Splunk Search

Splunk Search
Community Activity
Susannajuurinen
Hi! I have a small problem here.. I have two different sourcetypes named 'server' and 'metrics'. Server-sourcetype h...
by Susannajuurinen Explorer in Splunk Search 01-31-2014
0 3
0
3
theeven
Hi Folks, Here's what I have, index=blah | bucket span=1d _time | chart count(id) over _time by src Chart: _time...
by theeven Explorer in Splunk Search 01-31-2014
0 4
0
4
sanjay_shrestha
Hi, I created generic saved search and it is running fine individually as below |savedsearch PausedTime_SS index_na...
by sanjay_shrestha Contributor in Splunk Search 01-31-2014
1 1
1
1
daktapaal
Hi Guys, appendpipe [stats avg(*) as *], adds a new row with the average of all the rows of the respective column....
by daktapaal Path Finder in Splunk Search 01-31-2014
0 2
0
2
kramsay
I am having trouble trying to parse data from a raw event line. The raw event come in 2 different ways further below...
by kramsay Engager in Splunk Search 01-30-2014
0 4
0
4
Pierceyuk
So we spot checked a random time in splunk for a sourcetype(made up of 2 hosts sending in data). The data was missing...
by Pierceyuk Path Finder in Splunk Search 01-30-2014
0 4
0
4
petermuller
I'm currently trying to optimize my searches to keep my Splunk searches as quick as possible. Is there any appreciabl...
by petermuller Explorer in Splunk Search 01-30-2014
1 2
1
2
daktapaal
I have the following in my query index=_internal source=*license_usage.log | eval sizemb=b/1024/1024 timechart span...
by daktapaal Path Finder in Splunk Search 01-30-2014
0 7
0
7
lindsley
Hi, I have a search like this to return the number of times users have logged in over a week. source="mysource" "lo...
by lindsley Engager in Splunk Search 01-30-2014
0 2
0
2
duenguyen
I have issue with index field which contain comma. Below is my csv input "28650096","2013-12-02 20:30:30","blocked"...
by duenguyen Explorer in Splunk Search 01-30-2014
0 4
0
4
_gkollias
I have a search that tables project name, the group it belongs to, and the total count of deployment types: index=e...
by _gkollias Builder in Splunk Search 01-30-2014
0 2
0
2
dmlee
Hi, I have a BlueCoat Proxy log in main index if I run index="main" sourcetype="bcoat_proxysg" cn="*" | head 10 ...
by dmlee Communicator in Splunk Search 01-30-2014
0 6
0
6
OldManEd
To the powers that be, here is my dilemma. I have a simple query that reviews data in 15 minute blocks and prints ou...
by OldManEd Builder in Splunk Search 01-30-2014
0 7
0
7
vinay_ks04
I have three columns ColumnA ColumnB ColumnC vin 1 1 vin 1 2 vin ...
by vinay_ks04 New Member in Splunk Search 01-29-2014
0 6
0
6
daktapaal
Hi All, I have a lookup table that looks like: Key,value cat1,val1 cat2,val2 cat3,val3 this is in a lookup file c...
by daktapaal Path Finder in Splunk Search 01-29-2014
0 5
0
5
lukeh
Hi  I have a search that calculates the Bounce Rate for a web site: source="web" configuration.client.company=foo ...
by lukeh Contributor in Splunk Search 01-29-2014
1 5
1
5
Jananee_iNautix
A field called username has values INPUT: kesia@abc.bgf.hf:123 gefuf@ef.eff.gre:872 .I want to take the string bef...
by Jananee_iNautix Path Finder in Splunk Search 01-29-2014
0 5
0
5
splunkIT
We are currently looking at improving CPU optimization on the Splunk environment. We have found that the limits.conf ...
by splunkIT Splunk Employee Splunk Employee in Splunk Search 01-29-2014
2 5
2
5
wardallen
I'm collecting events from a logfile that look like this : 270929.542: [GC 270929.542: [ParNew Desired survivor size...
by wardallen Path Finder in Splunk Search 01-29-2014
0 8
0
8
_gkollias
I have a search that gives me the date and total number of projects: index=eis_continuous_integration sourcetype=eis...
by _gkollias Builder in Splunk Search 01-29-2014
0 5
0
5
tyronetv
I have an application sourcetype that is a mix of normal informational data and also houses a subset of web requests ...
by tyronetv Communicator in Splunk Search 01-29-2014
0 1
0
1
tyronetv
Within my event data I have a file name for a data set that we move around between services. Input files are sent ...
by tyronetv Communicator in Splunk Search 01-29-2014
0 11
0
11
tyronetv
When my users log into my system they are identified with a token number that follows all of their activity going for...
by tyronetv Communicator in Splunk Search 01-29-2014
0 3
0
3
jimjohn
I have a transaction table where insert and update will be happen on every time. I need to take a copy of the table o...
by jimjohn Path Finder in Splunk Search 01-29-2014
0 3
0
3
BertKraan
I count all my httpstatus'ses and get a neat result using: index=prd_access sourcetype="access:web:iis:project" | ch...
by BertKraan Engager in Splunk Search 01-29-2014
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...