Splunk Search

Splunk Search
Community Activity
chaitu99
source="file.txt" | transaction startswith="message1" endswith="message2" | stats count values(duration) as DUR log...
by chaitu99 Explorer in Splunk Search 03-18-2013
0 1
0
1
splunk_zen
I need to feed several days most busy hour into a weighted score evolution over time, which I'm running troubles int...
by splunk_zen Builder in Splunk Search 03-18-2013
1 9
1
9
nandm
I have a scenario where I need to restrict 100+ users within an index to their respective departments. I created an a...
by nandm New Member in Splunk Search 03-18-2013
0 1
0
1
iKate
In fact this question is an app or enhancement request. It would be extremely useful to have more chart types, like i...
by iKate Builder in Splunk Search 03-18-2013
1 1
1
1
terryloar
This works: | chart count(eval(file_date="invalid")) AS "Invalid Date Syntax" It returns "6" This doesn't work: | c...
by terryloar Path Finder in Splunk Search 03-18-2013
0 2
0
2
hjwang
dear all as title mentioned , i found some fields extraction can not reach 100 percent on total event, how can i lis...
by hjwang Contributor in Splunk Search 03-16-2013
0 3
0
3
sunrise
I want to introduce Splunk to IT operations. One of our operations is to investigate the problem with error codes of ...
by sunrise Contributor in Splunk Search 03-16-2013
1 1
1
1
apzuckerman
Hi there, I'm new to Splunk, and I'm not 100% sure if its functionality enable it to tie in to Docusign's system via...
by apzuckerman New Member in Splunk Search 03-15-2013
0 1
0
1
mikelanghorst
I've got a rather tricky (at least for me) data set that I'd like to extract values from. For this example text ` ...
by mikelanghorst Motivator in Splunk Search 03-15-2013
0 2
0
2
p_basanth
I have 2 separate rex extractions. Both work fine individually. I need to combine both these rex's into single search...
by p_basanth New Member in Splunk Search 03-15-2013
0 3
0
3
dbaker42
I'm running the following command: host=Computername AND EventCode=1309 | rename "Exception message" as Exception_mes...
by dbaker42 Engager in Splunk Search 03-15-2013
0 4
0
4
shri_27
Hi all, [subsearch]: Subsearch produced 173215 results, truncating to maxout 50000. [subsearch]: Search auto-finalize...
by shri_27 Path Finder in Splunk Search 03-15-2013
2 2
2
2
drussell88
I am getting a warning in my splunkd.log for DistributedBundleReplicationManger. 03-15-2013 08:44:28.028 -0400 WARN ...
by drussell88 Explorer in Splunk Search 03-15-2013
0 2
0
2
dgadjov
I'm trying to make a table that has one of the column headers to have the value as the most occurring value in anothe...
by dgadjov Explorer in Splunk Search 03-15-2013
0 1
0
1
KNichol5hd
sourcetype=campusmgr earliest=-72h latest=+72h [search sourcetype=msdhcp earliest=03/10/2013:12:40:00 latest=03/10/20...
by KNichol5hd Explorer in Splunk Search 03-15-2013
1 4
1
4
rossikwan
After the events received, how to identify the events receiving date & time?
by rossikwan Path Finder in Splunk Search 03-15-2013
0 4
0
4
KarunK
Hi All, Again depending on my favourite support people. I have lookup file looks like below. channel,customer chnl...
by KarunK Contributor in Splunk Search 03-15-2013
0 1
0
1
disha
Hi, I am very new to python. I need a small example of how to collect splunk search output in python variable. Please...
by disha Contributor in Splunk Search 03-15-2013
0 1
0
1
caiyundong
pass the field values to another view and how to get it,I don't know how to do ??? Please give me some help! thanks!
by caiyundong Engager in Splunk Search 03-14-2013
1 2
1
2
smolcj
How to convert the date and time in the below format to epoch time? 201303140216 yyyymmddHHMM here hour and minute is...
by smolcj Builder in Splunk Search 03-14-2013
0 4
0
4
rakesh_498115
Hi.. Can we pass entire search query using lookup files ? Name,Query A,sourcetype="A" | table A B,query2 C,quer3 $...
by rakesh_498115 Motivator in Splunk Search 03-14-2013
0 1
0
1
anuragkapur
I am trying to plot the CPU utilisation of all processes on a Solaris server using the following search query: index=...
by anuragkapur Explorer in Splunk Search 03-14-2013
0 2
0
2
arrowsmith3
Having an issue with line breaking at the time stamp for a particular sourcetype. RAW 2013-03-13T15:32:52.247-0700:...
by arrowsmith3 Path Finder in Splunk Search 03-14-2013
0 2
0
2
melonman
Hi, I think this is similar case as user URL tracking on web sites, and I am trying to track what page a user have ...
by melonman Motivator in Splunk Search 03-14-2013
0 5
0
5
sonicZ
I am trying to get a truncated list of metadata, and cant seem to get the search recognized. How can i filter certain...
by sonicZ Contributor in Splunk Search 03-14-2013
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors