Splunk Search

Splunk Search
Community Activity
Olli1919
Hi, when trying to filter a high EPS feed with a lookup I am experiencing quite some performance issues. Are are kno...
by Olli1919 Path Finder in Splunk Search 08-06-2013
0 5
0
5
aaronkorn
Hello, We have the following table with this search but would like to drill down to a table with just the ticket det...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-06-2013
0 2
0
2
ephemeric
Greetz, Is it possible to search a range of bucket ids? I have moved a lot of warm/cold buckets and scrubbed the id...
by ephemeric Contributor in Splunk Search 08-06-2013
0 2
0
2
samhughe
One of our users has a lookup requirement that I'm struggling to find a workable solution. They want to have a numbe...
by samhughe Path Finder in Splunk Search 08-06-2013
0 4
0
4
hartfoml
I would like to create a timechart with an SLA value. I have tried this search sourcetype=foo | eval sla=50 | timech...
by hartfoml Motivator in Splunk Search 08-06-2013
0 4
0
4
Simon
Hi All I've got a very bad csv to index, which is basically a csv with 63 columns and tildes as separators, because ...
by Simon Contributor in Splunk Search 08-05-2013
0 2
0
2
ChhayaV
hi, I have a log files which are having columns that are not fixed. if first log entry has col1,col2,col3 then next ...
by ChhayaV Communicator in Splunk Search 08-05-2013
0 2
0
2
Mag2sub
How would CPU core load or CPU core sizing be split between a search head and its peer indexer when "searches with re...
by Mag2sub Path Finder in Splunk Search 08-05-2013
0 2
0
2
aaronkorn
Hello, We have the following search in a chart but the dates are sorting alphabetically rather than numerically. ie ...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-05-2013
0 2
0
2
bruceclarke
All, I'm wondering if there is a way to change my configuration files to ignore the capitalization of a field. For ...
by bruceclarke Contributor in Splunk Search 08-05-2013
0 3
0
3
greg
What I want is: ... | stats avg(eval(MyValue!=0)) as Avg It doesn't work that way (Avg is always 1.0). Of course...
by greg Communicator in Splunk Search 08-05-2013
0 9
0
9
aaronkorn
Hello, We have the following chart which displays current ticket counts over the last 7 days for different groups bu...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-05-2013
2 10
2
10
adityapavan18
Hi I know that splunk automatically creates default fields like host,sourcetype,index at index time.And also the sp...
by adityapavan18 Contributor in Splunk Search 08-05-2013
0 2
0
2
ChhayaV
hi, I want to do a lookup to a CSV file which is having multi line field value when i upload a file for lookup its g...
by ChhayaV Communicator in Splunk Search 08-05-2013
0 4
0
4
cwacha
Hi, I have built an app that aggregates data into a summary index. The app also provides a query that searches for t...
by cwacha Path Finder in Splunk Search 08-05-2013
0 1
0
1
splunkuser2013
I would like to use function case and regex together and extract the value of capturing group in one field e.g. http_...
by splunkuser2013 New Member in Splunk Search 08-05-2013
0 3
0
3
ChhayaV
hi, Is there any performance impact if i use inline search instead of saved one? Thanks and Regards
by ChhayaV Communicator in Splunk Search 08-05-2013
0 1
0
1
pembleton
Hey, quite a long post, but I'm going crazy here trying to solve this problem: I have a connection log of: id, userna...
by pembleton Path Finder in Splunk Search 08-05-2013
1 2
1
2
jsash1
Hi, I have a requirement for an event detection engine which is able to identify a string (e.g. username) in a parti...
by jsash1 New Member in Splunk Search 08-04-2013
0 3
0
3
craigcook
I've just started using summary indexes - I have two searches that work as expected on querying data in just the prev...
by craigcook New Member in Splunk Search 08-04-2013
0 1
0
1
kailun92
Hi all, I need to join two table up and do a count of rain. Below is my search query is there anything wrong ? I can'...
by kailun92 Communicator in Splunk Search 08-03-2013
0 6
0
6
Lowell
I have a questions about custom search commands and the streaming_preop option. Is there some reason why the preopt ...
by Lowell Super Champion in Splunk Search 08-02-2013
1 1
1
1
michartmann
We want to restrict certain usergroups possibility to search in Splunk based on a dynamic parameter For instance Me...
by michartmann Engager in Splunk Search 08-02-2013
1 4
1
4
ssehgal
Is there a way to limit the length of the results for a particular field? For example, if the URL/ref field is 100cha...
by ssehgal Explorer in Splunk Search 08-02-2013
1 1
1
1
ssehgal
hello i have a problem with splunk results. in some of the RAW logs i have a field called as "ref" and in some logs i...
by ssehgal Explorer in Splunk Search 08-02-2013
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...