitab Path Finder in Splunk Search 04-07-2015
0 2
0
2
wang
Let say I have a chart that reports the count of what user has purchased what item. I can create a nice table using ...
by wang Path Finder in Splunk Search 04-07-2015
0 2
0
2
hcheang
Hello I've been using metadata command for many reports and alarms for new host added, eps and reporting status and ...
by hcheang Path Finder in Splunk Search 04-07-2015
0 1
0
1
hagjos43
Is there any suggestions on how to improve search time on this particular search? This search literally takes 12-15 h...
by hagjos43 Contributor in Splunk Search 04-07-2015
1 9
1
9
jodros
I have the Mobile Access Server up and running. I am able to log in and view dashboards and reports. I have a basic...
by jodros Builder in Splunk Search 04-07-2015
0 3
0
3
jamesvz84
Given the following log format, is it possible to store the consecutive GROUPED/GROUPED_DET lines into one event whil...
by jamesvz84 Communicator in Splunk Search 04-07-2015
0 1
0
1
d29priyanka
I have a splunk search which has multikv and regex. index=os OR index=advantage sourcetype="*nmon*" |multikv|rex fie...
by d29priyanka New Member in Splunk Search 04-07-2015
0 9
0
9
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...