Splunk Search

Splunk Search
Community Activity
nidet
I have a folder which stores .txt files. I need to compare the data that is inside the files. Not only accumulate the...
by nidet Explorer in Splunk Search 11-25-2014
0 7
0
7
cogrunc
Hello, I deleted the redundant logs from an index with "delete" command. Now, I would like to update the metadata inf...
by cogrunc New Member in Splunk Search 11-25-2014
0 2
0
2
landen99
I am looking to identify the earliest event for each field-value pair. For example, given a list of usernames from A...
by landen99 Motivator in Splunk Search 11-25-2014
0 1
0
1
abhayneilam
Hi, I have created a dashboard in which I have added a timepicker and I have opened a drop-down menu which defines t...
by abhayneilam Contributor in Splunk Search 11-25-2014
0 3
0
3
MayankSplunk
From my search and transaction command I get the following table. To further process my results, I want to remove th...
by MayankSplunk Path Finder in Splunk Search 11-25-2014
1 5
1
5
Lowell
How can I easily add a "search bar" to the top of my own dashboards? Trying to add a quick and convenient way for le...
by Lowell Super Champion in Splunk Search 11-25-2014
0 2
0
2
snabel
Hi, I've this log entry: "2014-11-22 02:42:10,545 .. - average:2.74425 , min:1.43 , max:4.007..." i want to create...
by snabel Path Finder in Splunk Search 11-25-2014
1 5
1
5
martin_mueller
Converted from http://answers.splunk.com/answers/193524/how-to-write-a-search-to-return-events-with-a-vari.html Hi, ...
by SplunkTrust SplunkTrust in Splunk Search 11-25-2014
1 1
1
1
pde7
I want to dynamically set the earliest time to the first instance of a particular event. Is there a way to do that?...
by pde7 Explorer in Splunk Search 11-25-2014
0 4
0
4
ashnet16
I'm trying to exclude the word query and in from my string to create a new field called query. I'm not having any luc...
by ashnet16 Path Finder in Splunk Search 11-25-2014
0 2
0
2
Raghav2384
Hello Experts, I am trying to extract key-value pairs from the following. Here's the sample log. I have tried using ...
by Raghav2384 Motivator in Splunk Search 11-24-2014
0 6
0
6
sunrise
Hi Splunkers, I'm considering about splunk clustering in VM env, 1 Search Head, 3 Search Peers, 1 Cluster Master. An...
by sunrise Contributor in Splunk Search 11-24-2014
1 2
1
2
JWBailey
:: my search :: | stats count dc(player) by result Let’s say the result field has two possible values, Win and Los...
by JWBailey Communicator in Splunk Search 11-24-2014
0 7
0
7
subtrakt
Is there a way i can have a search look at a lookup that has predefined search queries in each row and then run a sea...
by subtrakt Contributor in Splunk Search 11-24-2014
0 3
0
3
nterry
So I am trying to filter out outliers using the 3 sigma rule across some transactions. My search is as follows: blah...
by nterry Path Finder in Splunk Search 11-24-2014
0 3
0
3
adewinter
I have a field "LYC_USERNAME" that shows up in our logs. In order to determine the total number of distinct users of...
by adewinter Explorer in Splunk Search 11-24-2014
0 5
0
5
mmouse88
Using 6.1, I would like to create a horizontal line with area chart. I have read so many examples and my search comm...
by mmouse88 Path Finder in Splunk Search 11-24-2014
0 8
0
8
dolfantimmy
I am using a search cloned from the SoS app. I modified it to sort in the search itself. Though the search does run...
by dolfantimmy Path Finder in Splunk Search 11-24-2014
0 6
0
6
bruno_eduardo
I have a Risk field with this possible values (Critical, High, Medium, Low) and I want to be red when critical, high ...
by bruno_eduardo Path Finder in Splunk Search 11-24-2014
0 4
0
4
feickertmd
Does there exist some sort of map or guide to understanding Splunk's internal indexes (_internal, _audit, _introspect...
by feickertmd Communicator in Splunk Search 11-24-2014
3 5
3
5
harish_ka
I have search result of last 10 days. Can we get the count based on time range, like "count(Alert) as Total count w...
by harish_ka Communicator in Splunk Search 11-24-2014
1 4
1
4
r2r2
Hello! I am trying to make a dashboard with fields from 2 indexes using the command "join". I wrote a search source="...
by r2r2 Explorer in Splunk Search 11-24-2014
0 6
0
6
hbenaicha
Hi, i am desperately seeking help as I am a beginner Splunk user and I am struggling to extract the data I need from ...
by hbenaicha Engager in Splunk Search 11-23-2014
0 4
0
4
abhisawa
I have cluster of more than 100 hosts which getting data over network from multiple source. I can calculate rate of i...
by abhisawa Explorer in Splunk Search 11-23-2014
0 6
0
6
abhayneilam
Hi, I have a query like : index=XXX sourcetype=YYY |search AGE = "*" NAME="CIA" OR NAME="FIA" |timechart span=1...
by abhayneilam Contributor in Splunk Search 11-23-2014
0 5
0
5
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...