| How do i combine these stats commands? 1) | stats count by user host creates table: user host count 2) | s... by r999 Path Finder in Splunk Search 02-04-2014 2 1 | 2 | 1 | ||
| So first I'm wondering what my error in the following search is: eventtype=sis_daily | join _time [search eventtype=... by sdorich Communicator in Splunk Search 02-04-2014 0 2 | 0 | 2 | ||
| When upgrading from 1.1.0 to 1.1.1 DB Connect, I had to change all my fields from being written with capitalization t... by aelliott Motivator in Splunk Search 02-03-2014 5 4 | 5 | 4 | ||
| Hello Splunkers, I Have syslog log in my splunk index, for example: 2014-01-13 23:59:59 Local7.Error 172.16.80.... by dfigurello Communicator in Splunk Search 02-03-2014 0 2 | 0 | 2 | ||
| I am sending events into Splunk using a tool that has a notification engine. The notification engine only allows me t... by kjonzeatgmaildo New Member in Splunk Search 02-03-2014 0 6 | 0 | 6 | ||
| Hi, I want to change the color of selected Splunk header tab. as it is very difficult to see the highlighted secti... by harshal_chakran Builder in Splunk Search 02-03-2014 0 1 | 0 | 1 | ||
| How would you search an application log for the absence of one or more specific events in a given time period? I'm l... by jsmith39 Path Finder in Splunk Search 02-03-2014 0 6 | 0 | 6 | ||
| Hello, How can I get a trend of total events by sourcetype in a graph over a week? My indexing volume dropped signi... by echojacques Builder in Splunk Search 02-03-2014 0 1 | 0 | 1 | ||
| All database connections quit working at the same time. I have checked the splunkd.log, dbx.log, and the jbridge.log... by kmcconnell Path Finder in Splunk Search 02-03-2014 0 9 | 0 | 9 | ||
| Hi , I have data in the following format: NOT_HOMOLOGATED-(UNKNOWN) HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6... by kavyatim Path Finder in Splunk Search 02-03-2014 0 1 | 0 | 1 | ||
| Hi all, I have a log file that briefly logs file in this pattern. For e.g. Available 12-01-2014 03:03:44 So if... by leon24 Explorer in Splunk Search 02-02-2014 0 5 | 0 | 5 | ||
| I have multiple indexes setup. Most user queries go to my default index however my users typically execute a search o... by treyka Path Finder in Splunk Search 02-02-2014 0 3 | 0 | 3 | ||
| Here is a simplified version of my issue. I have csv file as below named Q.csv Q1avg, Q2avg100 , ... by iTechEvent Explorer in Splunk Search 02-02-2014 0 2 | 0 | 2 | ||
| I have a query Q1 which is used to collect avg over 10 days.Say the average is AvgQ1 100. I have another query Q2 whi... by iTechEvent Explorer in Splunk Search 02-02-2014 1 3 | 1 | 3 | ||
| | savedquery Q1 -> this runs okay | savedquery Q1 | savedquery Q2 -> not okay. splunk error. | savedquery Q1, Q2... by iTechEvent Explorer in Splunk Search 02-01-2014 0 5 | 0 | 5 | ||
| Hi Guys, I am trying to do this scenario where a subsearch is called to retrieve 2 fields using regex out of which o... by ramanjain1983 Path Finder in Splunk Search 02-01-2014 1 4 | 1 | 4 | ||
| Are all these OK? * | STATS COUNT * | stats count * | STATS count * | stats COUNT Conclusion: search lang keywords... by V_at_Splunk Splunk Employee 5 7 | 5 | 7 | ||
| Hi Guys, I have a requirement like this. In a search I am getting a field like ExtraInfo Count User-... by tirusplunk Engager in Splunk Search 01-31-2014 0 5 | 0 | 5 | ||
| Hi! I have a small problem here.. I have two different sourcetypes named 'server' and 'metrics'. Server-sourcetype h... by Susannajuurinen Explorer in Splunk Search 01-31-2014 0 3 | 0 | 3 | ||
| Hi Folks, Here's what I have, index=blah | bucket span=1d _time | chart count(id) over _time by src Chart: _time... by theeven Explorer in Splunk Search 01-31-2014 0 4 | 0 | 4 | ||
| Hi, I created generic saved search and it is running fine individually as below |savedsearch PausedTime_SS index_na... by sanjay_shrestha Contributor in Splunk Search 01-31-2014 1 1 | 1 | 1 | ||
| Hi Guys, appendpipe [stats avg(*) as *], adds a new row with the average of all the rows of the respective column.... by daktapaal Path Finder in Splunk Search 01-31-2014 0 2 | 0 | 2 | ||
| I am having trouble trying to parse data from a raw event line. The raw event come in 2 different ways further below... by kramsay Engager in Splunk Search 01-30-2014 0 4 | 0 | 4 | ||
| So we spot checked a random time in splunk for a sourcetype(made up of 2 hosts sending in data). The data was missing... by Pierceyuk Path Finder in Splunk Search 01-30-2014 0 4 | 0 | 4 | ||
| I'm currently trying to optimize my searches to keep my Splunk searches as quick as possible. Is there any appreciabl... by petermuller Explorer in Splunk Search 01-30-2014 1 2 | 1 | 2 |