Splunk Search

Splunk Search
Community Activity
chris
I have a search that should display a percentage of bad events compared to the good events over a time period. I want...
by chris Motivator in Splunk Search 10-29-2013
0 1
0
1
xvxt006
Hi, I am getting order count today by hour vs last week same day by hour and having a column chart. This works fine m...
by xvxt006 Contributor in Splunk Search 10-29-2013
1 5
1
5
john_byun
I have the following search that gives me the ratio between the values from 2 separate searches. I'm sure it's prett...
by john_byun Path Finder in Splunk Search 10-28-2013
0 5
0
5
jwestberg
I have a dataset that is going into Splunk where an event is a timestamp followed by a list of key value pairs where ...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 10-28-2013
2 6
2
6
nandipatisunil
I have trap data coming onto my Splunk Server ... the data looks like this 1.3.6.1.4.1.3279.1.1.8.1.35.2 = ObjectSyn...
by nandipatisunil Path Finder in Splunk Search 10-28-2013
2 4
2
4
jberlin
My search is partially working in the aspect that it returns event data, however all of the events are mashed into on...
by jberlin Path Finder in Splunk Search 10-28-2013
0 2
0
2
tristanmatthews
I'm having trouble understanding the math rules on the search line, so instead of continuing to guess what might work...
by tristanmatthews Path Finder in Splunk Search 10-28-2013
1 1
1
1
sandeep_thosar
Hi Team, I am new to splunk and currently we are working to visualize splunk reports to Tableau, but when we import ...
by sandeep_thosar Explorer in Splunk Search 10-28-2013
1 14
1
14
briang67
I have an unstructured log file that looks like the following. How would I go about creating key/value pairs for metr...
by briang67 Communicator in Splunk Search 10-28-2013
0 7
0
7
xvxt006
Hi, i would like to capture the below 2 patterns and i tried to use the below combination but i am not getting inten...
by xvxt006 Contributor in Splunk Search 10-28-2013
0 4
0
4
lmarcel
I have a dashboard table based on the search: index=eaccess Card_Name="John*" | convert timeformat="%m/%d/%y %I:%M:...
by lmarcel New Member in Splunk Search 10-28-2013
0 3
0
3
ajmills
Hello-- For comparison purposes I'd like to determine how many times each of our alerts have been triggered. Is this...
by ajmills New Member in Splunk Search 10-28-2013
0 1
0
1
rahulgopal
Is the Splunk audit log format or the description of each field in the audit.log file documented somewhere? I'm inter...
by rahulgopal Explorer in Splunk Search 10-28-2013
0 2
0
2
tmarlette
I am attempting to get the top offenders of average latency, by their client IP, but limited to the top 50 results, s...
by tmarlette Motivator in Splunk Search 10-28-2013
0 1
0
1
MaximKorobov
I have quoted parameters in log files, which are processed by Splunk: "Version":"21" How to extract that parameter...
by MaximKorobov New Member in Splunk Search 10-28-2013
0 3
0
3
rhayle
The navigation menu at the top would be so much better if it could transmit the context (index and host) for the new ...
by rhayle Path Finder in Splunk Search 10-28-2013
1 8
1
8
MadhuriVanga
Hi, My saved search looks like below: index="efg" "$var$" rex "(abc=.*? )(?<payload>.*)(>)" | eval payload=replace(...
by MadhuriVanga New Member in Splunk Search 10-28-2013
0 1
0
1
xvxt006
Hi, we have 2 uri patterns as shown below /search?searchQuery=4gmw4 (the end part is always single word which is al...
by xvxt006 Contributor in Splunk Search 10-27-2013
0 4
0
4
skippylou
Trying to figure out if this is possible. Many times I do a search similar to: host=somehosts* earliest=-1d | clust...
by skippylou Communicator in Splunk Search 10-27-2013
2 4
2
4
tristanmatthews
Hi, I have a weird data structure I'm trying to figure out a better way to handle. The data I'm getting uses categor...
by tristanmatthews Path Finder in Splunk Search 10-27-2013
0 2
0
2
sourabhguha
Hi, Following is my input. It is a set of tab delimited files. Here is a sample. I made updates to props.conf and tr...
by sourabhguha Explorer in Splunk Search 10-27-2013
0 4
0
4
HeinzWaescher
Hi everbody, I have got a field "Action" with different Values (A,B,C,D,E). I would like to calculate the percentage...
by HeinzWaescher Motivator in Splunk Search 10-27-2013
0 2
0
2
yuwtennis
Hi! I want to ask question if something like below can be implemented. I have created 4 searches. search A : creat...
by yuwtennis Communicator in Splunk Search 10-27-2013
0 2
0
2
yuwtennis
Hi ! I would like to get an advice with search command. I want to do something like , Reference the next row (line...
by yuwtennis Communicator in Splunk Search 10-27-2013
0 2
0
2
sourabhguha
Hi, I am indexing a set of csv files. the files do not have the header fields in it. While I am creating the source...
by sourabhguha Explorer in Splunk Search 10-27-2013
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...