Splunk Search

Splunk Search
Community Activity
solarboyz1
From our Cisco ISE we get Posture report events, each event can have multiple PostureReports. PostureReport=Encase ...
by solarboyz1 Builder in Splunk Search 12-03-2014
0 6
0
6
IvyZhang
I need the count, average response time, and stdev response time for top 10 users. I also want to group the rest of u...
by IvyZhang New Member in Splunk Search 12-03-2014
0 1
0
1
pbourit
Hi, I use a csv file as a lookup in a search command like this : sourcetype="airmantool" | rex ".\s(?[A-Z]+)\s+[(...
by pbourit New Member in Splunk Search 12-03-2014
0 2
0
2
akelly4
I'm trying to figure out if it's possible to take the results out of a search and define them and automatically use t...
by akelly4 Path Finder in Splunk Search 12-03-2014
0 3
0
3
nibinabr
I have a log file that has the start_time and stop_time of different actions. We can call the action to be in the "ac...
by nibinabr Communicator in Splunk Search 12-03-2014
0 10
0
10
subtrakt
Hello - Any suggestions on how to append a subsearch where count < 50? ...|stats count | where count < 50 | append...
by subtrakt Contributor in Splunk Search 12-02-2014
0 7
0
7
intachur
Hi! I would like to extract fields from my nginx access log which was configured so: '[ $connection : $msec : $requ...
by intachur Explorer in Splunk Search 12-02-2014
0 6
0
6
vasanthmss
Hi There, Identify the transaction duration based on individual field, field3,fiel4 values. Events may not be same ...
by vasanthmss Motivator in Splunk Search 12-02-2014
1 1
1
1
sat94541
I have two Data Centers: one in New York (NY) and other in San Francisco (SF) city. We have a Cluster Master , Searc...
by sat94541 Communicator in Splunk Search 12-02-2014
1 1
1
1
sat94541
Can the Cluster Peer be re-added to the Cluster Master without restarting Cluster master or the Cluster Peer? I have ...
by sat94541 Communicator in Splunk Search 12-02-2014
0 1
0
1
edookati
I need the 90th percentile value in a series of values and the count of values that are greater than the 90th percent...
by edookati Path Finder in Splunk Search 12-02-2014
0 3
0
3
Meena27
Hi, I am trying to work to get "Specific text" in the subject of an alert using regex if possible. Here it goes, ...
by Meena27 Explorer in Splunk Search 12-02-2014
0 1
0
1
elaineli1010
I'm trying to query instances where Security_ID != {Domain Name}\Account_Name in the security event logs per Microsof...
by elaineli1010 Engager in Splunk Search 12-02-2014
1 3
1
3
italogf
Is It possible do two different searches and write the output data in another index?
by italogf Explorer in Splunk Search 12-02-2014
0 1
0
1
templier
Hello. Can you help me? I have a log: filename":"\u0421\u043e\u0433\u043b\u0430\u0448\u0435\u043d\u0438\u0435 \...
by templier Communicator in Splunk Search 12-02-2014
0 4
0
4
rsathish47
Hi All, Where do we find date of creation for Knowledge objects (Searches and reports, Event types, Tags, Fields and...
by rsathish47 Contributor in Splunk Search 12-01-2014
2 2
2
2
subtrakt
Greetings! Trying to build a search that automatically compares volume for this year against the same day of the wee...
by subtrakt Contributor in Splunk Search 12-01-2014
2 5
2
5
ShaneNewman
I have setup a MSSQL database connection using the DB Connect App, this database does have a specific port. When sett...
by ShaneNewman Motivator in Splunk Search 12-01-2014
0 2
0
2
mlf
I have a search that generates 24 hours of timechart results with a 10 minute span. The search returns expected resu...
by mlf Path Finder in Splunk Search 12-01-2014
0 5
0
5
g_prez
having some time trying to extract fields automaticaly from the message below. really wanted to test out the xtract b...
by g_prez Path Finder in Splunk Search 12-01-2014
0 4
0
4
sideview
First, the answer here may be to simply not use span=1h at all, but rather to use bins=500 or some similar number in...
by SplunkTrust SplunkTrust in Splunk Search 12-01-2014
1 2
1
2
bruceclarke
All, I'd like to do something like the following | dbquery MyDatabase "SELECT * FROM myTable WHERE timestamp > '$ea...
by bruceclarke Contributor in Splunk Search 12-01-2014
3 1
3
1
prabhu_kar
We have a CSV fields set defined (shortening it here), Txn,Destination,Status test1,NY,Pass test2,NY,Pass test2,NY,...
by prabhu_kar New Member in Splunk Search 12-01-2014
0 6
0
6
ITCrowd
(index=unix) (sourcetype="web") | eval Time.atFirewall=DateOutbound-DateInbound | eval Time.atDataCentre=strptime(ind...
by ITCrowd Engager in Splunk Search 12-01-2014
0 2
0
2
jwf
Hello. I want to get a statistic for values of every X number of non-overlapping events. For example, for events wit...
by jwf New Member in Splunk Search 12-01-2014
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...