Splunk Search

Splunk Search
Community Activity
AaronMoorcroft
Morning Guys Over the last week or so, my license usage has gone up by around 10 gig. I have looked in our Deploymen...
by AaronMoorcroft Communicator in Splunk Search 03-25-2015
0 3
0
3
stephane_cyrill
Hi Folks, I'm unable to pass a variable to span (e.i span=duration s) where duration is an integer. Is there a comma...
by stephane_cyrill Builder in Splunk Search 03-25-2015
0 5
0
5
varunnair26
Hi, In my Splunk instance there are two indexes which I need to use for arithmetic operations on the timestamp field...
by varunnair26 Explorer in Splunk Search 03-24-2015
0 10
0
10
dovelsh12223621
All I want to do like this: - The calculation of each page the bandwidth consumed. - Calculate the total bandwidth ...
by dovelsh12223621 Path Finder in Splunk Search 03-24-2015
2 2
2
2
chsanth
I have a string like this: dps.qsz=0,dps.lck=false,dps.dis=false,dps.mx=2,dps.ac=0 Now, I want to extract dps.mx= ...
by chsanth New Member in Splunk Search 03-24-2015
0 2
0
2
wegscd
I am using DB Connect to insert some data into an index. Query 'A' inserts data in mkv format, and sourcetype 'ItimPr...
by wegscd Contributor in Splunk Search 03-24-2015
0 5
0
5
ahogbin
Hello to all.. I am attempting (partially succesfully so far) to extract some text. The problem I am having is that ...
by ahogbin Communicator in Splunk Search 03-24-2015
0 16
0
16
whateverwhouare
I want to reorder my columns. I tried both table and fields, and they seemed to work through the web UI, but when I t...
by whateverwhouare New Member in Splunk Search 03-24-2015
0 1
0
1
therockhead
Beginner here, I'm trying to do the following in one query 1) Get all unique users and the count of users 2) Using...
by therockhead Path Finder in Splunk Search 03-24-2015
0 14
0
14
jizzmaster
I have a field, Count, which is adding up to several thousand. I don't care that it is 74,743, though. I just want to...
by jizzmaster Path Finder in Splunk Search 03-24-2015
0 1
0
1
danje57
Hello, I try to create stats to have all countries and cities that communicate with my servers. I made this search:...
by danje57 Path Finder in Splunk Search 03-24-2015
1 4
1
4
kestasm
Hello, I want to exclude all the WinEventLogs for service C:\Windows\System32\svchost.exe which doesnt contain the d...
by kestasm Path Finder in Splunk Search 03-24-2015
0 10
0
10
Sloefke
Hi, I'm trying to determine the span parameter for timechart dynamically, but I can't find a way to get it to work. ...
by Sloefke Path Finder in Splunk Search 03-24-2015
1 8
1
8
tb5821
How does splunk work with multiple sub-searches? If I want to have two sub-searches which one is evaluated first? Is ...
by tb5821 Communicator in Splunk Search 03-23-2015
3 4
3
4
HattrickNZ
I am thinking of using lookups for categorizing field values into certain categories, as below. Using lookups is prob...
by HattrickNZ Motivator in Splunk Search 03-23-2015
0 13
0
13
sohnaeo
Hello Guys, I am new to Splunk so please bear with me. I am having an issue and couldn't find any resolution yet. I...
by sohnaeo New Member in Splunk Search 03-23-2015
0 8
0
8
ccollord
Hi, To make a long story short i have some logs that are key value pairs, like so: foo="bar" dog="cat" frog="bat" Un...
by ccollord Explorer in Splunk Search 03-23-2015
1 2
1
2
dfenko
I am trying to track email sending logs, using information that we adjust in the message_id while sending a message. ...
by dfenko Explorer in Splunk Search 03-23-2015
0 8
0
8
pedromvieira
Hi. I'd like to rex a field that starts with another field value. EX: ****Data UA=Mozilla/5.0 (Linux; Android 4.0...
by pedromvieira Communicator in Splunk Search 03-23-2015
1 2
1
2
tjohnson341
I am attempting to extract fields from a file which was created to be human readable, so it has fields aligned at cer...
by tjohnson341 Explorer in Splunk Search 03-23-2015
0 4
0
4
bheemireddi
Any ideas around this? When I use the fields command in this search: some search | fields Activity1, Activity2... ...
by bheemireddi Communicator in Splunk Search 03-23-2015
0 4
0
4
phuehne
The two queries: search sourcetype="access*" host="www*" | timechart count by host and search sourcetype="access*" ho...
by phuehne Explorer in Splunk Search 03-23-2015
1 8
1
8
HeinzWaescher
Hi, after updating to 6.2.2 I tried to set up a new automatic lookup. I've created the lookup definition, but I can'...
by HeinzWaescher Motivator in Splunk Search 03-23-2015
0 2
0
2
a212830
Hi, I have a tcp data stream that has embedded hosts that I need to transform, and I'm hoping to get some regex help...
by a212830 Champion in Splunk Search 03-22-2015
0 1
0
1
Sloefke
Hi, I have defined a macro that returns an amount of seconds with "s" appended to it, based on a start and end time...
by Sloefke Path Finder in Splunk Search 03-22-2015
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...