Splunk Search

Splunk Search
Community Activity
kpavan
Hi All, Am getting undefined fields in splunk, since all my conf files are configured correctly. If am searching the...
by kpavan Path Finder in Splunk Search 12-09-2014
1 3
1
3
pjb2160
Hello, I would like to compare two dates: log_time 08/Dec/2014:15:36:34 +1100 _time 2014-12-08 15:36:34 It is my e...
by pjb2160 Path Finder in Splunk Search 12-08-2014
0 2
0
2
Punit
I am able to create a timechart graph successfully of what I need. The timechart displays the data for each day. Now...
by Punit New Member in Splunk Search 12-08-2014
0 5
0
5
pipegrep
I'm using this search to retrieve indexing data by month; index="_internal" source="*metrics.log" group="per_host_th...
by pipegrep Path Finder in Splunk Search 12-08-2014
0 4
0
4
ravichandran
When I try the following with last 30 days in the search I run into problems: SourceName="sname" Message="**" | buck...
by ravichandran Explorer in Splunk Search 12-08-2014
0 6
0
6
ertzsmith
I need to calculate 75th percentile by minutes Time: 11:12 magnitude 3.4 Time: 11:12 magnitude 4.4 Time: 11:12 magni...
by ertzsmith New Member in Splunk Search 12-08-2014
0 5
0
5
sympatiko
HI, I just want to ask if it's possible to have an incremental number in my output table in splunk search? Example: ...
by sympatiko Communicator in Splunk Search 12-08-2014
1 2
1
2
boney_s
Hai friends, I have logged two SIMILAR files in splunk, which contains details of different meters like voltage,curr...
by boney_s Explorer in Splunk Search 12-07-2014
0 2
0
2
TIAA
/opt/splunk/var/run/searchpeer is filling up the SPLUNK home
by TIAA Engager in Splunk Search 12-07-2014
3 1
3
1
benjaminlin1019
I am looking for a way to restrict users to run "dbquery" command but still be able to access the dashboard/report th...
by benjaminlin1019 Explorer in Splunk Search 12-06-2014
0 1
0
1
niall_munnelly
Hiya, I swear I knew how to do this without macros, which seem like overkill, but I've lost it. Here's a simple exam...
by niall_munnelly Path Finder in Splunk Search 12-06-2014
2 2
2
2
tayyujie
I need to group results and give it another name as a result. For example, I have the following fruits and the numbe...
by tayyujie Explorer in Splunk Search 12-06-2014
0 5
0
5
hartfoml
I am tracking open session VPN activity VPN activity can be over long periods of time. I am traking the user activit...
by hartfoml Motivator in Splunk Search 12-05-2014
0 1
0
1
lensammus
I'd like to combine/add/include the results of a search to each item of a top 10 search for data like: msg="error ...
by lensammus New Member in Splunk Search 12-05-2014
0 1
0
1
photuris
Ok, y'all, I'm completely flummoxed. Simplified: I have two sourcetypes ("a" and "b"). Each sourcetype has 500,000 i...
by photuris Explorer in Splunk Search 12-05-2014
1 4
1
4
asherman
Hi, I want to use Timechart to track daily use, but sometimes the daily data won't arrive until 12 AM (time to compil...
by asherman Path Finder in Splunk Search 12-05-2014
0 5
0
5
landen99
For a simple example of the concept, let's consider Linux file permissions encoding of read, write and execute into a...
by landen99 Motivator in Splunk Search 12-05-2014
0 1
0
1
ravichandran
I am trying to create a report table like the following: Exception Name 1Jan 2Jan 3 Jan ....30Jan Exception 1 ...
by ravichandran Explorer in Splunk Search 12-05-2014
1 5
1
5
andreacorrie
I am trying to count occurrences of events from raw logs. Basically, if the log contains the string "MediaFailed", th...
by andreacorrie Explorer in Splunk Search 12-05-2014
0 2
0
2
philallen1
Hi So I've used Field Extractions to name 2 different fields in my logs: "dealtCurrency" and "dealtCurrencyDefault"....
by philallen1 Path Finder in Splunk Search 12-05-2014
0 5
0
5
moshiro
Wanted to know the best way to extract multiple fields along with their associated values. I have a log that I need t...
by moshiro New Member in Splunk Search 12-05-2014
0 2
0
2
abhayneilam
Hi, I have a file which has a data in which many lines are starting with "aa", so I don't want to index all the line...
by abhayneilam Contributor in Splunk Search 12-04-2014
0 5
0
5
ryoji_solsys
I would like to extract fields in the response field dynamically by using "<_KEY_1" "<_VAL_1>" in transforms.conf re...
by ryoji_solsys Explorer in Splunk Search 12-04-2014
1 2
1
2
jimjh
My data files are in Avro, and I have a props.conf that looks like [source::/logs/...] sourcetype = api [api] KV_MO...
by jimjh Path Finder in Splunk Search 12-04-2014
1 4
1
4
ryoji_solsys
Is there anyway I can modify a field name at search time ? I have a field "client__phone" (with double underscores) ...
by ryoji_solsys Explorer in Splunk Search 12-04-2014
1 3
1
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors