Splunk Search

Splunk Search
Community Activity
greg
I have a set of rules in one of my sourcetypes: Rule Expr Value Rule0 <0 Value0 Rule1 ...
by greg Communicator in Splunk Search 04-10-2013
2 6
2
6
christian_l
Hi all, I got a problem while performing a lookup at a csv-file.In general the lookup works fine, but its missing som...
by christian_l Path Finder in Splunk Search 04-10-2013
0 4
0
4
kengilmour
Hello, I have a very peculiar time problem that I want to fix with a quick and dirty fix. I am creating a sparkline ...
by kengilmour Path Finder in Splunk Search 04-10-2013
0 3
0
3
shri_27
Hi all, I have 2 files, where suplierID,contractID are the common fields, Now I want to exclude the values of these f...
by shri_27 Path Finder in Splunk Search 04-10-2013
0 1
0
1
beaunewcomb
I'm trying to get the Pulse cloudwatch app to work using boto and dateutil, but splunkd.log shows this: 04-09-2013 2...
by beaunewcomb Communicator in Splunk Search 04-09-2013
0 1
0
1
cosullivan66
Hi all, wish I could figure this one out myself but I'm stumped. I'm interested in producing a list of all the accoun...
by cosullivan66 Explorer in Splunk Search 04-09-2013
0 2
0
2
marellasunil
Eval is not validating "string" proparly, means status=Normal is not validating. It is perfectly working for numaric ...
by marellasunil Communicator in Splunk Search 04-09-2013
0 3
0
3
tnkoehn
I have an initial search that will find the top 100 Called_Numbers by the number of calls they are taking. A simplifi...
by tnkoehn Path Finder in Splunk Search 04-09-2013
0 5
0
5
praveenvemuri
Hi I am trying two get distinct count of field1 when field2 contains string 200, 500, 400 etc and i am trying to sum...
by praveenvemuri Explorer in Splunk Search 04-09-2013
0 1
0
1
steve
I ran the following: source="/path/to/vpn_log" | anomalousvalue action=summary date_hour Every event was normal (ev...
by steve Path Finder in Splunk Search 04-09-2013
0 1
0
1
Dark_Ichigo
I want to collect all data before a specified text or that ends with it, I have tried the following: (.+?)ABC_....
by Dark_Ichigo Builder in Splunk Search 04-08-2013
0 9
0
9
sarahh
Hi, May I ask if there is any steps on how can you have your custom command take in the search results of "x|custom...
by sarahh Engager in Splunk Search 04-08-2013
0 4
0
4
aswanda
I am looking for a way to compare data from multiple inputlookup csv's. Each CSV has the same exact set of fieldnames...
by aswanda Engager in Splunk Search 04-08-2013
0 1
0
1
lpolo
Let's say we have the following 3 logs sources: request.log : timestamp id=123 q=1 filter=2 query_time="timestamp" ...
by lpolo Motivator in Splunk Search 04-08-2013
0 4
0
4
sathiyamoorthy
Executed a tscollect with two fields 'URL' and 'download size', how to extract URLs which matches particular regex. ...
by sathiyamoorthy Explorer in Splunk Search 04-08-2013
0 1
0
1
erick_costa
How to plot values in graphs? Searchs or Xml Dashboard!!!!
by erick_costa Path Finder in Splunk Search 04-08-2013
0 2
0
2
flanny16
Hello All, I have setup splunk as a syslog receiver from a test wireless controller. this is working great. Next, I h...
by flanny16 New Member in Splunk Search 04-08-2013
0 2
0
2
anuragkapur
I have read in a few places that the max points that can be plot using a timechart is 1000. I have the following quer...
by anuragkapur Explorer in Splunk Search 04-08-2013
0 3
0
3
dewald13
I am trying to create an "action" field extraction to grab "permitted/denied" from my Cisco device logs. I can get th...
by dewald13 Path Finder in Splunk Search 04-08-2013
0 2
0
2
sumanth_isac
Hi , I have data files which is generated by script(eg. xyz12.ksh) When each time a script runs a file is generated w...
by sumanth_isac Path Finder in Splunk Search 04-08-2013
0 2
0
2
KarunK
Hi All, I have a field called "diskin" which can have two values in two measurements 1) K for kilobytes 2) M for m...
by KarunK Contributor in Splunk Search 04-07-2013
1 4
1
4
Jiten009
Hi, I have below query and its working fine. sourcetype="mylogs" | fields QTime |eval QTimes = case(QTime<50, "0-50m...
by Jiten009 Explorer in Splunk Search 04-07-2013
0 3
0
3
unclethan
In splunk 5.0.1 adding "minspan" to timechart results in the message "minspan option has no effect when span is speci...
by unclethan Path Finder in Splunk Search 04-05-2013
0 5
0
5
jcmaynard
Search: index=XXX source=/xxx/xxx/xxxx.log | regex 'something' How would I do this properly showing just the regexed...
by jcmaynard Explorer in Splunk Search 04-05-2013
0 3
0
3
foloyo1314
How to get full join result of the below two logs: log1: ID, value1 1,aaa 1,abc log2: ID, value2 1,X1 1,X4 When join...
by foloyo1314 Engager in Splunk Search 04-05-2013
1 3
1
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors