Splunk Search

Splunk Search
Community Activity
chrismok
Hi, I have some logs that look like the sample below. If I use .net or java or SQL, I can solve it, but I really don...
by chrismok Path Finder in Splunk Search 09-18-2014
1 3
1
3
ewanbrown
In my source data I have an array of several values, only one of which is of interest. My sample search string is: i...
by ewanbrown Path Finder in Splunk Search 09-18-2014
1 2
1
2
esflavio
In my situation I have "Web Requests" events, which I group in transactions with the following search: sourcetype="W...
by esflavio New Member in Splunk Search 09-18-2014
0 3
0
3
DonDandrea
I have a data source I am trying to ingest into Splunk. It is a txt file that is written to by multiple systems. My p...
by DonDandrea Path Finder in Splunk Search 09-18-2014
0 2
0
2
karthikTIL
HI,I have two fields A and B with time format as 1/07/2014 3:41:12 PM. e.g., if A is 1/07/2014 3:41:12 PM and B is 1...
by karthikTIL Path Finder in Splunk Search 09-18-2014
1 8
1
8
karthikTIL
HI, I have source file test.csv which has words like "abc-234 " , "456", "df 654", "er567 -ly". In all the ...
by karthikTIL Path Finder in Splunk Search 09-17-2014
1 5
1
5
Darksynergy
I am trying to run a search that shows executibles that are run by any user on my network. Yet I want to exclude the ...
by Darksynergy Explorer in Splunk Search 09-17-2014
0 11
0
11
drmed
We occasionally have infrastructure outages that result in a higher number of timeouts during the outage period. Woul...
by drmed Explorer in Splunk Search 09-17-2014
1 2
1
2
PrinceOfEval
I'm trying to pull a bunch of logs, group them by user account, and then compare aspects of IP addresses involved per...
by PrinceOfEval Path Finder in Splunk Search 09-17-2014
0 4
0
4
Splunkster45
This is my first time using splunk and I have 2 questions. First of all, say I have when I enter a certain search (" ...
by Splunkster45 Communicator in Splunk Search 09-17-2014
1 1
1
1
jlawsonmers
In trying to learn how to exclude a subnet from a search using CIDR notation, I was directed to this link: http://ans...
by jlawsonmers New Member in Splunk Search 09-17-2014
0 7
0
7
kmcconnell
I have a regex question that I hope will be easy for someone. I’m not big on regexes so I’m coming to you all for he...
by kmcconnell Path Finder in Splunk Search 09-17-2014
1 5
1
5
ebdavis333
The search string I am currently using is the following: | metadata type=hosts |where recentTime < now() - 86400 | e...
by ebdavis333 New Member in Splunk Search 09-17-2014
0 3
0
3
andreacorrie
I am trying to get a percentage of failures per day using timechart and eval but keep getting the error: Error in 't...
by andreacorrie Explorer in Splunk Search 09-17-2014
1 6
1
6
splunker12er
I have a lookup table blacklist.csv , which has blacklisted src & dest IPs. Using the below search query , I am listi...
by splunker12er Motivator in Splunk Search 09-17-2014
0 4
0
4
splunkn
Im having users list in lookup file, and using the index and sourcetype I can extract one set of users. The requireme...
by splunkn Communicator in Splunk Search 09-17-2014
0 4
0
4
rhoska
In 4.2.1 build 98164 I'm using the Interactive Field Extractor and the Generated pattern automatically generates an e...
by rhoska Engager in Splunk Search 09-17-2014
5 2
5
2
karthikTIL
HI, I have two files, test1.csv and test2.csv. I want to do some arithmetic calculation involving fields from both f...
by karthikTIL Path Finder in Splunk Search 09-17-2014
0 3
0
3
matt4321
Using the below search works when I only specify a single ifName. host=ohtwbgitxsg10 ifName=1/1 | sort _time | delta...
by matt4321 Explorer in Splunk Search 09-17-2014
0 3
0
3
przemol
Hello, our security officer asked me to deploy splunk forwarder on several hosts. I wanted to use puppet for that ta...
by przemol New Member in Splunk Search 09-16-2014
0 2
0
2
jonarnes
Hi. I am trying to understand how I can list new referrers (hostnames) : rex field=headers.Referer "^https?://(ww...
by jonarnes Engager in Splunk Search 09-16-2014
0 3
0
3
felix_fxm
After query MySQL data base in DB connect, the date is number, how to make it as "YYYY-MM-DD HH-MM-SS"?
by felix_fxm Engager in Splunk Search 09-16-2014
1 4
1
4
thisissplunk
This is the question I need to answer with Splunk: "How can I determine when different unique events with alert="ONE...
by thisissplunk Builder in Splunk Search 09-16-2014
0 9
0
9
hulahoop
This question originates from suggestions from this thread: Is it possible to preserve original order of events? It ...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 09-16-2014
3 5
3
5
csepulveda
Hi guys, we have a problem when we try to use timecharts that involve dates having in between a daylight saving time ...
by csepulveda New Member in Splunk Search 09-16-2014
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...