Splunk Search

Splunk Search
Community Activity
Benomran
I have a long search that is 4 rows, however the only dynamic portion is the first row. I would like to automatically...
by Benomran Explorer in Splunk Search 04-09-2014
1 10
1
10
dmlee
Hi , I saw this search command in "File Monitor Inputs" dashboard in SoS App this command can get some special inf...
by dmlee Communicator in Splunk Search 04-09-2014
1 1
1
1
hagjos43
I'm a noob to regex. I'm trying to extract the time-taken field from our IIS logs (this is the very last entry in the...
by hagjos43 Contributor in Splunk Search 04-09-2014
0 3
0
3
senthilgoa
I want to make empty cell in splunk table Name Time Day xxx 11.0 1 xxx 1 xxx 1 yyy 12.0 2 yy...
by senthilgoa Engager in Splunk Search 04-09-2014
0 3
0
3
sushma7
Hi, Please find the below XML file: 20140401-05:39:58 <![CDATA[Connection established]]> FTP 26875...
by sushma7 Path Finder in Splunk Search 04-09-2014
0 13
0
13
abhi144
I have a csv file in which two field are ShopNo and ShopId. From search i'm getting ShopNo and ShopIdinDevice so i wa...
by abhi144 New Member in Splunk Search 04-09-2014
0 1
0
1
frank_zhang
Hi, I have the following two sources: Source1: | Time | IP | MAC | | 08:01 | 10.0.1.1 | MAC1 | | 08:02...
by frank_zhang Path Finder in Splunk Search 04-09-2014
0 17
0
17
hadinh
Is web interface automatically installed with Splunk enterprise? Will it appear after installing and starting splunk ...
by hadinh Explorer in Splunk Search 04-08-2014
0 4
0
4
mamulani11
I have User_Id field in my log. In the user_Id field I have value like john,sonia,ces\ts1,...... Now when i am search...
by mamulani11 New Member in Splunk Search 04-08-2014
0 4
0
4
shri_27
Hi All, I have a field whose values look like value1>value2>value3!! Now i want to extract only value3 using rex! ...
by shri_27 Path Finder in Splunk Search 04-08-2014
0 12
0
12
snoobzilla
How do I get the last KER out of my lookup and get it into search below as LASTKER? I have a lookup table of error s...
by snoobzilla Builder in Splunk Search 04-08-2014
0 8
0
8
bkondakindi
Folks , we have case like as normal user from DBA not able to add his DB to external database on splunk side. as ...
by bkondakindi Path Finder in Splunk Search 04-08-2014
0 1
0
1
Jananee_iNautix
Hi , There are two fields named "start_time" and "end_time" extracted from logs and displayed in the format "03/...
by Jananee_iNautix Path Finder in Splunk Search 04-08-2014
0 2
0
2
ycalpu
I want to exclude the INFO log level in one of my searches. How would i do a "not" condition in the following: sour...
by ycalpu New Member in Splunk Search 04-08-2014
0 1
0
1
Ant1D
Hi, I have a field named hello_world and a value of the field is * I am writing a search where the results will not...
by Ant1D Motivator in Splunk Search 04-08-2014
0 7
0
7
duenguyen
Can I have indexer smart enough to go to dedicate index base on data value Here is my data "2013-12-02 20:30:30","a@...
by duenguyen Explorer in Splunk Search 04-08-2014
0 5
0
5
mrjester
I am consuming logs from my Vyatta firewall and I am having trouble getting the field extractor to reliably pull the ...
by mrjester Explorer in Splunk Search 04-07-2014
0 3
0
3
kaoriaraki
先週と今週の結果を比較するサーチを実行したいと考えています。 下記の例では曜日をキーにjoinして比較していますが、週の半ば(例えば水曜日)にサーチを実行すると水曜日までのグラフしか表示されません。 先週分は、日曜日から土曜日までの1...
by kaoriaraki Explorer in Splunk Search 04-07-2014
1 1
1
1
nikhilmehra79
As a quick check can some one suggest me if we have a 2 indexer envirornment with 2 search heads - does it make sense...
by nikhilmehra79 Path Finder in Splunk Search 04-07-2014
0 12
0
12
hbpatel142
Below Query Provides the Result. counter="% Processor Time" | chart avg(Value) over host by counter | search "% Proce...
by hbpatel142 Engager in Splunk Search 04-07-2014
1 1
1
1
j1nagar
Hello, I know i am doing something wrong but been going nowhere on this. Basically, have a maven project in eclipse ...
by j1nagar New Member in Splunk Search 04-07-2014
0 4
0
4
melonman
Hi I am looking for a search that iterates all my fieldname start with f* and get the statistics value of each f an...
by melonman Motivator in Splunk Search 04-07-2014
0 3
0
3
rsathish47
Hi , mvzip function takes two multivalue fields, I want to combine three multiple value.. Please let me if we have ...
by rsathish47 Contributor in Splunk Search 04-07-2014
3 2
3
2
jsmith39
I have a list of servers that do data backups to disk on a week night basis and I've built a query to display the res...
by jsmith39 Path Finder in Splunk Search 04-07-2014
0 3
0
3
SplunkUser5888
Hey guys, I'm trying to use regular expressions but can't get my head around it. I'm receiving lines such as: u'C:...
by SplunkUser5888 Path Finder in Splunk Search 04-07-2014
0 3
0
3
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors