Splunk Search

Splunk Search
Community Activity
splunkiscool1
Hello, I would like to get an alert if the indexing volume for an index drops. I'm thinking something similar this...
by splunkiscool1 Engager in Splunk Search 04-15-2013
0 5
0
5
echalex
Hi, I need to reference a file distributed by an input app from within the app itself (outputs.conf). I need to conf...
by echalex Builder in Splunk Search 04-15-2013
0 5
0
5
jevenson
I've got a search that looks something like this: search | eval Minutes=case(field<120,"0 to 2", field>=120 AND fiel...
by jevenson Path Finder in Splunk Search 04-14-2013
1 3
1
3
asarolkar
I have two sourcetypes A and B - each has a column SERIAL_NUMBER Sourcetype A has over 1000,000 records Sourcetype B...
by asarolkar Builder in Splunk Search 04-14-2013
1 6
1
6
marellasunil
I am having 5 applications each having service names few are same. Ex : Application A - Services AA, AB, AC, Applicat...
by marellasunil Communicator in Splunk Search 04-13-2013
0 1
0
1
reed_kelly
Most of our MS SQL Servers require integrated security and the databases are not on the default instance. Our Splunk ...
by reed_kelly Contributor in Splunk Search 04-13-2013
0 2
0
2
lindsaygw
Here is the 6 lines in a log file that all come out together in the log but they are each different lines (not wrappe...
by lindsaygw New Member in Splunk Search 04-12-2013
0 3
0
3
rlautman
I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes th...
by rlautman Path Finder in Splunk Search 04-12-2013
0 1
0
1
splunk4steve
I am trying to get a list of people who have logged in to our system in the last 24 hours. The unix app runs a scrip...
by splunk4steve New Member in Splunk Search 04-12-2013
0 6
0
6
rchille
I have a search that returns values in a table like this: USERTIMEIPLocationuser1time1ip1loc1user1time2ip1loc1user2t...
by rchille Engager in Splunk Search 04-12-2013
0 5
0
5
aaronkorn
One of our Splunk searches that just searches for all events in an index for the last 24hrs used to be blazingly fast...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
0 4
0
4
aaronkorn
Hello, We have a search that is looking through a script that calculates the size of directories throughout the day ...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
2 1
2
1
andrey2007
I locally index data from apache server. I can see events for search sourcetype="access_*" and field extraction works...
by andrey2007 Contributor in Splunk Search 04-12-2013
0 3
0
3
subinj
Hi. I have an excel dump of incident tickets generated from the ticketing tool. Sample incidents' description from t...
by subinj New Member in Splunk Search 04-12-2013
0 10
0
10
splunk_zen
How is it possible that an eval expression which its components total weight is 100, breach that expected value? For ...
by splunk_zen Builder in Splunk Search 04-12-2013
0 2
0
2
betto86
Hi all  I need you help because I can't figure out how to solve this problem. Suppose we have a table, made of two ...
by betto86 Engager in Splunk Search 04-12-2013
0 1
0
1
royimad
I have a regular expression that extract everything that exist between brackets Extraction: (?i) .*? (?P<METHOD>\...
by royimad Builder in Splunk Search 04-12-2013
0 5
0
5
splunk_zen
How can I get a result out of an eval expression (without falsely decreasing the result computing its components as 0...
by splunk_zen Builder in Splunk Search 04-12-2013
0 2
0
2
royimad
Hello, I have a table with 4 Header: A B C D I need to show A C D column if B is null and B C D column if A is nul...
by royimad Builder in Splunk Search 04-12-2013
0 2
0
2
ccastrapel
Hi, I have a working search right now that returns user and host. I am wondering how to remove results where the val...
by ccastrapel New Member in Splunk Search 04-11-2013
0 1
0
1
noambz
Hi, I am getting events in the form of: __time, app_name, action,udid "2013-04-11 23:26:32","nxTomo HK V0.9","game...
by noambz Explorer in Splunk Search 04-11-2013
0 3
0
3
arrowsmith3
I have a search time query | dbquery OEM "SELECT regexp_replace(d.target_name, '\..*', '') AS output, d.collection_...
by arrowsmith3 Path Finder in Splunk Search 04-11-2013
0 1
0
1
RicoSuave
I sometimes receive the following error message in my shp environment (4.3.5) when executing a search: ERROR: Reach...
by RicoSuave Builder in Splunk Search 04-11-2013
5 2
5
2
lpolo
I need to back fill an index from a scheduled search but the result set of the scheduled search is quite large. There...
by lpolo Motivator in Splunk Search 04-11-2013
0 1
0
1
MattQ
I would like to return a chart that has LOGIN SUCCESS LOGIN FAILURE and TOTAL LOGIN ATTEMPTS. In my logs I return ...
by MattQ Explorer in Splunk Search 04-11-2013
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...