Splunk Search

Splunk Search
Community Activity
ruiaires
I have an automatic lookup that works ok but when I try to filter results by selecting a field that comes from the lo...
by ruiaires Path Finder in Splunk Search 09-12-2014
1 2
1
2
gartnerj
Folks, I have the following REGEX: (?:[^:\n]*:){4}\d+\.\d+\w+,(?P<ComponentName>[^,]+),(?P<EventCode>[^,]+),(?P<Mess...
by gartnerj Explorer in Splunk Search 09-12-2014
1 8
1
8
realajay89
source=XXXXX | lookup customer_journey.csv "Page Name" as "Page Name" output "Customer Journey Name" as Transaction "...
by realajay89 Explorer in Splunk Search 09-12-2014
1 13
1
13
pedromvieira
Can I INSERT or UPDATE a table from a search in Splunk with DB Connect?
by pedromvieira Communicator in Splunk Search 09-11-2014
0 1
0
1
a212830
Hi, I want to look at the format for a number of hosts that are using the same sourcetype (I suspect that the format...
by a212830 Champion in Splunk Search 09-11-2014
0 6
0
6
Noorzaie
Is there a way to pass parameter to a saved search from an ODBC connection in Excel? (since only saved searches can ...
by Noorzaie Explorer in Splunk Search 09-11-2014
0 3
0
3
gudavasr
Hi, I have these entries in the log. I am trying to extract fields FINISHED and ERROR_RUNNING for this. But I am abl...
by gudavasr Path Finder in Splunk Search 09-11-2014
0 7
0
7
ben_leung
I have a tabled results of _time. Each one is an event and I want to find a difference for each event and have the va...
by ben_leung Builder in Splunk Search 09-11-2014
1 3
1
3
vtsguerrero
Hello! Can anyone please help me with this Search-String? I have an Epoch Data inside my query like this: **index=m...
by vtsguerrero Contributor in Splunk Search 09-11-2014
0 3
0
3
tcalhoon
I am in need of a search that will display the number of Distinct users by index over the past 3 months. I have creat...
by tcalhoon Explorer in Splunk Search 09-11-2014
0 3
0
3
manus
I know how to get the week day from raw events, the week day is stored in the field date_wday. However, I wonder if t...
by manus Communicator in Splunk Search 09-11-2014
2 2
2
2
lbogle
I have the main search returning results appropriately in the "Events" tab however, visualization returns incorrect g...
by lbogle Contributor in Splunk Search 09-10-2014
0 2
0
2
DaveAsh
I am using timewrap to return week over week results. I need to be able to change the order of comparison from week1,...
by DaveAsh Engager in Splunk Search 09-10-2014
0 3
0
3
rroberts
Is this still a possibility with Splunk 6.0 and higher? "The search process can't parse the search string. In the se...
by rroberts Splunk Employee Splunk Employee in Splunk Search 09-10-2014
2 3
2
3
kmattern
Is there a limit to the number of eval functions that can be used in a single search? It appears that using more than...
by kmattern Builder in Splunk Search 09-10-2014
0 7
0
7
splunkingsplun1
I am receiving the following message in Splunk 6.01 "Minimum free disk space reached (5000MB) for /opt/splunk/var/run...
by splunkingsplun1 Explorer in Splunk Search 09-10-2014
1 4
1
4
dcasey
Looking for a simple approach to combine two fields into one. Ref: ES / Audit / Incident Review Audit There is no r...
by dcasey Engager in Splunk Search 09-10-2014
0 4
0
4
manus
I tried to join a search and subsearch on _time with the join command, but this failed, even though the resulting tim...
by manus Communicator in Splunk Search 09-10-2014
1 4
1
4
ashnet16
I'm trying to display bounce rate as a single value percent. Does anyone have any idea on how I can do it? As of of,...
by ashnet16 Path Finder in Splunk Search 09-10-2014
0 1
0
1
ewanbrown
I have a query similar to index=beacon BeaconType=pageview | timechart span="1d" count by Country giving ...
by ewanbrown Path Finder in Splunk Search 09-10-2014
0 2
0
2
Mubarish
I have created source stanza and tried to extract fields within the source. The path of the source is : C:\Users\xb...
by Mubarish Path Finder in Splunk Search 09-10-2014
1 5
1
5
benoitleroux
Using Hunk with simple search like index=myindex retreives all the expected results. But as soon as I add something ...
by benoitleroux Explorer in Splunk Search 09-10-2014
0 5
0
5
karthik4455
Escalated_Tickets Resolved_Tickets 4334 3453 5545 8438 7565 8948 8877 4675 9868 4334 3453 ...
by karthik4455 Explorer in Splunk Search 09-10-2014
0 4
0
4
echojacques
Is there a way to format the "_time" field? I currently use _time in many of my dashboards and searches; however, it...
by echojacques Builder in Splunk Search 09-10-2014
4 3
4
3
jftasis
Hi All, I have a list of known application error strings which I wanted to count. I've created a csv file containin...
by jftasis New Member in Splunk Search 09-10-2014
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...