Splunk Search

Splunk Search
Community Activity
juancarlos_pola
Hello, I am quite new using Splunk and I have a question, that might be already be solved before, but I just want to ...
by juancarlos_pola Explorer in Splunk Search 09-30-2014
0 3
0
3
mcm10285
I have a search with one subsearch, that looks like this. sourcetype=sourcetype1 <search string> [search sourcetype=...
by mcm10285 Communicator in Splunk Search 09-29-2014
0 2
0
2
kris99
how do i use range to display green tick or red cross for the following index=xx sourcetype="yyy" State!="On" If '...
by kris99 New Member in Splunk Search 09-29-2014
0 7
0
7
nickbyrne
We have enterprise data which we are querying and running through some 'hypothetical' business situations. So, ideall...
by nickbyrne New Member in Splunk Search 09-29-2014
0 1
0
1
vspreethi17
I am trying to calculate the average number of errors by calculating events(with error)/total events. Here is my que...
by vspreethi17 Explorer in Splunk Search 09-29-2014
1 4
1
4
cdupuis123
Trying to dump off what seems like a simple thing to do from raw iis logs. just want to not allow this to index: cs_...
by cdupuis123 Path Finder in Splunk Search 09-29-2014
1 5
1
5
sadkha
I have a set of logs which wasn't automatically parsed when indexed into Splunk. I would like to extract a field fr...
by sadkha Path Finder in Splunk Search 09-29-2014
1 1
1
1
vikas_gopal
Hi Experts, I am configuring a dynamic ldap group with splunk .Group employee has more than 50,000 users. when I am ...
by vikas_gopal Builder in Splunk Search 09-29-2014
1 1
1
1
jonzhong
Hi I manage to load my directory into splunk. Its a directory of multiple single line .txt file. Splunk is able to r...
by jonzhong New Member in Splunk Search 09-29-2014
0 3
0
3
malat_UoM
Hi, folks, I'm building an alert to detect anomalous logons, intending to use the following (simplified) logic, Sea...
by malat_UoM Explorer in Splunk Search 09-29-2014
1 2
1
2
nirmah
Hi all Splunkers! So transactions. I have 3 eventtypes, lets call them et-A, et-B and et-C and I want to find all Tr...
by nirmah Explorer in Splunk Search 09-28-2014
0 1
0
1
larsxschneider
My events have the following structure: id=[id] key=[key] value=[value] For example: id=1 key=mycounter value=4 id=1...
by larsxschneider Explorer in Splunk Search 09-28-2014
0 3
0
3
reedmohn
In users' /search/history folder there is a file named .csv (I guess that could be , as they are the same here) In t...
by reedmohn Communicator in Splunk Search 09-28-2014
7 1
7
1
april_tao
For below search : eventtype=MYTYPE [search eventtype=MYTYPE | sort 0 _time desc | dedup fieldX | return 1000 sourc...
by april_tao New Member in Splunk Search 09-27-2014
0 1
0
1
newbiesplunk
Hi, I had the following sentence and wish to extract fields as follows: event Row: 1234, tp1, 314242, 1, 2014-0...
by newbiesplunk Path Finder in Splunk Search 09-27-2014
0 2
0
2
keerthana_k
Hi I have a timechart which plots a stacked area chart of multiple series. I want to omit the null values. I tried s...
by keerthana_k Communicator in Splunk Search 09-26-2014
0 3
0
3
I-Man
While running splunk diag on an indexer, i received the following error messages. Any idea's as to what they mean or ...
by I-Man Communicator in Splunk Search 09-26-2014
0 5
0
5
siraj198204
Hi , Similarly , source="dbmo-tail://idware/id_account" application=TFD [|inputlookup execSSO.csv |rename sso as ow...
by siraj198204 Explorer in Splunk Search 09-26-2014
0 9
0
9
ljfantin
Hi Guys, I updated from BugSense to Splunk and I saw this in my log [SPLJSONModel.m:256] Incoming data was invalid [...
by ljfantin Engager in Splunk Search 09-26-2014
1 3
1
3
leatherface
I can add an absolute row number to my search results with streamstats count as row However, I would like the ro...
by leatherface Explorer in Splunk Search 09-26-2014
2 4
2
4
gsteff
Can anyone confirm that custom event renderers still work as documented in Splunk 6? I've tried going through the CSS...
by gsteff Explorer in Splunk Search 09-26-2014
3 2
3
2
alemarzu
Hi there fellas, I'm having troubles trying to chart eventless days when they are the first events to plot in a chr...
by alemarzu Motivator in Splunk Search 09-26-2014
0 6
0
6
VABarn
Hello gurus! Would you please help with this problem? I have one index (main) and two sources (hostInfo and smRelat...
by VABarn New Member in Splunk Search 09-26-2014
0 3
0
3
linu1988
Hello, I am having trouble converting to Hour:Minute:Second format from epoch time First i have made a subtraction w...
by linu1988 Champion in Splunk Search 09-26-2014
0 8
0
8
RVDowning
I have the following line: timechart span=1d sum(TypeAErrors) , sum(TypeBErrors), dc(racf) as "Unique Ids" but the...
by RVDowning Contributor in Splunk Search 09-26-2014
1 8
1
8
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...