Splunk Search

Splunk Search
Community Activity
justinfranks
I have a log of login timestamps. I would like to display the total count and total unique value count on the same ba...
by justinfranks Path Finder in Splunk Search 05-13-2014
0 5
0
5
dmacgillivray
I have an issue with data titles that would appear to be repeated, yet in the case below, The passwordexpiry_date: fi...
by dmacgillivray Communicator in Splunk Search 05-13-2014
0 11
0
11
Thuan
I run a search on a field that has multiple values. For example the field quest_name has the following values quest...
by Thuan Explorer in Splunk Search 05-13-2014
0 3
0
3
schose
Hi community, I've some kind of webserver log. i want to get the traffic per transaction.. so far I'm getting the wh...
by schose Builder in Splunk Search 05-13-2014
0 2
0
2
kavyatim
Hi , I have a 23 faults in XXXX city with X as latitude and Y as longitude, Now I want to plot fault count (23) on...
by kavyatim Path Finder in Splunk Search 05-13-2014
1 1
1
1
Jananee_iNautix
Hi, There is a requirement to group the events that startswith"String1" and endswith "String2" as a transaction OR g...
by Jananee_iNautix Path Finder in Splunk Search 05-13-2014
0 8
0
8
mikelanghorst
For this sample data: 172.21.174.78 - "/dc=com/dc=caiso/OU=people/CN=Bob User" [11/May/2012:11:27:40 -0700] "POST /AP...
by mikelanghorst Motivator in Splunk Search 05-12-2014
2 5
2
5
melonman
Hi I am using Hunk and I am looking for a way to get transaction (grouping events by userid with start transaction ...
by melonman Motivator in Splunk Search 05-12-2014
0 6
0
6
MichaelCohen829
Hello Splunk Community, I am trying to answer this question: How many users have logged into the system on at least...
by MichaelCohen829 Explorer in Splunk Search 05-12-2014
0 2
0
2
essklau
Hello, My question is whether or not I can, via sp, return a list of all fieldnames which contain a specified value...
by essklau Path Finder in Splunk Search 05-12-2014
0 1
0
1
hjwang
Dear all I know splunk can set this with dispatch.ttl=int<\p> in savedsearches.conf or ttl in alert_actions.conf, bu...
by hjwang Contributor in Splunk Search 05-12-2014
0 3
0
3
jedatt01
I have a requirement to route events to separate indexes based on two conditions. 1) must contain the string PI_EVENT...
by jedatt01 Builder in Splunk Search 05-12-2014
2 1
2
1
jdaivs
I am trying to compare the event count from each of my devices for the last 24 hours to the daily average of each dev...
by jdaivs Explorer in Splunk Search 05-12-2014
1 8
1
8
shangshin
Hi, My log event is in xml and the timestamp is in epoch format e.g. <timestamp>1399909145002</timestamp> How can ...
by shangshin Builder in Splunk Search 05-12-2014
0 6
0
6
davidpaper
Greetings, I've got a handful of API URLS, some with HTTP return status of 200, 201, and 500. I'm trying to come up...
by davidpaper Contributor in Splunk Search 05-12-2014
0 5
0
5
chengyu
Hi, my search: I'm try fast mode but status the same, My Splunk OS 5.04. Please help me, thanks. index="xxx" srcip...
by chengyu Path Finder in Splunk Search 05-12-2014
0 1
0
1
Mag2sub
In absence of device time zone and props setting ...and indexer in UTC ...what time zone is applied to events timesta...
by Mag2sub Path Finder in Splunk Search 05-11-2014
0 4
0
4
ppurokit
Hi All, I have the following search queries with me. index=XXX CISE_Failed_Attempts | timechart span=30m count by C...
by ppurokit Path Finder in Splunk Search 05-11-2014
0 4
0
4
nsaravan
Let us say I have 5 unique fields in my logs (var1 thru var5), I would like to first find the mean of the individual ...
by nsaravan New Member in Splunk Search 05-11-2014
0 5
0
5
johntopley
I have a custom log format that is Apache's access_combined format with a custom field representing an app's version ...
by johntopley Explorer in Splunk Search 05-10-2014
0 1
0
1
cgekoski
New to the splunk community and still learning the way of searches. In a nutshell i want to do a search against a cis...
by cgekoski Path Finder in Splunk Search 05-09-2014
0 2
0
2
mattcg
Is there a way to manually specify a lookup table for a search using a csv located on the server without making conf ...
by mattcg Explorer in Splunk Search 05-09-2014
1 5
1
5
jec013
I have 2 servers, Splunk1 and Splunk2, setup as search peers. How can I monitor when one of the servers goes down or...
by jec013 Explorer in Splunk Search 05-09-2014
0 2
0
2
MichaelCohen829
Hello Splunk Community I am trying to create a Search that will count the number of users who have a passed a certai...
by MichaelCohen829 Explorer in Splunk Search 05-09-2014
0 1
0
1
Mag2sub
We have a a scheduled query that returns certain search names ...how do we automate such that the scheduled query tha...
by Mag2sub Path Finder in Splunk Search 05-09-2014
0 6
0
6
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors