Splunk Search

Splunk Search
Community Activity
cgbsplunk
I want to be able to do a search of an index with search parameters returned from a database lookup. An example woul...
by cgbsplunk Explorer in Splunk Search 09-13-2013
0 6
0
6
tb5821
The concept seems simply yet there doesn't seem to be a straightforward way of doing it. I have URL which I want splu...
by tb5821 Communicator in Splunk Search 09-13-2013
0 1
0
1
BertKraan
Hello, splunk newbie here, I have tens of servers named like abc01, abc02 .... abc20. Now i would like to search for...
by BertKraan Engager in Splunk Search 09-13-2013
0 3
0
3
ChhayaV
hi, these are my searches index=tm_idx host="audit" | timechart count by Process usenull="f" index=tm_idx host="au...
by ChhayaV Communicator in Splunk Search 09-13-2013
1 2
1
2
keerthana_k
Hi, We are using Splunk version 5.0.4 in our application. In order to bucket our data and display the buckets in pro...
by keerthana_k Communicator in Splunk Search 09-13-2013
0 1
0
1
luthfi49
Hi all, When I use query : mysearch | stats avg(X) It is supposed that the result is the average value of field X in...
by luthfi49 Explorer in Splunk Search 09-13-2013
0 3
0
3
ltruesda
I have an index of events where each event is associated with a user. I want to produce a table where each row repre...
by ltruesda Explorer in Splunk Search 09-12-2013
0 3
0
3
cycheng
In http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Stats, I found that there is an optional argumen...
by cycheng Path Finder in Splunk Search 09-12-2013
1 1
1
1
sajoseph
HI, I have a dashboard query which is like this. index=elf |search * | chart count(eval(event_type="3000")) AS AUDIT...
by sajoseph Explorer in Splunk Search 09-12-2013
0 1
0
1
adrianathome
I have a field on my events that has the following: john,12345,mark,2356,maria,4567 rachel,8883,john2,488475 nothing...
by adrianathome Communicator in Splunk Search 09-12-2013
0 3
0
3
gjohnson
Forgive me if this has been asked before, but I am trying to do a lookup using geoip (maxmind database) to resolve IP...
by gjohnson New Member in Splunk Search 09-12-2013
0 3
0
3
jackykitkit
I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multip...
by jackykitkit New Member in Splunk Search 09-12-2013
0 1
0
1
wbordeau
I want to hide peaks in timechart that do not exceed a certain threshold. I'm trying the below query but am not havi...
by wbordeau Explorer in Splunk Search 09-12-2013
0 1
0
1
lbrindise
Have never used Splunk; just looking to see if something is possible. I not only want to monitor the things that Splu...
by lbrindise New Member in Splunk Search 09-12-2013
0 1
0
1
vbumgarner
Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>....
by vbumgarner Contributor in Splunk Search 09-12-2013
1 6
1
6
john
source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ...
by john Communicator in Splunk Search 09-12-2013
0 1
0
1
harsh1734
hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet...
by harsh1734 New Member in Splunk Search 09-12-2013
0 3
0
3
samiomer
hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct...
by samiomer Path Finder in Splunk Search 09-12-2013
0 1
0
1
rgcurry
I have a dashboard panel that displays the number of user sessions on a web server in a column chart. The user wants ...
by rgcurry Contributor in Splunk Search 09-12-2013
0 3
0
3
keerthana_k
Hi, We have scheduled saved search running every 5 minutes to create summary index. In our test setup we get 200 lo...
by keerthana_k Communicator in Splunk Search 09-12-2013
0 1
0
1
lguinn2
Okay, I am sure that I have done something stupid, but I can NOT figure it out! This search works and returns about ...
by Legend in Splunk Search 09-12-2013
1 3
1
3
shreeCS
Hi, I have csv file uploaded on to splunk.Here is the sample entries Intime Outtime 8:33 17:39 8:38 17:40 8:33 ...
by shreeCS New Member in Splunk Search 09-12-2013
0 2
0
2
ChhayaV
hi, this is my query index=tm_idx host="server" sourcetype="TM_Test_10" | rex field=msg "(?i)TM1\sserver\sload\s...
by ChhayaV Communicator in Splunk Search 09-12-2013
0 1
0
1
gstewart
Problem: Huge list of IP addresses across multiple subnets, how to group and list in order of subnets. This is what ...
by gstewart Explorer in Splunk Search 09-11-2013
0 3
0
3
madhack
I've configured a CSV lookup and an automatic lookup on Splunk 5.0.4 that work on one of my search heads (let's call ...
by madhack Explorer in Splunk Search 09-11-2013
1 6
1
6
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...