Splunk Search

Splunk Search
Community Activity
rmorlen
I would like to suppress all messages in the search app. It would be nice to be able to suppress then by role so tha...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 04-02-2015
3 5
3
5
splunkman341
Hey guys, I am trying to create a custom search which the question directly states. How would I go about doing that?...
by splunkman341 Communicator in Splunk Search 04-01-2015
0 5
0
5
jeffreyjewitt
Hi: I am looking at having greater control over our indexes. The problem I have, is that there are tons of searches ...
by jeffreyjewitt Explorer in Splunk Search 04-01-2015
0 1
0
1
skoelpin
I have 4 basic web services (I'll add more later) which are called throughout the day. My CalculateTax web service is...
by SplunkTrust SplunkTrust in Splunk Search 04-01-2015
0 5
0
5
dbendixen
I have a query that tells me the count of unique devices running a particular software version (major.minor.release.b...
by dbendixen Explorer in Splunk Search 04-01-2015
1 2
1
2
Helna
Hi there. Trying to join a few .ai file (created in Adobe Illustrator) to my query in Microsoft Query i get the follo...
by Helna Engager in Splunk Search 04-01-2015
0 2
0
2
radhika_paliset
0
1
newbiesplunk
Hi, If i wish to find out the duration for the first event and the last event in hour, minutes and second, what would...
by newbiesplunk Path Finder in Splunk Search 04-01-2015
0 1
0
1
bwheelock
I have some XML data broken down into events that have multiple child attributes that share the same name but are dis...
by bwheelock Path Finder in Splunk Search 03-31-2015
0 7
0
7
hartfoml
I am using this search to get license use over 30 days index="summary_indexers" | timechart partial=f span=1d sum(k...
by hartfoml Motivator in Splunk Search 03-31-2015
1 3
1
3
sushmitha_mj
I have created a dashboard with hourly sum(added) values for all users. In the dashboard I want to give the option of...
by sushmitha_mj Communicator in Splunk Search 03-31-2015
0 5
0
5
andreas_roth
Hi all, I'm getting events like this: time=11111 file=aaaa time=11111 file=bbbb time=11111 file=cccc time=11111 fil...
by andreas_roth Engager in Splunk Search 03-31-2015
0 3
0
3
sundaresh83
Hi, I am writing a search: timechart span=1h sum(Bytes) AS "MBytes " In the same search, I want it to return Mb ...
by sundaresh83 Explorer in Splunk Search 03-31-2015
1 9
1
9
sushmitha_mj
Hi, I am working on a distributed splunk environment. I have created an app and a separate indexer for this app to l...
by sushmitha_mj Communicator in Splunk Search 03-31-2015
2 5
2
5
Shisa
I'd like to understand the mathematical meaning of the below search on documentation. Is this my understanding right ...
by Shisa Explorer in Splunk Search 03-31-2015
0 1
0
1
Federica_92
Hi everyone, I have this search: index=main sourcetype=WinEventLog:Security | eval Logon_failur = case((EventCode...
by Federica_92 Communicator in Splunk Search 03-31-2015
0 5
0
5
jmonroe516
I have 2 searches index=test field1=abc field2=xyc | stats dc(field3) as Devices and index=test field1=abc field2...
by jmonroe516 Engager in Splunk Search 03-31-2015
1 2
1
2
alacercogitatus
So I'm working on a new App, one that generates summary data based on eventtypes and fields. The summary data looks l...
by SplunkTrust SplunkTrust in Splunk Search 03-31-2015
1 1
1
1
robertspeckmann
Hi, Im currently building a dashboard and one of my search strings is the one below. I currently see the values GPS ...
by robertspeckmann Explorer in Splunk Search 03-31-2015
0 9
0
9
chriselst
Hi all, just getting started and trying to get something together quickly to show management so forgive asking what i...
by chriselst Engager in Splunk Search 03-31-2015
0 1
0
1
hofer
I have a timechart with the Duration average (ca. 16ms) per second. timespan is 4s, the timechart itself is over 1 h...
by hofer Explorer in Splunk Search 03-30-2015
1 2
1
2
dovelsh12223621
Hi everyone, I need your help. My current search is like this: index="ihs_test" uri_path="*.jhtml" OR uri_path="*....
by dovelsh12223621 Path Finder in Splunk Search 03-30-2015
0 2
0
2
kshanky143
I have 3 tables. I want 2 things here: a) Click on Source 1, in Table 1, and Table 2 should show up b) Click on Sour...
by kshanky143 Path Finder in Splunk Search 03-30-2015
1 2
1
2
skoelpin
I currently have a dashboard with 24 panels on it. I went ahead and set each report/panel to accelerated and also put...
by SplunkTrust SplunkTrust in Splunk Search 03-30-2015
0 4
0
4
lim2
Hi, For query (SEVERE OR exception OR CRITICAL OR "[error]")|rex field=_raw "(?^\d\d-\w\w\w-\d\d\d\d\s\d\d:\d\d:\d\...
by lim2 Communicator in Splunk Search 03-30-2015
0 4
0
4
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...