Splunk Search

Splunk Search
Community Activity
vaibhavbeohar
Hi I have a file with fields CloseDateTime and StartDateTime, both the field have a format like "2013-03-08 16:26 PM...
by vaibhavbeohar Path Finder in Splunk Search 03-21-2013
0 1
0
1
guilmxm
Hi, I am trying to find the best and reliable solution to get precise graphs using timechart command. In deed, tim...
by guilmxm Influencer in Splunk Search 03-21-2013
1 3
1
3
p_basanth
| stats values(Domain), count by Short_Host gives me overall count. But i need individual count of each Domain. | st...
by p_basanth New Member in Splunk Search 03-21-2013
0 3
0
3
swilson91
Hi, I'm hoping someone can help me I currently have some queries I run that I can looking to automate into Splunk. ...
by swilson91 New Member in Splunk Search 03-21-2013
0 2
0
2
datasearchninja
I have some logs arriving via syslog, that have a single event broken up into multiple syslog messages. Due to issues...
by datasearchninja Communicator in Splunk Search 03-20-2013
0 2
0
2
noambz
Hi, I have the following search which generates the data below: some_search | bucket _time span=1h | stats count ...
by noambz Explorer in Splunk Search 03-20-2013
0 3
0
3
jacs
Can I cluster two Splunk nodes for data availability without having a search head node? In other words, use one or b...
by jacs New Member in Splunk Search 03-20-2013
0 1
0
1
Splunk_U
I have two search heads. I want that if a user logged in to SRCH1 and saved a search and logged off and then looged i...
by Splunk_U Path Finder in Splunk Search 03-20-2013
0 2
0
2
the_wolverine
We have some fields with large unique string values, e.g. EMAIL_SUBJECT, where search performance (particularly on wi...
by the_wolverine Champion in Splunk Search 03-20-2013
0 1
0
1
daniel333
All, I need to compare the results of two different searches and I am lost. Something like this. count( search st...
by daniel333 Builder in Splunk Search 03-20-2013
0 2
0
2
rakesh_498115
props.conf EXTRACT-IPUBMESSAGEID = <L:MESSAGEID>(?<IPUBMESSAGEID>[^<]*)</L:MESSAGEID> EXTRACT-Parse_MESSAGEID = IPUB...
by rakesh_498115 Motivator in Splunk Search 03-20-2013
0 3
0
3
p_basanth
I want to combine the below 2 ouputs into single line | stats count by Domain | stats values(Domain) by Short_Host ...
by p_basanth New Member in Splunk Search 03-20-2013
0 4
0
4
p_basanth
Any pointers on how to extract the third field Event1: <> Event2: the third field is populated with double ...
by p_basanth New Member in Splunk Search 03-20-2013
0 1
0
1
andyspusm
I am extracting a field "ipaddr" which is the result of using "eval" to convert a previously extracted field "nwclien...
by andyspusm Explorer in Splunk Search 03-19-2013
0 2
0
2
dilstn
I have a log files where it contains duplicates like "json from session" log duplicates .. so the log which contains ...
by dilstn Explorer in Splunk Search 03-19-2013
0 4
0
4
p_basanth
Using the below regex I was able to extract first7 fields Need to extract the last 3 fields How to skip the blank <> ...
by p_basanth New Member in Splunk Search 03-19-2013
0 4
0
4
dgadjov
Running this through the Splunk search I get no errors. However when I put this search in my Advance XML I get: misma...
by dgadjov Explorer in Splunk Search 03-19-2013
0 5
0
5
dgadjov
The goal is just to have the percentage pass rate at the bottom of a dynamically named column that contains "Passed" ...
by dgadjov Explorer in Splunk Search 03-19-2013
0 3
0
3
machosplunker
I am trying to filtering results based on hosts which are our hbase zookeepers and region servers. There are 3 hbase ...
by machosplunker Explorer in Splunk Search 03-19-2013
0 3
0
3
basusplunk
Hi, Please help me. Where can I get the latest splunk jar? Thanks, Basu.
by basusplunk New Member in Splunk Search 03-19-2013
0 3
0
3
lpolo
After upgrading to 5.0.1 splunk is reporting this message: "Metadata results from this peer are incomplete: the peer...
by lpolo Motivator in Splunk Search 03-19-2013
4 1
4
1
approachct
We are replacing our existing logging system with Splunk, but we still have the need to load some of these log events...
by approachct Path Finder in Splunk Search 03-19-2013
1 1
1
1
gudavasr
Hi, My transform file: [taskname] REGEX = \b(Task\w+)\b FORMAT = taskname::$1 props.conf REPORT-taskname = tas...
by gudavasr Path Finder in Splunk Search 03-19-2013
0 1
0
1
renuka13
hi, how do i find the difference between two dates which are in the form 12-JAN-2003? How do i first convert months ...
by renuka13 Explorer in Splunk Search 03-19-2013
0 1
0
1
bnafziger
I am a newbie. I'd like an another user's opinion of my logic. Is this the proper syntax for generation of std dev? I...
by bnafziger Engager in Splunk Search 03-19-2013
0 1
0
1
Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...