Splunk Search

Splunk Search
Community Activity
IVV
Hello! I have such events: 1: name="Alex" groups="['staff', 'manager', 'top']" 2: name="Paul" groups="['sta...
by IVV Path Finder in Splunk Search 02-06-2015
0 5
0
5
ssubbiah001
I'm new to splunk and am facing an issue when doing a search using Java SDK. I have a search that should return arou...
by ssubbiah001 Explorer in Splunk Search 02-06-2015
0 2
0
2
rus7am
Hello, We have this search below: stats count(eval(State="OPEN")) as "Open", count(eval(State="CLOSED")) as "Close...
by rus7am Explorer in Splunk Search 02-06-2015
0 2
0
2
hhlee
Hi Splunker! I have some trouble extracting values. for example, fruits apple (blah blah blah) apple (blah2 blah2 b...
by hhlee Engager in Splunk Search 02-05-2015
0 4
0
4
valameti
Hi, Can any one help me how to display the below value which is in double quotation using rex command API : IO ET ...
by valameti Explorer in Splunk Search 02-05-2015
0 2
0
2
joyce1018
example [dto=forename: "abcforename" surname: "abcsurname" ..................] I want to extract the forename and s...
by joyce1018 New Member in Splunk Search 02-05-2015
0 2
0
2
Runals
For embedded reports, is there a way to return just the table view of the data? I've embedded a search, it has run on...
by Runals Motivator in Splunk Search 02-05-2015
0 1
0
1
nravichandran
I want to calculate availability of an application. The logic i am using is number of errors per minute. So I am sear...
by nravichandran Communicator in Splunk Search 02-05-2015
0 3
0
3
adomila
Hi, I would just like to ask, as to how I could extract country codes within series of numerical values with no fix l...
by adomila Explorer in Splunk Search 02-05-2015
1 9
1
9
aelliott
Has anyone else pulled Incident Logs from SCSM (System Center 2012 Service Manager) into Splunk and what method(s) di...
by aelliott Motivator in Splunk Search 02-05-2015
0 2
0
2
jackson1990
I need to create table with fields present in Events result,excluding internal fields. Example: Indexed Data: A=xxx...
by jackson1990 Path Finder in Splunk Search 02-05-2015
0 2
0
2
sideview
In a funny way Im looking for the opposite of fillnull. I have some fields which are sometimes coming through with ...
by SplunkTrust SplunkTrust in Splunk Search 02-05-2015
0 5
0
5
jonnycundall
I expect this is easy and I missed something obvious. I am new to this tool. I created a field extraction from the s...
by jonnycundall Engager in Splunk Search 02-05-2015
0 3
0
3
paramagurukarth
We are just trying to handle a worst case where number of events crosses 50,000. I am using python "splunk.search.dis...
by paramagurukarth Builder in Splunk Search 02-04-2015
0 2
0
2
a212830
Hi, I need to create a field on the source field, but am not sure how to do that. Can someone help me?
by a212830 Champion in Splunk Search 02-04-2015
0 23
0
23
avilandau
I'm not sure this is the only way to do what I need, but this is the only thing I could think of. I have a table wit...
by avilandau Path Finder in Splunk Search 02-04-2015
3 4
3
4
RecoMark0
Hello, I am wondering if the timerange value a user selects for a search is able to be extracted from a field. For...
by RecoMark0 Path Finder in Splunk Search 02-04-2015
0 2
0
2
agoktas
Here is my search: index=windows source="WMI:Services" State=Stopped StartMode=Auto | rex field=_raw "\nName=(?PIB...
by agoktas Communicator in Splunk Search 02-04-2015
1 3
1
3
trodenbaugh
I'm trying to use a timechart function to display folder names and their sizes over time. When I do this, the string...
by trodenbaugh Explorer in Splunk Search 02-04-2015
0 2
0
2
njathan
Before really putting my custom regex in transforms.conf, is there a quick way to test and debug it?
by njathan Explorer in Splunk Search 02-04-2015
1 10
1
10
jlhamlet
Hi, I am indexing data with events in this format: Field1:value1|Field1:value2 ..... In my transforms.conf i set t...
by jlhamlet Path Finder in Splunk Search 02-04-2015
0 3
0
3
ttudor
I have the following fields stu_id, duration, and date_month. I want to do a search to display all sru_id's that hav...
by ttudor Explorer in Splunk Search 02-04-2015
1 4
1
4
turanascioglu
Hi, I'm new to Splunk and we would like to buy the enterprise version. Currently I'm testing and now I stumbled upon...
by turanascioglu New Member in Splunk Search 02-04-2015
0 7
0
7
joxley
Background: In a dashboard, I have a token excludes which I want someone to be able to enter 1*,5* into. I then want...
by joxley Path Finder in Splunk Search 02-04-2015
0 3
0
3
GandalfsApprent
Hey, All my users except admin are getting this error: Streamed search execute failed because: User '' could not act ...
by GandalfsApprent Engager in Splunk Search 02-04-2015
1 6
1
6
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...