Splunk Search

Splunk Search
Community Activity
lbogle
Hey Splunkers, I have a search that is successfully returning search results as needed, however, I'd like to clean up...
by lbogle Contributor in Splunk Search 08-22-2014
1 2
1
2
pavan_bhumanapa
In our logs, we have the below two lines where we need to extract both empty & values for Dms_Code. Currently we are ...
by pavan_bhumanapa New Member in Splunk Search 08-22-2014
0 2
0
2
rmcole
Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everythi...
by rmcole New Member in Splunk Search 08-22-2014
0 3
0
3
dhavamanis
Can you please tell us, how to scrub remove events from Splunk indexed data (index="idx" and source="error_log"). We ...
by dhavamanis Builder in Splunk Search 08-22-2014
0 5
0
5
PhilAndreotti
Hi I have a large chunk of raw data from one of my servers and am trying to filter the data down using a multiple RE...
by PhilAndreotti Explorer in Splunk Search 08-22-2014
0 6
0
6
africates
Hi, When I try to search anything through either 'Search & Reporting' or 'Splunk App for Windows Infrastructure' I a...
by africates Explorer in Splunk Search 08-22-2014
0 1
0
1
dhavamanis
Can you please help us with the REGEX to extract "varnishnsca" from the log below during the indexing time to assign ...
by dhavamanis Builder in Splunk Search 08-22-2014
1 3
1
3
TBo123
Hello again, here is my search result: _timeID1ID21.1.093012211.1.09 3012211.1.09 3012721.1.09 3012821.1.09 3012921...
by TBo123 Path Finder in Splunk Search 08-22-2014
0 2
0
2
PhilAndreotti
Hi I am quite new to Splunk and REX. I am using the SNMP modular input app to poll one of my servers for multiple t...
by PhilAndreotti Explorer in Splunk Search 08-22-2014
0 6
0
6
mark_chuman
I have a search that will return the log entry below. The search is here: < "Authentication succeeded for user [*] ...
by mark_chuman Path Finder in Splunk Search 08-21-2014
0 5
0
5
Lucas_K
I noticed that one particular power user was taking up almost all the realtime searches on 2 of our search heads. The...
by Lucas_K Motivator in Splunk Search 08-21-2014
1 2
1
2
th1agarajan
I need the item name and no of items sold based on max(itemSold) per hour TimeItemNo Of ItemsSold5:02xxx55:05yyy255:...
by th1agarajan Path Finder in Splunk Search 08-21-2014
0 1
0
1
lmartha
We are using Splunk 6.0 version and trying to add drilldown to column chart to display table. I searched examples rel...
by lmartha Explorer in Splunk Search 08-21-2014
1 5
1
5
joshuamcqueen
Stumped on a regex problem and need a hand. Basically, I have DNS logs that come in like this: 8/21/2014 9:32:20 AM...
by joshuamcqueen Path Finder in Splunk Search 08-21-2014
0 2
0
2
alexl1
hi, I want to create a search that shows results whenever a particular field doesn't exist. I tried isnull but it did...
by alexl1 Path Finder in Splunk Search 08-21-2014
0 2
0
2
rfujara_splunk
I'm the developer of the R Project app and currently working on issue #13. When executing this... index=_internal |...
by rfujara_splunk Splunk Employee Splunk Employee in Splunk Search 08-21-2014
0 1
0
1
cantgetnosleep
How does splunk handle transactions that span search time boundaries? If a transaction starts before a search interva...
by cantgetnosleep Explorer in Splunk Search 08-21-2014
1 5
1
5
fgysin
So, our application logs duration times of logged method calls as ..dT=XXXms.. and I would like to use this for nice ...
by fgysin Explorer in Splunk Search 08-21-2014
0 7
0
7
robertlabrie
I've written a lookup app called TA-browscap_lookup_express. It needs to write data out to a CSV to be re-used on fut...
by robertlabrie Path Finder in Splunk Search 08-21-2014
0 3
0
3
0range
Hello! How can I, for example, eval min(_time) an mvcombine ip for event grouped by two or three other fields? Thank...
by 0range Communicator in Splunk Search 08-21-2014
0 1
0
1
mjones414
index=_internal per_sourcetype_thruput series!=splunkd | eval gb=kb/1024/1024 | timechart span=1d useother=f sum(gb) ...
by mjones414 Contributor in Splunk Search 08-21-2014
0 1
0
1
sudotliu
I know there is a syntax difference between: sourcetype=blah | chart count over foo by bar and sourcetype=blah | char...
by sudotliu Explorer in Splunk Search 08-20-2014
4 6
4
6
ulikabbq
I am trying to turn my columns into rows and I have not had any luck with the xyseries command. Here is my search: ...
by ulikabbq Path Finder in Splunk Search 08-20-2014
1 4
1
4
agoebel
I was trying to create a tag/eventtype/equivilent for a message length checksum in our logfiles and it seems eventtyp...
by agoebel Path Finder in Splunk Search 08-20-2014
0 10
0
10
_gkollias
Hi All, Is there a way to rename the Search button say for a text form input in Splunk 6? Would I use a .css styles...
by _gkollias Builder in Splunk Search 08-20-2014
1 4
1
4
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors