Splunk Search

Splunk Search
Community Activity
tmurray3
I am trying to create a report to display the top 5 clients by total volume and their percentage of total volume from...
by tmurray3 Path Finder in Splunk Search 12-16-2014
0 1
0
1
nikhiltyagi
Hi, I am fairly new to splunk. I am trying to execute a subsearch. As a simple debug this is what I tried: Query - ...
by nikhiltyagi Explorer in Splunk Search 12-16-2014
0 1
0
1
patrice_boodhoo
I would like to have the same order of fields from the result when executing a search command from the user interface...
by patrice_boodhoo New Member in Splunk Search 12-16-2014
0 2
0
2
Paul82
I imagine what I'm trying to do is fairly simple, but I don't know how to do it. I need to search our logs through t...
by Paul82 New Member in Splunk Search 12-16-2014
0 2
0
2
joxley
I have the following data start_station | end_station _____________________________ Wimbledon | Waterloo Wim...
by joxley Path Finder in Splunk Search 12-16-2014
1 2
1
2
ChrisGermer
hi there, i'm very new to splunk and not much experience yet. the splunk-answers are great and helped me a lot. but ...
by ChrisGermer New Member in Splunk Search 12-16-2014
0 3
0
3
BunnyHop
I would like to create a graph that would show values compared from an initial source. Here's an example: [file1.t...
by BunnyHop Contributor in Splunk Search 12-15-2014
0 3
0
3
tomarcen
Hi. I've load splunk with my email logs. I'm getting all the url's in an email in _raw field. In an e-mail, if ther...
by tomarcen New Member in Splunk Search 12-15-2014
0 2
0
2
boney_s
Hello friends, I have indexed my own .log file in to Splunk and there are about 10 events in that log files. I wonde...
by boney_s Explorer in Splunk Search 12-15-2014
0 11
0
11
arungeorge09
I have a common field and 2 joins and want to work on the data which does not fall in the join condition.
by arungeorge09 Path Finder in Splunk Search 12-15-2014
0 5
0
5
jfreund
Hey folks, I have data formatted as follows time fielda fieldb I want to find the top 3 values of fielda for each ...
by jfreund Explorer in Splunk Search 12-15-2014
0 5
0
5
msarro
Hello everyone. We have been tasked with creating a report that examines the call use patterns of 3 customers. Each ...
by msarro Builder in Splunk Search 12-15-2014
1 2
1
2
DW2054
How to create a sudo to root, dedup 24 hour by user report? So far I have: process=sudo "USER=root"| rex "(?i) PWD...
by DW2054 Engager in Splunk Search 12-15-2014
0 2
0
2
efelder0
I have 2 fields in CSV that I want to only display the top 3 employees by the Class frequency. I know the Top command...
by efelder0 Communicator in Splunk Search 12-15-2014
0 3
0
3
ma_anand1984
I would like to create an email report with following details that runs every day All admin users All power users Us...
by ma_anand1984 Contributor in Splunk Search 12-15-2014
0 6
0
6
treinke
Looking to do a chart and even if the count of a value is 0 still diplay the name of the value. My search so far is:...
by treinke Builder in Splunk Search 12-15-2014
0 1
0
1
jagadish85
Hi, I want to extract the class Names which created the exceptions from the application server logs stacktrace. For...
by jagadish85 Path Finder in Splunk Search 12-15-2014
0 6
0
6
des_esse_err
It's a simple search query. It needs to find events containing a file name which will change every month. The eval c...
by des_esse_err Explorer in Splunk Search 12-15-2014
0 3
0
3
ArsenyKapralov
Hello I'm trying to use rtrim to modify dns host name which I receive from domain controller. I'm using following se...
by ArsenyKapralov Path Finder in Splunk Search 12-15-2014
2 1
2
1
solarboyz1
I have events from a Cisco ISE device that have multiple (up to 12) "posture reports" per message: … PostureReport=2...
by solarboyz1 Builder in Splunk Search 12-15-2014
0 2
0
2
arungeorge09
I want to join 2 queries by a common field and the counts of the searches are different. I want to work on the datase...
by arungeorge09 Path Finder in Splunk Search 12-15-2014
0 16
0
16
mark_chuman
Trying to create a useful CPU usage search, but coming up short. This search does not reflect what is actually being...
by mark_chuman Path Finder in Splunk Search 12-15-2014
0 9
0
9
RobertRi
Hi I have a timechart with integers, every minutes. Normaly, the value of the integers are between 1 and 120. Someti...
by RobertRi Communicator in Splunk Search 12-15-2014
0 5
0
5
arungeorge09
I have 2 indexes and would like to join them with a common field and the names are not same . I tried all posts with ...
by arungeorge09 Path Finder in Splunk Search 12-15-2014
0 9
0
9
henry_ty_leung
As stated in subject line, i would like to split a huge log with past 12 months' log records and dynamically without ...
by henry_ty_leung Explorer in Splunk Search 12-15-2014
0 6
0
6
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...