Splunk Search

Splunk Search
Community Activity
r999
How do i combine these stats commands? 1) | stats count by user host creates table: user host count 2) | s...
by r999 Path Finder in Splunk Search 02-04-2014
2 1
2
1
sdorich
So first I'm wondering what my error in the following search is: eventtype=sis_daily | join _time [search eventtype=...
by sdorich Communicator in Splunk Search 02-04-2014
0 2
0
2
aelliott
When upgrading from 1.1.0 to 1.1.1 DB Connect, I had to change all my fields from being written with capitalization t...
by aelliott Motivator in Splunk Search 02-03-2014
5 4
5
4
dfigurello
Hello Splunkers, I Have syslog log in my splunk index, for example: 2014-01-13 23:59:59 Local7.Error 172.16.80....
by dfigurello Communicator in Splunk Search 02-03-2014
0 2
0
2
kjonzeatgmaildo
I am sending events into Splunk using a tool that has a notification engine. The notification engine only allows me t...
by kjonzeatgmaildo New Member in Splunk Search 02-03-2014
0 6
0
6
harshal_chakran
Hi, I want to change the color of selected Splunk header tab. as it is very difficult to see the highlighted secti...
by harshal_chakran Builder in Splunk Search 02-03-2014
0 1
0
1
jsmith39
How would you search an application log for the absence of one or more specific events in a given time period? I'm l...
by jsmith39 Path Finder in Splunk Search 02-03-2014
0 6
0
6
echojacques
Hello, How can I get a trend of total events by sourcetype in a graph over a week? My indexing volume dropped signi...
by echojacques Builder in Splunk Search 02-03-2014
0 1
0
1
kmcconnell
All database connections quit working at the same time. I have checked the splunkd.log, dbx.log, and the jbridge.log...
by kmcconnell Path Finder in Splunk Search 02-03-2014
0 9
0
9
kavyatim
Hi , I have data in the following format: NOT_HOMOLOGATED-(UNKNOWN) HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6...
by kavyatim Path Finder in Splunk Search 02-03-2014
0 1
0
1
leon24
Hi all, I have a log file that briefly logs file in this pattern. For e.g. Available 12-01-2014 03:03:44 So if...
by leon24 Explorer in Splunk Search 02-02-2014
0 5
0
5
treyka
I have multiple indexes setup. Most user queries go to my default index however my users typically execute a search o...
by treyka Path Finder in Splunk Search 02-02-2014
0 3
0
3
iTechEvent
Here is a simplified version of my issue. I have csv file as below named Q.csv Q1avg, Q2avg100 , ...
by iTechEvent Explorer in Splunk Search 02-02-2014
0 2
0
2
iTechEvent
I have a query Q1 which is used to collect avg over 10 days.Say the average is AvgQ1 100. I have another query Q2 whi...
by iTechEvent Explorer in Splunk Search 02-02-2014
1 3
1
3
iTechEvent
| savedquery Q1 -> this runs okay | savedquery Q1 | savedquery Q2 -> not okay. splunk error. | savedquery Q1, Q2...
by iTechEvent Explorer in Splunk Search 02-01-2014
0 5
0
5
ramanjain1983
Hi Guys, I am trying to do this scenario where a subsearch is called to retrieve 2 fields using regex out of which o...
by ramanjain1983 Path Finder in Splunk Search 02-01-2014
1 4
1
4
V_at_Splunk
Are all these OK? * | STATS COUNT * | stats count * | STATS count * | stats COUNT Conclusion: search lang keywords...
by V_at_Splunk Splunk Employee Splunk Employee in Splunk Search 01-31-2014
5 7
5
7
tirusplunk
Hi Guys, I have a requirement like this. In a search I am getting a field like ExtraInfo Count User-...
by tirusplunk Engager in Splunk Search 01-31-2014
0 5
0
5
Susannajuurinen
Hi! I have a small problem here.. I have two different sourcetypes named 'server' and 'metrics'. Server-sourcetype h...
by Susannajuurinen Explorer in Splunk Search 01-31-2014
0 3
0
3
theeven
Hi Folks, Here's what I have, index=blah | bucket span=1d _time | chart count(id) over _time by src Chart: _time...
by theeven Explorer in Splunk Search 01-31-2014
0 4
0
4
sanjay_shrestha
Hi, I created generic saved search and it is running fine individually as below |savedsearch PausedTime_SS index_na...
by sanjay_shrestha Contributor in Splunk Search 01-31-2014
1 1
1
1
daktapaal
Hi Guys, appendpipe [stats avg(*) as *], adds a new row with the average of all the rows of the respective column....
by daktapaal Path Finder in Splunk Search 01-31-2014
0 2
0
2
kramsay
I am having trouble trying to parse data from a raw event line. The raw event come in 2 different ways further below...
by kramsay Engager in Splunk Search 01-30-2014
0 4
0
4
Pierceyuk
So we spot checked a random time in splunk for a sourcetype(made up of 2 hosts sending in data). The data was missing...
by Pierceyuk Path Finder in Splunk Search 01-30-2014
0 4
0
4
petermuller
I'm currently trying to optimize my searches to keep my Splunk searches as quick as possible. Is there any appreciabl...
by petermuller Explorer in Splunk Search 01-30-2014
1 2
1
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...