Splunk Search

Splunk Search
Community Activity
BrandSentiment
Is this string anywhere near where I need to be to find word1 and word2 no more than 6 words apart in the field inter...
by BrandSentiment Explorer in Splunk Search 10-26-2014
1 4
1
4
shellnight
Is there a query to combine 2 searches a running normal search and stats search and display a single output o...
by shellnight Explorer in Splunk Search 10-25-2014
0 23
0
23
pparkerntx99
Hope I get some help, message: The lookup table 'lo_hi_subnet_CIDR' does not exist. It is referenced by configuratio...
by pparkerntx99 Explorer in Splunk Search 10-24-2014
0 1
0
1
harshal_chakran
Hi, I have a csv file which looks like this I am trying to display a table with "ID" and "timestamp "displaying...
by harshal_chakran Builder in Splunk Search 10-24-2014
0 5
0
5
melonman
Hi, I want to index/lookup data stored in Vertica. Could I use DB Connect for this purpuse? Has anyone actually done...
by melonman Motivator in Splunk Search 10-24-2014
2 5
2
5
tmelios
I am trying to figure out how to get duration returned in milliseconds between two events. Transactions are great to ...
by tmelios Engager in Splunk Search 10-24-2014
0 5
0
5
ho000dor
Hi, Does anyone know what i need to put in between these two fields in order to make the query continue on the ip2 i...
by ho000dor Explorer in Splunk Search 10-24-2014
0 8
0
8
snemiro_514
Im rewritting a dashboard using data models. So far so good, but I'm stuck at this point where I need to redefine two...
by snemiro_514 Path Finder in Splunk Search 10-24-2014
1 1
1
1
tfitzgerald15
I'm working on a chart which will map a baseline of existing data. The search I am currently using is as follows. so...
by tfitzgerald15 Explorer in Splunk Search 10-24-2014
0 1
0
1
narduk
I am having a problem extracting multivalued fields. I think it's because this particular field is quoted. ids=\"XXX...
by narduk Explorer in Splunk Search 10-24-2014
1 10
1
10
craigkleen
I need a little help putting all the pieces together on this. I'm trying to build a table in Splunk that would show ...
by craigkleen Communicator in Splunk Search 10-24-2014
0 6
0
6
sibanandapani1
We have few searches. How to find whether search is a rare search, or Dense or Sparse search. Was there anywhere log...
by sibanandapani1 Explorer in Splunk Search 10-24-2014
0 1
0
1
akhan8928
Hey all, We are recording very order we receive as an event. What I'd like to do is get a count every 15 minutes rea...
by akhan8928 New Member in Splunk Search 10-24-2014
0 2
0
2
Mahieu
Hi everyone, I'm seeing strange results using stdev. I'm using the following command : sourcetype=whatever | stats ...
by Mahieu Communicator in Splunk Search 10-24-2014
2 3
2
3
PabloBonilha
Hello everyone, I'm trying to consolidate the percentage of errors per day using the query below, but this is not ha...
by PabloBonilha Explorer in Splunk Search 10-24-2014
1 4
1
4
andrey2007
I have an index with start and finish time of user`s workday 27.08.2014 user="userA" weekday="monday" worktime="10....
by andrey2007 Contributor in Splunk Search 10-24-2014
1 6
1
6
abhayneilam
Hi, I have a correlation ID in one index ( index="AAA" | rex "XXXXXX\]\[(?.*?)\]" ) which I want to match wit...
by abhayneilam Contributor in Splunk Search 10-24-2014
0 4
0
4
conor_splunk
I am trying to extract a field from a Windows event which can contain multiple values. At the search line I can do th...
by conor_splunk Path Finder in Splunk Search 10-24-2014
1 1
1
1
daniel_hanft
Hi Splunk Community, how many splunk processes are normal on a Linux Indexer? I've observed sometimes there are up t...
by daniel_hanft Explorer in Splunk Search 10-23-2014
1 5
1
5
alucas_1stop
I spent about 5 minutes trying to figure out how to even title this question. Its much easier explained by this exam...
by alucas_1stop New Member in Splunk Search 10-23-2014
0 14
0
14
tlow
Hi, i'm try using the interactive field extractor tools create a field for this "Exception Message"="Thread was bein...
by tlow Explorer in Splunk Search 10-23-2014
0 5
0
5
victorstarosten
I need to find unique hosts consumed by a specific index. I use the following search string: index=my_index |stats ...
by victorstarosten Engager in Splunk Search 10-23-2014
0 4
0
4
armonsal
Hello everyone, I have events with this format 10/23/2014 04:00:02 -0300, search_name=CDR_INSTITUCIONES_APP, search...
by armonsal Explorer in Splunk Search 10-23-2014
0 3
0
3
a212830
Hi, I have a very ugly data feed, and the customer thinks that they are getting duplicate events, because the event ...
by a212830 Champion in Splunk Search 10-23-2014
0 3
0
3
vtsguerrero
Hello guys! I know Splunk has a REGEX helper, but in this case, I have an amount of data wich is almost binary, take ...
by vtsguerrero Contributor in Splunk Search 10-23-2014
1 14
1
14
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...