Splunk Search

Splunk Search
Community Activity
sieutruc
Hello, I get difficult when manipulating XML field name, if i use like: sourcetype="test_xml_as" | table content_ta...
by sieutruc Contributor in Splunk Search 04-16-2013
0 5
0
5
bmgilmore
If I run a search such as the following: sourcetype=access_combined action=purchase | stats sum(price) as Price by p...
by bmgilmore Path Finder in Splunk Search 04-16-2013
1 1
1
1
mikedavem
Hi all, I'm working on an extraction of information into a SQL Server log. I've a field Message that looks like : L...
by mikedavem New Member in Splunk Search 04-16-2013
0 3
0
3
rstanonik
A search returned 7000 events within one second. By default splunk shows me the most recent events and allows me to n...
by rstanonik Engager in Splunk Search 04-16-2013
0 3
0
3
marellasunil
For another query where I have to use not equal to in a query for string, even not equal to is not working properly i...
by marellasunil Communicator in Splunk Search 04-15-2013
0 3
0
3
kbcuait
Hi, is it possible to broaden a search with something like this: | dbquery "dbname" "SELECT fieldname_(*) FROM table...
by kbcuait Explorer in Splunk Search 04-15-2013
0 4
0
4
Wiggy
Say I have two different logs, source=a.txt and source=b.txt and their format is as follows: Source=a.txt 09-Apr-20...
by Wiggy Splunk Employee Splunk Employee in Splunk Search 04-15-2013
0 1
0
1
jevenson
I'm trying to get a weighted ratio of errors per server. I have a lookup table like this: host,percent server1,25 se...
by jevenson Path Finder in Splunk Search 04-15-2013
0 1
0
1
jevenson
Is there a way to use a lookup table to have a list of host, and use that list to only search logs for those hosts? ...
by jevenson Path Finder in Splunk Search 04-15-2013
1 3
1
3
tomhowe
We are pushing in [json] events with a timestamp field that contains time since epoch in milliseconds, eg: {[-] nam...
by tomhowe New Member in Splunk Search 04-15-2013
0 1
0
1
paycorp
Hello, I was wondering which indexes are included in the daily 500mb limit of the free version? Is it just the main...
by paycorp Engager in Splunk Search 04-15-2013
0 3
0
3
splunkiscool1
Hello, I would like to get an alert if the indexing volume for an index drops. I'm thinking something similar this...
by splunkiscool1 Engager in Splunk Search 04-15-2013
0 5
0
5
echalex
Hi, I need to reference a file distributed by an input app from within the app itself (outputs.conf). I need to conf...
by echalex Builder in Splunk Search 04-15-2013
0 5
0
5
jevenson
I've got a search that looks something like this: search | eval Minutes=case(field<120,"0 to 2", field>=120 AND fiel...
by jevenson Path Finder in Splunk Search 04-14-2013
1 3
1
3
asarolkar
I have two sourcetypes A and B - each has a column SERIAL_NUMBER Sourcetype A has over 1000,000 records Sourcetype B...
by asarolkar Builder in Splunk Search 04-14-2013
1 6
1
6
marellasunil
I am having 5 applications each having service names few are same. Ex : Application A - Services AA, AB, AC, Applicat...
by marellasunil Communicator in Splunk Search 04-13-2013
0 1
0
1
reed_kelly
Most of our MS SQL Servers require integrated security and the databases are not on the default instance. Our Splunk ...
by reed_kelly Contributor in Splunk Search 04-13-2013
0 2
0
2
lindsaygw
Here is the 6 lines in a log file that all come out together in the log but they are each different lines (not wrappe...
by lindsaygw New Member in Splunk Search 04-12-2013
0 3
0
3
rlautman
I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes th...
by rlautman Path Finder in Splunk Search 04-12-2013
0 1
0
1
splunk4steve
I am trying to get a list of people who have logged in to our system in the last 24 hours. The unix app runs a scrip...
by splunk4steve New Member in Splunk Search 04-12-2013
0 6
0
6
rchille
I have a search that returns values in a table like this: USERTIMEIPLocationuser1time1ip1loc1user1time2ip1loc1user2t...
by rchille Engager in Splunk Search 04-12-2013
0 5
0
5
aaronkorn
One of our Splunk searches that just searches for all events in an index for the last 24hrs used to be blazingly fast...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
0 4
0
4
aaronkorn
Hello, We have a search that is looking through a script that calculates the size of directories throughout the day ...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
2 1
2
1
andrey2007
I locally index data from apache server. I can see events for search sourcetype="access_*" and field extraction works...
by andrey2007 Contributor in Splunk Search 04-12-2013
0 3
0
3
subinj
Hi. I have an excel dump of incident tickets generated from the ticketing tool. Sample incidents' description from t...
by subinj New Member in Splunk Search 04-12-2013
0 10
0
10
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...