Splunk Search

Splunk Search
Community Activity
zliu
Below is the transforms.conf at $SPLUNK_HOME/etc/local: [test_lookup] filename=test.csv And I uploaded test.csv (a...
by zliu Splunk Employee Splunk Employee in Splunk Search 07-29-2014
5 2
5
2
dreamwork801
I want my users to be able to chose a file extension from a drop down that is populated with a search. I was thinking...
by dreamwork801 Path Finder in Splunk Search 07-29-2014
1 5
1
5
sethuk555
Hi, I need to find the transaction time between these 2 statements which has same startswith Log strings(different e...
by sethuk555 Engager in Splunk Search 07-29-2014
0 1
0
1
lbogle
Hello Splunkers, I'm processing results of an asset database search. I have one database that is the 'reference' data...
by lbogle Contributor in Splunk Search 07-29-2014
0 5
0
5
jlkokko
What is the proper command/syntax to specify a day of the week for searching (converting date/timestamp)? example: i...
by jlkokko Path Finder in Splunk Search 07-29-2014
1 7
1
7
EricLloyd79
I am feeling more and more like the new Pivot UI functionality is way too limiting. Can anyone help me to do a query ...
by EricLloyd79 Builder in Splunk Search 07-29-2014
0 2
0
2
edookati
I am using the below query to join 2 searches, but the table is showing me duplicate rows with only common_fields and...
by edookati Path Finder in Splunk Search 07-28-2014
1 4
1
4
lbogle
Hello Splunkers, I feel like I have the most basic of questions here but I can't get it to work. I have a .csv log fi...
by lbogle Contributor in Splunk Search 07-28-2014
1 2
1
2
dabunn
I have sendmail logs which have an action field which can be DELIVER, DROP or QUARANTINE. What I am trying to do is ...
by dabunn Engager in Splunk Search 07-28-2014
1 3
1
3
dlespron
I know I must be missing something simple and have searched here trying multiple things but still can't get this to w...
by dlespron Path Finder in Splunk Search 07-28-2014
1 1
1
1
Thuan
I am trying to feed Arcsight with the results of a Splunk search using the real time output app. I get the following...
by Thuan Explorer in Splunk Search 07-28-2014
0 1
0
1
ezajac
How can I create a field extraction to modify a key in a key value pair? I have a new file that I am indexing. The ke...
by ezajac Path Finder in Splunk Search 07-28-2014
0 3
0
3
JoeSco27
I am working in a single node environment (indexer is also deployment-server)and I am having trouble determining why ...
by JoeSco27 Communicator in Splunk Search 07-28-2014
0 3
0
3
LordVoldemort
This issue continually bites me and there's something I'm just not understanding. If I search like so: sourcetype=...
by LordVoldemort Explorer in Splunk Search 07-28-2014
0 5
0
5
TBo123
Hello, I hope there is someone who can help me solve this problem. I'd like to know how to group events shown as fo...
by TBo123 Path Finder in Splunk Search 07-28-2014
1 2
1
2
shangshin
Hi, I get the user_id info from web log and would like to enrich data from the connected DB in Splunk. I tried the...
by shangshin Builder in Splunk Search 07-28-2014
1 5
1
5
Bhuavana
Hi, Could you please let me know how to set chart title dynamically without using Sideviewutils.
by Bhuavana Explorer in Splunk Search 07-28-2014
0 10
0
10
pierra56
I'm blocking. I would like to appear in the form of a graph or table, the number of bytes that my top 5 IP addresses...
by pierra56 Explorer in Splunk Search 07-28-2014
1 4
1
4
mvaradarajam
Hi All, How to use index="*"|timechart count by sourcetype,source
by mvaradarajam Path Finder in Splunk Search 07-28-2014
0 2
0
2
C_Sparn
Hello I'm looking for a possibility to add 5 seconds to a time value that is in strftime format. The crt eval is an e...
by C_Sparn Communicator in Splunk Search 07-28-2014
0 2
0
2
simontam
I am quite new to Splunk search query. I have collected traffic logs from paloalto firewall. I want to have the Top 1...
by simontam Explorer in Splunk Search 07-28-2014
0 7
0
7
karthik4455
I appended 2 searches and each of them has "top Engineer" and now my result is like this. Engineer Escalated Cl...
by karthik4455 Explorer in Splunk Search 07-27-2014
2 2
2
2
atanasmitev
Hi, I am trying to compress/optimize a search, spanning multiple lines, see below (obfuscated, but logically the sam...
by atanasmitev Path Finder in Splunk Search 07-27-2014
1 3
1
3
atanasmitev
Hello all, I am trying to search for distinct count higher than a value. Below is what I tried, obfuscated : stats...
by atanasmitev Path Finder in Splunk Search 07-27-2014
1 2
1
2
xvxt006
Hi, i have a dashboard and i want to get data for each environment. For example QA/Prod, etc. So i want to have a d...
by xvxt006 Contributor in Splunk Search 07-25-2014
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors