Splunk Search

Splunk Search
Community Activity
nikhilagrawal
We have recently upgraded the Splunk SearchHead and Indexer to Splunk V6. Since afternoon we are facing below error a...
by nikhilagrawal Path Finder in Splunk Search 01-17-2014
0 2
0
2
wye054
Hi , i am using this query to get the daily transaction for every hour for a day. sourcetype="*Leg324.log" tid|rex...
by wye054 New Member in Splunk Search 01-17-2014
0 1
0
1
ykmohank
Hi, From Splunk web interface a saved search is returning around 300,000+ events. While calling the same saved searc...
by ykmohank New Member in Splunk Search 01-17-2014
0 2
0
2
Jananee_iNautix
Hi, There's a problem in displaying abbreivated month and year when using the below search query source="RSBA_LOGS2"...
by Jananee_iNautix Path Finder in Splunk Search 01-17-2014
0 13
0
13
HeinzWaescher
Hi, in my event the field Amount can appear several times. The value is an amount of products. Sometimes Splunk iden...
by HeinzWaescher Motivator in Splunk Search 01-17-2014
1 8
1
8
jaj
source= "KeyOfThis" | table theRawValue, _time | chart values(theRawValue) by _time So, when I run this query there ...
by jaj Path Finder in Splunk Search 01-17-2014
0 1
0
1
Jananee_iNautix
I have log statement as follows as 1.20131220.server-0.log:2013-12-20 09:38:00,852 [fewfg424] SUCCESS: The FTP S...
by Jananee_iNautix Path Finder in Splunk Search 01-16-2014
0 6
0
6
juriggs
Hi, I have to calculate duration in milliseconds which is working, but when I add file size data to the query, the d...
by juriggs Path Finder in Splunk Search 01-16-2014
0 4
0
4
dcollette
Is it possible to have splunk parse the following date format? Year-Day-Hour_minute_Second i.e. 2008-265-03:19:26 wo...
by dcollette New Member in Splunk Search 01-16-2014
0 5
0
5
bsizemore
Our custom apps' dashboard panels graphs and "open in search" lead to 404s. Dashboard + several panels http://splunk...
by bsizemore Path Finder in Splunk Search 01-16-2014
0 1
0
1
splunek
Hi. I'm a splunk newbie and I am trying to construct a query over multiple sources that will do a sum of points over ...
by splunek Engager in Splunk Search 01-16-2014
0 8
0
8
fk319
I am using "bucket span=log1.1 Time" but it puts it bucket ranges, 1-1.1, 1.1-1.2, etc. so I tried to use log(Time,1...
by fk319 Builder in Splunk Search 01-16-2014
0 2
0
2
kluey
Hi, I have syslogs that I would like to search for by ZONE (UNTRUST) and IP (12.12.12.1). Below is a sample of how ...
by kluey Explorer in Splunk Search 01-16-2014
0 4
0
4
HeinzWaescher
Hi, in one single event, the field amount appears multiple times. What I need is a new field that includes the total...
by HeinzWaescher Motivator in Splunk Search 01-16-2014
0 6
0
6
HeinzWaescher
Hi, I want to configure some field aliases. I want to add an alias C for the fields A & B. I've done this in the se...
by HeinzWaescher Motivator in Splunk Search 01-16-2014
0 14
0
14
vijai_thomas
Hi, I want to count the number or errors within two keywords say starttran and endtran. My log data would be like s...
by vijai_thomas Engager in Splunk Search 01-15-2014
0 2
0
2
changwoo
i am trying to search by year i have a field like movie_year ( ex: 1991, 1999, 2000) and i want make a dashboard wh...
by changwoo Communicator in Splunk Search 01-15-2014
0 3
0
3
Jananee_iNautix
I have to do something like according to the extension of the filename that i extract from logs i want to flag them. ...
by Jananee_iNautix Path Finder in Splunk Search 01-15-2014
0 4
0
4
dlespron
For instance, I have a search where I want to query for a value that would set that value to orderid such as: source...
by dlespron Path Finder in Splunk Search 01-15-2014
0 2
0
2
appleman
Hello there, I just wonder if I can divide an index into two indexes. e.g, Divide the data in index=main to index=pr...
by appleman Contributor in Splunk Search 01-15-2014
2 6
2
6
RMartinezDTV
Hi, I have a search where I'm attempting to use a lookup table and the top command in the same search. The search is...
by RMartinezDTV Path Finder in Splunk Search 01-15-2014
0 2
0
2
gmhp
Is there a search that will warn me of a logfile that is 0 bytes and is not updating? TIA.
by gmhp New Member in Splunk Search 01-15-2014
0 1
0
1
dfigurello
Hey Splunkers, Could you help me about identify a field. I don't have experience with regex. In my case I have fire...
by dfigurello Communicator in Splunk Search 01-15-2014
0 4
0
4
yuwtennis
Hi! I would like to have some help with summary indexing. My situations is like following: I have events that come...
by yuwtennis Communicator in Splunk Search 01-15-2014
0 2
0
2
yuwtennis
Hi! Is it possible to overwrite the summary index with same timestamp? Lets say you already have a summary index as...
by yuwtennis Communicator in Splunk Search 01-15-2014
0 2
0
2
Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...