Splunk Search

Splunk Search
Community Activity
ckurtz
Just moved to a new 6.2.2 Search Head Cluster (SHC) from a Search Head Pool (SHP) which had mounted bundles enabled. ...
by ckurtz Path Finder in Splunk Search 03-20-2015
0 1
0
1
IngloriousSplun
I have two different network sensors - Sensor A and Sensor B. Each has their own event format that I aggregate in Sp...
by IngloriousSplun Communicator in Splunk Search 03-20-2015
2 10
2
10
harshal_chakran
Hi, I have a csv file as shown below: DATE VALUE 1-Jan 2 02-Jan 3 04-Jan 5 05-Jan ...
by harshal_chakran Builder in Splunk Search 03-20-2015
0 2
0
2
rlough
Hey everyone, We currently have a query that tracks the top 100 users hitting our server in the past 24hrs. It looks...
by rlough Path Finder in Splunk Search 03-20-2015
0 4
0
4
moiezuddin
I have a source="/opt/www/logs i need the fields jobTitle, orgName, orgSegment, parentOrgname, and userType Can any...
by moiezuddin Explorer in Splunk Search 03-20-2015
0 2
0
2
reedmohn
At the risk of once again displaying my ignorance... I added this transform regex to transforms.conf: [myformat] REG...
by reedmohn Communicator in Splunk Search 03-20-2015
0 14
0
14
vinodmadaan
Hi Guys, I am working with pivot in splunk and what I want from the pivot (bar chart) is to display bars in differen...
by vinodmadaan Path Finder in Splunk Search 03-20-2015
0 3
0
3
bibc
I'm using the following regex to extract name from data: .. | rex "@name='(?P<Name>[^']+)" max_match=0 This works ...
by bibc Explorer in Splunk Search 03-20-2015
1 5
1
5
ektasiwani
I am new to Splunk so just want to know that if I have a python variable with some value, can I pass that value in a ...
by ektasiwani Communicator in Splunk Search 03-19-2015
0 3
0
3
lukeh
Hi Ninjas, I have a search which produces a bar chart comparing four different fields week over week: index=foo con...
by lukeh Contributor in Splunk Search 03-19-2015
2 2
2
2
mookiie2005
I need to mask WILLIAM as seen below: 2015-03-18 10:04:37,453 [WebContainer : 1] INFO com.farmers.ffq.saq.service.S...
by mookiie2005 Communicator in Splunk Search 03-19-2015
0 3
0
3
ianshefferman
We have a situation where our organization hosts 2 separate Splunk instances, each containing different indexes and e...
by ianshefferman Explorer in Splunk Search 03-19-2015
0 1
0
1
HattrickNZ
I have the following search with OR operators index=index1 host=host1 elementType=ET measInfoId=117440551 OR measIn...
by HattrickNZ Motivator in Splunk Search 03-19-2015
0 3
0
3
rgoody
Have source from cisco:asa with a field value of user. The following search(s) will return all values for user: (Th...
by rgoody New Member in Splunk Search 03-19-2015
0 10
0
10
jgcsco
I am counting the occurrence of uniq keys in the log file and need to do the following count: <...>key1<....> <...>k...
by jgcsco Path Finder in Splunk Search 03-19-2015
1 2
1
2
matthieu_araman
Hello, I'm trying to generate sample logs with eventgen in my eventgen.conf, I'm using token.1.token = ipsrc token....
by matthieu_araman Communicator in Splunk Search 03-19-2015
0 1
0
1
smudge797
How can i search on this Key Value pair to display PricingInfo / PriceCount An example log entry may look like the b...
by smudge797 Path Finder in Splunk Search 03-19-2015
0 6
0
6
hofer
I have an timechart (over 1 hour) with "count by STATUS" and i changed the span of the timechart to 4s, since Splunk ...
by hofer Explorer in Splunk Search 03-19-2015
0 1
0
1
badadata1
How do I return events from searching the Splunk internal field _cd? For example, the following are the _cd values. ...
by badadata1 Explorer in Splunk Search 03-19-2015
0 4
0
4
kartik13
Hi, By using intersect i got the list of hosts. now i want to to get the list of errors in those host. how can i ach...
by kartik13 Communicator in Splunk Search 03-19-2015
0 2
0
2
hofer
I'd like to make a chart on how many times a state-text occurs. The thing is, there can be more than one state-text i...
by hofer Explorer in Splunk Search 03-19-2015
0 2
0
2
moiezuddin
I have a search: source="/opt/www/logs/nbcucentral/nbcucentral.log"| rex "(?P\w+.\w+@\w+.\w+)" | rex "details (?P\w+...
by moiezuddin Explorer in Splunk Search 03-19-2015
0 8
0
8
skoelpin
I have a query which returns back response times that are greater than 5 seconds.. I then set an alert to email me wh...
by SplunkTrust SplunkTrust in Splunk Search 03-18-2015
0 4
0
4
asdfasdf12321
So I have the search: index=testIndex1 | eval newField=userName+age I look through the results, set the newField...
by asdfasdf12321 Explorer in Splunk Search 03-18-2015
1 4
1
4
sat94541
Splunk deployment -adhoc query have been slow for the past months. 1- We upgraded our system from 2 core to 12 core...
by sat94541 Communicator in Splunk Search 03-18-2015
2 3
2
3
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...