Splunk Search

Splunk Search
Community Activity
Splunkster45
I have two types of logs in my files that record when a user logs in and logs out. They are of the form: Session <nu...
by Splunkster45 Communicator in Splunk Search 10-16-2014
0 1
0
1
jaj
I have a log where labelData=123-345 or lableData=123 How I want to ignore the -345 and just keep the first ...
by jaj Path Finder in Splunk Search 10-16-2014
0 6
0
6
FutureSight
In order for me to create appropriate Splunk alerts for a certain process, I need to be able to dynamically generate ...
by FutureSight Engager in Splunk Search 10-16-2014
3 2
3
2
Bhuavana
Hi, I have a below log : INFO com.wu.channelservices.businesslogic.impl.ChannelServicesLogicImpl S:METHOD_NAME=Gwp...
by Bhuavana Explorer in Splunk Search 10-16-2014
0 2
0
2
a212830
Hi, I need to do a field extraction on a multi-line event. The values have quotes, and I'm having problems getting ...
by a212830 Champion in Splunk Search 10-15-2014
0 2
0
2
tayyujie
I am running pfSense in my environment. Currently, I am sending logs through UDP 50000, and my source type is pfsense...
by tayyujie Explorer in Splunk Search 10-15-2014
0 4
0
4
renems
I'm having a really hard time figuring this one out. How can I enrich my search results with an inputlookup? In this...
by renems Communicator in Splunk Search 10-15-2014
0 1
0
1
ludowillemans
How can I limit the available events in an app ? Search results in the app should only return events that also match...
by ludowillemans Explorer in Splunk Search 10-15-2014
0 2
0
2
sjanwity
How do I hide rows based on the number of rows returned in a transaction? (EDITED: removed all the contextual inform...
by sjanwity Communicator in Splunk Search 10-15-2014
1 3
1
3
yuanliu
In stats, values() can be used to enumerate values fitting the stats criteria. Is there a similar function to do thi...
by SplunkTrust SplunkTrust in Splunk Search 10-15-2014
0 1
0
1
OMohi
I would like to know how do I find the distribution of all Universal forwarders in Splunk by os type (Unix, Windows, ...
by OMohi Path Finder in Splunk Search 10-15-2014
0 4
0
4
kmasood
Hello, I have this query, which takes an ip address, returns FQDN and count columns: base search | `ip2fqdn(ip)` | ...
by kmasood Explorer in Splunk Search 10-15-2014
0 8
0
8
ttudor
I want to get a list of all the field names in an oracle.csv file. I generally do something like: "[inputlookup orac...
by ttudor Explorer in Splunk Search 10-15-2014
0 2
0
2
kkossery
Hi Experts, I'm getting below output in a PDF report from Splunk, 2014-10-10 09:58:27 EDT (Framework:INFO) [RID:52...
by kkossery Communicator in Splunk Search 10-15-2014
1 8
1
8
myahes
I need to tag certain field / value pairs with multiple tags. Is there a way to do this in bulk (i.e. upload a file ...
by myahes Explorer in Splunk Search 10-15-2014
0 1
0
1
giovere
Is there a way to have a bold red static line (for example y=100) in a line timechart?Is it possible to have two y ax...
by giovere Path Finder in Splunk Search 10-15-2014
0 3
0
3
kris99
unable to use where >= with timechart timechart max(value) AS la by User | eval la=round(la,2) | where la >=10
by kris99 New Member in Splunk Search 10-14-2014
0 4
0
4
Scarecrowddb
Hi All, I was wondering how you go about sending different criteria to the null que and whether the below would work...
by Scarecrowddb Explorer in Splunk Search 10-14-2014
2 3
2
3
arabii
Hi, I want to filter some events based on the occurence of multiple matchs, for instance, I want to match all (Windo...
by arabii Engager in Splunk Search 10-14-2014
1 3
1
3
liyiou
I searched the error events and use the "cluster" operator as below: error | cluster | table cluster_count _raw I...
by liyiou New Member in Splunk Search 10-14-2014
0 4
0
4
rpolanco
This is the search that I'm trying to do but it does not return anything. I'm trying to create a string variable and ...
by rpolanco New Member in Splunk Search 10-14-2014
0 6
0
6
ardave
If I have fields such as: _time = timestamphost = the host nameMessage = either "up" or "down" How do I group by th...
by ardave Explorer in Splunk Search 10-14-2014
1 2
1
2
Splunkster45
I have two types of logs in my files that record when a user logs in and logs out. They are of the form: Session <nu...
by Splunkster45 Communicator in Splunk Search 10-14-2014
0 1
0
1
ryastrebov
Hello Splunkers! My eventdata places on folders: /folder1/subfolder1/123/log1.log /folder1/subfolder1/234/log2.log ...
by ryastrebov Communicator in Splunk Search 10-14-2014
0 4
0
4
eichfuss
Hi community, propably a simple question, but I still hanging. I need a search over two logfiles, which shows me all...
by eichfuss Path Finder in Splunk Search 10-14-2014
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...