Splunk Search

Splunk Search
Community Activity
masumbuet
Hi, I want to select fields conditionally based on user input. It is a drilldown search. I want to show specific fiel...
by masumbuet New Member in Splunk Search 12-12-2014
0 1
0
1
harshnagpal
0
1
shingdayho
Hi, I want to find information from 2 hosts, I can do it by running the command below: 192.168.144.1 OR 192.168.24...
by shingdayho Explorer in Splunk Search 12-12-2014
0 8
0
8
edookati
I am using the below query, but few events in the logs don't have service_name values. They only have operation_name....
by edookati Path Finder in Splunk Search 12-11-2014
0 2
0
2
snemiro_514
Hi splunkers, I need to create a new attribute in one datamodel. I think I don't understand the syntax or what's goi...
by snemiro_514 Path Finder in Splunk Search 12-11-2014
0 1
0
1
hcheang
Hello. I would like to know if there is any speicific - convenient - way to perform stats count by various date. Us...
by hcheang Path Finder in Splunk Search 12-11-2014
0 4
0
4
ajm33
I'm currently trying to join two log events across separate sources using their file name. The issue i have run in to...
by ajm33 Engager in Splunk Search 12-11-2014
0 3
0
3
chengka
Splunk 6.2 I used the Field Extractor app to extract a field from an previous field. The resulting extraction tested...
by chengka Explorer in Splunk Search 12-11-2014
0 6
0
6
andrewkenth
I have a chart displaying in dashboard panel. When a value is 0 I'd like to call it out by makeing the text or backgr...
by andrewkenth Communicator in Splunk Search 12-11-2014
0 1
0
1
sumanth_isac
Hi I have data as below. 9B 85 65 70 20 61 6C 69 76 65 2C 33 30 30 30 30 3C 00 is one pattern 9B 85 65 70 20 61 6...
by sumanth_isac Path Finder in Splunk Search 12-11-2014
0 3
0
3
idsiano
I have a log that contains a polling state of a device, PLUGGED/UNPLUGGED, logged every 10 s. I want to chart a timel...
by idsiano Explorer in Splunk Search 12-10-2014
0 2
0
2
mmaier_splunk
Hello, i have an application that has an bug in the logging, but i need to workaround it. log structure: Dec 10 ...
by mmaier_splunk Splunk Employee Splunk Employee in Splunk Search 12-10-2014
0 4
0
4
terryloar
... | tail 200 works fine. ... | eval tail_value=200 | tail tail_value throws this error: Error in 'tail' comm...
by terryloar Path Finder in Splunk Search 12-10-2014
0 2
0
2
Runals
I have one set of logs showing authentication which contain time stamps, user names, and IP addresses (source 1). I'd...
by Runals Motivator in Splunk Search 12-10-2014
0 5
0
5
ckals46
hello all! I have a sentense of raw data so I want to extract only one field. raw data's example : A,B,C,D,E,F,12...
by ckals46 New Member in Splunk Search 12-10-2014
0 1
0
1
anoopambli
I have two queries, 1) index = coreops sourcetype=sitescope_monitorstat UpTime | rex field=_raw "days=\s(?\d+)" | wh...
by anoopambli Communicator in Splunk Search 12-10-2014
0 1
0
1
dhavamanis
We have the logs with milliseconds, but when use _time function and its not giving the second level grouped results, ...
by dhavamanis Builder in Splunk Search 12-10-2014
0 5
0
5
prashantjois
I'm trying to build a table of outages. For example: Host Num. Outages A 1 B 2 C 0 Servers ...
by prashantjois Explorer in Splunk Search 12-10-2014
0 5
0
5
agoktas
Hello, I have two searches that alert on every occurrence: 3rd party agent drops offline: index=app_evtlogs_prod ...
by agoktas Communicator in Splunk Search 12-10-2014
1 8
1
8
DerekKing
Hi, I would like to be able to push a new value into a multi-valued field, from another field. ie. Field1="Derek"...
by DerekKing Path Finder in Splunk Search 12-10-2014
1 2
1
2
_gkollias
Hello, I am looking for a way to calculate the avg rate of occurrence for a particular field. There are multiple va...
by _gkollias Builder in Splunk Search 12-10-2014
0 1
0
1
krwinters11
I am using the predict command like this: | timechart values(Recovery) as values | predict values Can someone help m...
by krwinters11 Path Finder in Splunk Search 12-10-2014
0 2
0
2
krwinters11
I have done 2 (what I thought were) identical searches. One ended with: | timechart first(valueA) as A first(valueB...
by krwinters11 Path Finder in Splunk Search 12-10-2014
0 1
0
1
ajeeshneelamkav
Hi All, I am new to Splunk and need to complete the below use case Files in a linux directory are regularly archive...
by ajeeshneelamkav New Member in Splunk Search 12-10-2014
0 11
0
11
denmatias
Hi, How to loop like this Event fields field1 [value1a, value1b, value1c, value1d,...] field2 [value2a, value2b, v...
by denmatias New Member in Splunk Search 12-10-2014
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...