Splunk Search

Splunk Search
Community Activity
gajananh999
Dear all, I need your help to how to remove timestamp from this field. 2014-05-19T03:25:26.000-04:00 There is TO w...
by gajananh999 Contributor in Splunk Search 06-10-2014
0 4
0
4
shankern
Hi, I would like to get the following stats in a distributed index setup: index name, current size of index (sum all...
by shankern Explorer in Splunk Search 06-10-2014
0 3
0
3
frankharry
![alt text][1]I have log files with errors and warnings so my requirement is first events show only errors or warnin...
by frankharry New Member in Splunk Search 06-09-2014
0 1
0
1
rupesh30n
Hi, How can I retrieve nth word in a string using rex or other alternatives? For example: "ABC BBC XYZ QAS" "POP IM...
by rupesh30n Explorer in Splunk Search 06-09-2014
0 4
0
4
a212830
Hi, I just added a db lookup (via db connect), and when I try to use it via a search, I get a "lookup table does not...
by a212830 Champion in Splunk Search 06-09-2014
2 1
2
1
kingsizebk
The result from this search: index=_internal | eval something=case(kb!="0", "1") | stats sum(something) as sumST | st...
by kingsizebk Path Finder in Splunk Search 06-09-2014
0 6
0
6
chungmp
I am creating a dashboard for failed login, however, in the table created, there will be rows with all "" as values- ...
by chungmp New Member in Splunk Search 06-09-2014
0 1
0
1
rsathish47
Hi all, I have created custom search command. I need to add a custom search command to the list that search help pop...
by rsathish47 Contributor in Splunk Search 06-09-2014
0 3
0
3
wtian4
As the title says, after cleaning the event data and reindexing, the splunk search doesn't return events prior to the...
by wtian4 Engager in Splunk Search 06-09-2014
0 1
0
1
pisc
時間の計算を行い、各端末がどれぐらいの時間使用しているか調査したいと考えています。 このような例のログになります。 時間 , 端末名 , ステータス 2014/6/5 12:00:00 , PC01 , ログイン 2014/6...
by pisc Explorer in Splunk Search 06-08-2014
0 2
0
2
neiljpeterson
It is a very simple search for a string. (Account lock outs to be precise) and as worked in the past. But just recent...
by neiljpeterson Communicator in Splunk Search 06-06-2014
0 1
0
1
xvxt006
Hi we have some uri's as shown below which have 2 words (/verify/abrasives) before /ecatalog and 3 words and 4 words....
by xvxt006 Contributor in Splunk Search 06-06-2014
0 3
0
3
soundchaos
I am trying to find a search command that will get me a list of my top 20 client ip addresses (c_ip) along with each ...
by soundchaos Path Finder in Splunk Search 06-06-2014
0 3
0
3
ShaneNewman
I am getting this error on some data I am trying to push into a Teradata database: command="dboutput", Unexpected er...
by ShaneNewman Motivator in Splunk Search 06-06-2014
1 16
1
16
DFresh4130
We have some apache logs that I've added the %D (response time in microseconds) log config to at the very end. The s...
by DFresh4130 Path Finder in Splunk Search 06-06-2014
0 3
0
3
sanchitlohia
I have a splunk query like this index=main_branch* | table email_id file_size_in_bytes I want to count for simila...
by sanchitlohia Explorer in Splunk Search 06-06-2014
0 6
0
6
jtrucks
Is there a way to set a max size on the entire tsidxstats or even a single set of tsidxstats? I have the Splunk for ...
by jtrucks Splunk Employee Splunk Employee in Splunk Search 06-06-2014
3 2
3
2
HeinzWaescher
Hi, I've got some fieldvalues like this: field=aaaaaaaabbbbccccddddeeeeeeeeeeee I would like to add a "-" after c...
by HeinzWaescher Motivator in Splunk Search 06-06-2014
0 2
0
2
redc
I've set up a database lookup, but it's not returning any results; it should be returning 5 events. Here are the sce...
by redc Builder in Splunk Search 06-05-2014
0 2
0
2
mfrost8
A user has asked me if they can take a chart they just generated in Splunk and then send it to other users who don't ...
by mfrost8 Builder in Splunk Search 06-05-2014
2 8
2
8
Dimitri_McKay
Wondering if it's possible to embed a macro into another macro.
by Dimitri_McKay Splunk Employee Splunk Employee in Splunk Search 06-05-2014
0 2
0
2
Bliide
New Splunk user. I am creating web dashboards and I want to calculate the percentage of successful status codes. Th...
by Bliide Path Finder in Splunk Search 06-05-2014
0 2
0
2
mmouse88
I have a created a table using timechart with the max #. It generates a row of maximum of sourcetype. How would I r...
by mmouse88 Path Finder in Splunk Search 06-04-2014
0 16
0
16
the_wolverine
Is there a search that I can run at the indexer that will tell me what versions my forwarders are on?
by the_wolverine Champion in Splunk Search 06-04-2014
4 4
4
4
jheney
I have a single numeric field that I want to timechart in ranges...i.e. rangemap the field into custom buckets, then ...
by jheney New Member in Splunk Search 06-04-2014
0 1
0
1
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors