Splunk Search

Splunk Search
Community Activity
gjohnson
I have a home grown ticket system (relational database). It includes a "DateClosed" field that gets updated (obviousl...
by gjohnson New Member in Splunk Search 01-30-2015
0 1
0
1
echalex
Hi, I'm trying to convert a dashboard based on internal searches to one using data models. One thing I'm missing is ...
by echalex Builder in Splunk Search 01-30-2015
0 1
0
1
kenvanderheyden
Hi all, I'm having an issue with timestamp extraction. Trying to extract the timestamp from formatted text, and I c...
by kenvanderheyden Path Finder in Splunk Search 01-30-2015
0 7
0
7
pjb2160
Hello, I have two data sources Active Directory (Source 1) and Change Approvals (Source 2). I need to identify any A...
by pjb2160 Path Finder in Splunk Search 01-29-2015
0 2
0
2
KindaWorking
I am relatively new to all things splunk. I am trying to set up a timechart that will pass a value onto another input...
by KindaWorking Path Finder in Splunk Search 01-29-2015
0 3
0
3
liquid
I have a search head cluster (splunk 6.2) with two search head members (1 captain,1 search head,1 deployer) and one i...
by liquid Engager in Splunk Search 01-29-2015
0 1
0
1
Isaias_Garcia
Hi- I have the logs below in SPlunk. I wanted to create an alert when the UsePct is gretaer than 90%. Please help f...
by Isaias_Garcia Path Finder in Splunk Search 01-29-2015
0 2
0
2
sivagujju
I am using the below query to create a timechart. sourcetype=xxx AND source = "xxxx" | rex "Operation:(?[A-Z]*)" |...
by sivagujju New Member in Splunk Search 01-29-2015
0 6
0
6
hcheang
Hello, I've been using the query provided at http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume to g...
by hcheang Path Finder in Splunk Search 01-29-2015
0 5
0
5
datablick
Hello. I have a search that looks for event id's that are the result of a regex: index=app_sec_prod sourcetype="...
by datablick Engager in Splunk Search 01-29-2015
1 2
1
2
vishal_bandavad
I am using | dbquery to get the lookup details and outputlookup to generate the lookup file, but it always generates ...
by vishal_bandavad Explorer in Splunk Search 01-29-2015
0 3
0
3
rlough
So I finally got my query to work only to find out that subsearch has a limit to 10,000 results! Is there a way to ra...
by rlough Path Finder in Splunk Search 01-29-2015
2 5
2
5
kknopp
I am trying to rex a URL string. Here is an example: ManageAccount.do?ACTION=VIEW&id=27271905&acctViewType=transact...
by kknopp Path Finder in Splunk Search 01-29-2015
0 9
0
9
jhillenburg
Hi. I am creating a search and dashboard to display our last ten locked account events. This seems to work well as I ...
by jhillenburg Path Finder in Splunk Search 01-29-2015
1 5
1
5
blieberman
I have a search as below : index="network_wireless" sourcetype="Wireless_Client_Count*" | rex "(?[^,]*),(?[^,]*),...
by blieberman Engager in Splunk Search 01-29-2015
0 4
0
4
reswob4
I'll state my problem first, then some of the posts, apps, and documents I've looked at already.... In AD, we have a...
by reswob4 Builder in Splunk Search 01-29-2015
0 6
0
6
hartfoml
On patch night some of my splunk servers are not starting. I can see the ones that are starting with this search ho...
by hartfoml Motivator in Splunk Search 01-29-2015
0 2
0
2
jundai
This works wonderfully to give me the count and median per server farm, per URL: index=wtf earliest=10/13/2014:10:0...
by jundai Explorer in Splunk Search 01-29-2015
1 5
1
5
Splunkster45
I have a field of the following form: mysplit=A.B Where A is a string of letters and B is a Number. I'm trying...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 5
0
5
Dallastek
Im trying to count how many events by category per email domain and do a total of events going to each domain. My que...
by Dallastek Explorer in Splunk Search 01-29-2015
0 8
0
8
Splunkster45
In each log event, I have 3 fields that keep a record count of the number of rows inserted, updated and deleted. I am...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 2
0
2
marees123
*swt* "changed state to" */*/* | rex "(?i) Interface (?P[^,]+)" | rex "(?i)changed state to (?P.+)" | table host, AnI...
by marees123 Path Finder in Splunk Search 01-28-2015
0 4
0
4
nfieglein
I run this command: index=dccmtdit sourcetype=DCCMT_Log4J_JSON | transaction DpsNum maxevents=-1 It returns: 4,999...
by nfieglein Path Finder in Splunk Search 01-28-2015
0 2
0
2
smolcj
Hi, My search is like given below and my column names are source file names. As the source file name consists of dir...
by smolcj Builder in Splunk Search 01-28-2015
0 3
0
3
neha10
Hi , I have a scripted input in my app which is polling data every 60 minutes. This data brings a particular field w...
by neha10 Engager in Splunk Search 01-28-2015
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors