Splunk Search

Splunk Search
Community Activity
jalfrey
I would like to calculate the top talkers by application (name/ID) but I have run into a snag. The firewall returns "...
by jalfrey Communicator in Splunk Search 07-02-2013
0 4
0
4
richnavis
I"m trying to create a search that will show me the count of certain types of events I get in a Windows Event Log. ...
by richnavis Contributor in Splunk Search 07-02-2013
0 5
0
5
KarunK
Hi All, My Splunk instance 5.0.1 running in Solaris 10 is crashing. I have updated with the latest Splunk 5.0.3 but ...
by KarunK Contributor in Splunk Search 07-02-2013
0 5
0
5
sha1020
Hi, some events are displayed with the wrong message in the Splunk for Sourcefire app Event Dashboard: Events with ...
by sha1020 Explorer in Splunk Search 07-02-2013
0 1
0
1
ncbshiva
Hi I have a log file , i want to search events for first occurrence of word "error" in that file, till the first occ...
by ncbshiva Communicator in Splunk Search 07-02-2013
0 5
0
5
ChhayaV
Hi, I want to extract url's from the events as a seperate field. Here is the log file 04/15/2013 17:51:58.09 w3wp...
by ChhayaV Communicator in Splunk Search 07-02-2013
0 7
0
7
ChhayaV
Hi, Is it possible to do lookup using a calculated field if yes then what is the procedure? i tried doing it but not ...
by ChhayaV Communicator in Splunk Search 07-02-2013
0 7
0
7
cpeteman
I have the current statement using append: search_term1 | stats count by ip_address | table ip_address count | appen...
by cpeteman Contributor in Splunk Search 07-01-2013
5 4
5
4
motobeats
I have a search that generates a table with various stats (min, max, %-tile) all by date_hour. Today I ran into an is...
by motobeats Path Finder in Splunk Search 07-01-2013
0 5
0
5
afd0174
Hi, I have a question about the Splunk C# SDK. I have successfully built the SDK and can use the example submit() p...
by afd0174 Explorer in Splunk Search 07-01-2013
0 3
0
3
gstewart
I'd like to use the 24 hour time format in search results (en-GB localization), but retain the US date format mm/dd/y...
by gstewart Explorer in Splunk Search 07-01-2013
4 1
4
1
wpreston
I'm trying to perform a database lookup on the User_ID field in my events but the lookup fails. The User_ID field ma...
by wpreston Motivator in Splunk Search 07-01-2013
1 5
1
5
SplunkUser5888
Hi guys, I've got a script uploading html files into Splunk. This uses IOC to check which hosts are infected and by w...
by SplunkUser5888 Path Finder in Splunk Search 07-01-2013
0 4
0
4
sunrise
Hi Splunkers, I wanna develop custom python scripts as a search command whose input data is search fields, output da...
by sunrise Contributor in Splunk Search 06-30-2013
0 3
0
3
bmgilmore
Are there any differences between the following queries other than my observation (below): xyseries Foo Bar Valuecha...
by bmgilmore Path Finder in Splunk Search 06-30-2013
3 2
3
2
apackard
I am trying to plot a 4 column chart, say 'A, B, C, D', where each column value is actually a single value series (so...
by apackard Engager in Splunk Search 06-30-2013
1 1
1
1
acedeno
Hi, I'm trying to create a table of data which draws upon a subsearch and a join in order to have more completely re...
by acedeno Explorer in Splunk Search 06-30-2013
1 4
1
4
ravinder82
Hi Team, I am new to Splunk portal. I have to search on multiple hosts for HTTP hits and display the result in singl...
by ravinder82 New Member in Splunk Search 06-30-2013
0 5
0
5
Weng
For the following data, Date=4 June 2013, Result=Win,Ticks=11,Setup=Range Fade, Risk=10, Target=11 .....and more I ...
by Weng New Member in Splunk Search 06-29-2013
0 3
0
3
xvxt006
Hi, I know we have addcoltotals if we want to get total for the specified column. Do we have any function or any way...
by xvxt006 Contributor in Splunk Search 06-29-2013
0 3
0
3
shri_27
Hi How to give permissions to fields extracted using interactive field extraction so that they can be seen within al...
by shri_27 Path Finder in Splunk Search 06-29-2013
0 1
0
1
jalfrey
I'm getting a dst= and also getting a porto=. Both values return the port number and they appear to be the same value...
by jalfrey Communicator in Splunk Search 06-28-2013
0 2
0
2
gnovak
This really has me stumped. Not sure why this isn't working. I've got data in a log that looks like this: --- ...
by gnovak Builder in Splunk Search 06-28-2013
0 8
0
8
jsp
I have a bunch of events coming in the format of the below example. They are random in the time it takes from start t...
by jsp Engager in Splunk Search 06-28-2013
0 1
0
1
motobeats
Can the granularity of the default timeline on the Search page be changed? Looks like it is optimized for speed depen...
by motobeats Path Finder in Splunk Search 06-28-2013
2 3
2
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...