Splunk Search

Splunk Search
Community Activity
d29priyanka
I have a splunk search which has multikv and regex. index=os OR index=advantage sourcetype="*nmon*" |multikv|rex fie...
by d29priyanka New Member in Splunk Search 04-07-2015
0 9
0
9
edrivera3
Hi After a search I extracted the field "test_number". Now I would like to use those extracted field values to make ...
by edrivera3 Builder in Splunk Search 04-07-2015
0 1
0
1
darthsplunk
Hi, I'm having problems using mvfilter to filter out NULL strings. This is my search: index=nmap* | eval state=mvf...
by darthsplunk Explorer in Splunk Search 04-07-2015
2 7
2
7
moiezuddin
How to get the details of field app=sencer, when it not shown in the values for the app field?
by moiezuddin Explorer in Splunk Search 04-07-2015
0 5
0
5
mzorzi
The events collected from the MVM have multiline fields, I would like to extract vendor_description,vendor_observatio...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 04-07-2015
0 4
0
4
mohitab
I had a query being called from my webApp which was getting XML results nicely. Query: search index="timedata" | ...
by mohitab Path Finder in Splunk Search 04-07-2015
1 2
1
2
sanjay_shrestha
We have a situation where we need to join multiple child objects of a data model. e.g. ProjectInformation (Datam...
by sanjay_shrestha Contributor in Splunk Search 04-07-2015
0 1
0
1
vasavigangana
Hai I tried following search: sourcetype="smaple12" OR sourcetype="sample22" OR sourcetype="sample32" Install_Mod...
by vasavigangana Explorer in Splunk Search 04-07-2015
2 3
2
3
ferza
I want to gather specific information out of unique sessions. There are 4 bits of information, I've been able to gath...
by ferza Explorer in Splunk Search 04-06-2015
0 3
0
3
lenafried
I’m analyzing events that may contain one or more file names. Extracting a file name when there’s only one per even...
by lenafried New Member in Splunk Search 04-06-2015
0 2
0
2
viswanathsd
In our dispatch directory jobs are getting purged though we didn't set any parameters explicitly,all are default only...
by viswanathsd Path Finder in Splunk Search 04-06-2015
0 4
0
4
KShen
I have a search string: sourcetype=databaseError "object is null" to get the total row number of the result. ne...
by KShen New Member in Splunk Search 04-06-2015
0 3
0
3
krwinters11
This is the error I am receiving: command="r", R exited with code 1: Error: unexpected symbol in: "input <- read.csv...
by krwinters11 Path Finder in Splunk Search 04-06-2015
0 3
0
3
TaylorWhitt
Is it possible to get the first and last concurrent events by a field? I'm trying to use this with NAT translations ...
by TaylorWhitt Path Finder in Splunk Search 04-06-2015
4 1
4
1
asieira
I have a JSON data source in which one of the fields contains a comma separated list of values. Is there a way to use...
by asieira Path Finder in Splunk Search 04-06-2015
0 2
0
2
metersk
Is it possible to return the results from a subsearch alongside the results of the outer/primary search? [search ear...
by metersk Path Finder in Splunk Search 04-06-2015
1 2
1
2
KShen
I have several query.Each query I have the list of the result. But I just need to know the report of each of the tot...
by KShen New Member in Splunk Search 04-06-2015
0 3
0
3
a212830
Hi, I need some help setting up a TIME_PREFIX for the following: INFO | jvm 1 | 2015/04/05 01:56:20 | Sametime...
by a212830 Champion in Splunk Search 04-06-2015
0 4
0
4
vtsguerrero
Hello everybody, sup? I need a little help for this, I have fields separated for a datetime, for example: day_ini =...
by vtsguerrero Contributor in Splunk Search 04-06-2015
0 7
0
7
vasavigangana
Hai i have some installation logfiles and i want to caluculate cpu time for each components(success and falied c...
by vasavigangana Explorer in Splunk Search 04-06-2015
0 3
0
3
Laya123
hi, my search is : index=* sourcetype=ABC host=ABC c_met="GET" c_u_s="*mweb.dll*" [search index=* sourcetype=ABC h...
by Laya123 Communicator in Splunk Search 04-06-2015
0 10
0
10
skoelpin
I have this string.. <a:StatusMessage i:nil="true"></a:StatusMessage> I have millions of these strings which do no...
by SplunkTrust SplunkTrust in Splunk Search 04-05-2015
1 1
1
1
rpattison
All of our SQLServer DBs have a primary and a fail-over. One the rare ocasion when we fail-over Splunk stops indexing...
by rpattison Explorer in Splunk Search 04-04-2015
0 1
0
1
responsys_cm
I'm using the DB Connect V1 app in Splunk 6.2 on an Ubuntu Linux server. I have a local sqlite database. I can use ...
by responsys_cm Builder in Splunk Search 04-04-2015
0 1
0
1
huaraz
Hi I would like to get alerted about the percentage of extraction errors ( since there is no built-in function for t...
by huaraz Explorer in Splunk Search 04-04-2015
0 5
0
5
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...