Splunk Search

Splunk Search
Community Activity
Yancy
When using the fields sidebar, I can see how often a field appears out of my total result set (ie Appears in 62% of r...
by Yancy Path Finder in Splunk Search 02-14-2013
0 1
0
1
todd0
Why does the timeline go away when you aggregate the data with commands like stats? Can we get it back? It used to ...
by todd0 New Member in Splunk Search 02-14-2013
0 1
0
1
chakheevav
I have a bunch of events in one index. The events are divided by sourcetype, for example: sourcetype=foo | fields fr...
by chakheevav Engager in Splunk Search 02-14-2013
0 2
0
2
myli12
I am processing packets drop log events and want to have a report that contains only those events with nopktDrop>= th...
by myli12 Path Finder in Splunk Search 02-14-2013
0 1
0
1
armaanxman
I am testing Splunk on windows 2k8 R2. The sourcetype = "trc" (log file) is really huge in size and I want to block i...
by armaanxman Engager in Splunk Search 02-14-2013
1 1
1
1
aferone
I'd like to have one column chart showing the percentage of drive space taken on each of the drives in the screenshot...
by aferone Builder in Splunk Search 02-14-2013
0 8
0
8
dbautist
I have two separate searches and I want to display the results in 1 timechart with a calculated field. "searchA" | t...
by dbautist Explorer in Splunk Search 02-14-2013
0 2
0
2
masterpipo
I need to correlate the delays in mail handling in postfix logs to the sender address. As you know, the line in mail...
by masterpipo New Member in Splunk Search 02-14-2013
0 2
0
2
1234testtest
rex "(?i)\(ms\):(?P<duration>.+)" Query: sourcetype="mylog" | rex "(?i)\(ms\):(?P<duration>.+)" | eval epochtim...
by 1234testtest Path Finder in Splunk Search 02-14-2013
0 4
0
4
aleem
Hi, I have events with 360 lines of text. My problem is that Splunk 1. writes the first 257 lines of the event 2...
by SplunkTrust SplunkTrust in Splunk Search 02-14-2013
0 2
0
2
strive
Hi, I read through the pie chart docs in splunk. I am not able to customize it to my needs. My Search query is: fi...
by strive Influencer in Splunk Search 02-14-2013
0 1
0
1
dbastidas
I am a fairly new Splunk user..I have 5 different source types. Each sourcetype represents a unique txt file that ge...
by dbastidas New Member in Splunk Search 02-14-2013
0 3
0
3
balajsoz
Hi, Am having the data contains below; Asset Time stamp Temperature LD-02 00:12.6 43 41 HT-02 00:26.3 45 5...
by balajsoz Path Finder in Splunk Search 02-13-2013
0 1
0
1
smolcj
hi, the default number of events displayed in show source are 25,50,100,200,500,1000. Can i change it so that i can s...
by smolcj Builder in Splunk Search 02-13-2013
0 5
0
5
adrianathome
I have a search that has 3 joins. search1 | join common_field1 [search2] | join commonfield2 [search3] | table field...
by adrianathome Communicator in Splunk Search 02-13-2013
0 1
0
1
disha
I may be overthinks this.There must be some way of doing it. I have a data like : How can I display values of Debug ...
by disha Contributor in Splunk Search 02-13-2013
1 4
1
4
dgavic
Hello, I would like to know how to set up Splunk to offload data from one Splunk indexer to another, once the data r...
by dgavic Explorer in Splunk Search 02-13-2013
1 2
1
2
Wilcooley
I would like to format a field other than _time as relative time, like the reltime command does for _time (and only f...
by Wilcooley Path Finder in Splunk Search 02-13-2013
1 3
1
3
keerthana_k
Hi My requirement is to provide a drop down box in my dashboard. Based on the value selected in the drop down, I need...
by keerthana_k Communicator in Splunk Search 02-13-2013
1 1
1
1
hartfoml
I have a search that is | to REX then | to EVAL that is not working. I'm sure it must be a timing issue something li...
by hartfoml Motivator in Splunk Search 02-13-2013
1 6
1
6
drussell88
I am having an issue with the average execution lag increasing over a period of 24 hours. This is pushing off the ti...
by drussell88 Explorer in Splunk Search 02-13-2013
0 5
0
5
nugetchar
Hi everyone! Here is my problem: Thanks to a search, I have multiple lines on the same graph. But now, I want to merg...
by nugetchar Explorer in Splunk Search 02-13-2013
0 2
0
2
mcbradford
Is there a simple way to have splunk assign field names based on ":"? For example, Splunk does a good job of picking...
by mcbradford Contributor in Splunk Search 02-13-2013
0 2
0
2
rechteklebe
Hello, i would like to create a statistic about following events: example: [2013-xxxxx], INFO,xxxxx,user[xxxxx],se...
by rechteklebe Path Finder in Splunk Search 02-13-2013
0 2
0
2
brettcave
Is it possible to build a form with checkboxes to build a query? Something like: < input type="checkbox" token="some...
by brettcave Builder in Splunk Search 02-12-2013
1 6
1
6
Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...