Splunk Search

Splunk Search
Community Activity
Splunkster45
Currently I can use a write an if statement in the following form: ... | eval adjusted_start=start_sum + 1 | eval c...
by Splunkster45 Communicator in Splunk Search 01-06-2015
1 1
1
1
Splunkster45
I want to be able to create a column on the statistic tab that has 1 if it is the start of the transaction or a 0 if...
by Splunkster45 Communicator in Splunk Search 01-06-2015
0 5
0
5
Wind
Such as when I using the following search: sourcetype="xyz" status=* |stats dc(ID) by ID status |sort by ID I will ge...
by Wind New Member in Splunk Search 01-06-2015
0 2
0
2
prabu_harsh12
string used in the search rex "(?i) Message= (?P[^.]+)" Event log form where im trying to extract "Message=The Win...
by prabu_harsh12 New Member in Splunk Search 01-06-2015
0 3
0
3
ssingh5
How we can monitor and genrate daily or weekly Splunk Health Reports? Can Splunk daemon status be monitored?
by ssingh5 Path Finder in Splunk Search 01-06-2015
0 2
0
2
ksolanki88
index="xyz_order_line"|join ORDER_NUMBER_KEY[|inputlookup sample_lookup1.csv|where serial_no>0 AND serial_no<50001]| ...
by ksolanki88 Explorer in Splunk Search 01-06-2015
0 2
0
2
akanno
Hi,Splunk community. I have a question about time-base-lookup. I set following attribute to transforms.conf [test]...
by akanno Communicator in Splunk Search 01-05-2015
0 4
0
4
DanielFordWA
Hi, I have around 50-60 searches/reports that are required to run each month after a lookup is manually updated and ...
by DanielFordWA Contributor in Splunk Search 01-05-2015
0 1
0
1
stefanlasiewski
I know that Splunk can show me results for the last 24 hours. I also know that Splunk can show me results in real tim...
by stefanlasiewski Contributor in Splunk Search 01-05-2015
0 4
0
4
bcdatacomm
I have a saved search that I alert on and there is certain events I don't want the alert to trigger for when it's com...
by bcdatacomm Explorer in Splunk Search 01-05-2015
2 2
2
2
sbeamro
Hi, when I run any search the date format is MM/DD/YEAR. how can I change the format to appear as DD/MM/YEAR ?
by sbeamro Explorer in Splunk Search 01-05-2015
1 7
1
7
epacke
Dear experts! Happy new year to you all.  Got a strange thing when I am creating a timechart in Splunk in the panel...
by epacke Path Finder in Splunk Search 01-05-2015
0 2
0
2
himynamesdave
Happy New Year everyone! Regex n00b here - I am struggling to break events for a particular source. Any help would b...
by himynamesdave Contributor in Splunk Search 01-04-2015
0 5
0
5
davidatpinger
My apologies if this is easy - I couldn't find a good example. I've got some log data that is mostly nicely formatte...
by davidatpinger Path Finder in Splunk Search 01-02-2015
0 7
0
7
shandman
I have seen several threads opened with this issue, but nothing that fits the situation we are facing. This is taki...
by shandman Path Finder in Splunk Search 01-02-2015
0 3
0
3
rameshlpatel
Hi, I am printing current time in java milisecond in logs which i want to show in splunk by converting that into d...
by rameshlpatel Communicator in Splunk Search 01-02-2015
0 1
0
1
dondky
Hi guys, I'm working on calculating the average time spent by a user on a internal iis site in our environment. I ...
by dondky Path Finder in Splunk Search 12-31-2014
1 1
1
1
splunkn
I am in need of the following requirement. Could anyone help me with this? I need to extract the users for 200+ appli...
by splunkn Communicator in Splunk Search 12-31-2014
0 1
0
1
lennys26
I have a search which gives a top 5 list of faults (S3_call_error2) for a customer base. Instead of just showing the...
by lennys26 Communicator in Splunk Search 12-31-2014
1 6
1
6
anupkpurushu
The schema file and data file both reside on hdfs. Hunk is able to read the data file and show the raw data but it d...
by anupkpurushu New Member in Splunk Search 12-30-2014
0 6
0
6
Oti47
Hello, how could I add more email recipients to one Report? Like cc: 123atmyhohme.com, 456atmyhome.com regards Mich...
by Oti47 Path Finder in Splunk Search 12-30-2014
0 4
0
4
richard_g_curry
One of my business partners wants to create a search on his Akamai data taking the Rule IDs from the WAS Info field a...
by richard_g_curry Explorer in Splunk Search 12-30-2014
0 2
0
2
Splunk_U
I have written the below search string: index=os source=interfaces | multikv fields RXbytes, TXbytes ...
by Splunk_U Path Finder in Splunk Search 12-30-2014
0 5
0
5
shellnight
Need to find hosts where an event of a type was not followed by event of another type within an hour I need to find...
by shellnight Explorer in Splunk Search 12-29-2014
1 14
1
14
kenvanderheyden
Hi all, Working in splunk 6.2.1 enterprise. I have the following dataset (simplified) SomeDateField Event1 Event...
by kenvanderheyden Path Finder in Splunk Search 12-29-2014
1 1
1
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...