Splunk Search

Splunk Search
Community Activity
robK123
Hello, I have a search that covers 7 days of data showing when users failed to login 5 or more times but I want to k...
by robK123 Explorer in Splunk Search 01-02-2013
0 3
0
3
dadi
hi guys, I've this following command that works perfectly in search query, but doesn't work in macro: .... | lookup ...
by dadi Path Finder in Splunk Search 01-02-2013
1 9
1
9
robK123
I have this search I want to only display results for when the sum(failures) is higher than 4 how can I do this? (in...
by robK123 Explorer in Splunk Search 01-02-2013
0 2
0
2
pramodkumar
Hi Team, Am facing one issue, my requriement is to continously monitor the file and want to pick only the latest rec...
by pramodkumar Path Finder in Splunk Search 01-02-2013
0 3
0
3
sumanth_isac
Dear all, I am not able to remove old log files from my search. I tried all possibilities. I tried 1. ./splunk sto...
by sumanth_isac Path Finder in Splunk Search 01-01-2013
0 11
0
11
wellsajs
Hi, Has any one been able to work out howto incorporate the exclusion of public holidays in searches. I am trying t...
by wellsajs Explorer in Splunk Search 01-01-2013
0 3
0
3
xli_splunk
We need to know the env variables used to construct home path.
by xli_splunk Splunk Employee Splunk Employee in Splunk Search 12-31-2012
0 1
0
1
yap
I've encountered with this finding at Packetstorm website. May I know whether Splunk already verified and acknowledge...
by yap Explorer in Splunk Search 12-31-2012
0 2
0
2
jmaschle
i have several years of daily event data in a sqlserver table i would like to stack and chart and get some good stats...
by jmaschle New Member in Splunk Search 12-31-2012
0 6
0
6
Splunk_U
Can you please help me out to merge these two search strings index=os sourcetype=vmstat | multikv fields memUsedPc...
by Splunk_U Path Finder in Splunk Search 12-31-2012
0 5
0
5
pramodkumar
Hi Team, I have successfully indexed the data but it is not getting dispalyed in Search, dont know which settings i ...
by pramodkumar Path Finder in Splunk Search 12-31-2012
2 5
2
5
smolcj
hi, i want to change the fontsize of a single result table in application.css. i did a homework and i tried .Si...
by smolcj Builder in Splunk Search 12-31-2012
1 6
1
6
Aakanksha
Is it possible to display weekly as well as daily data on the same chart? Eg. Three weeks data with sub-scale of 7 da...
by Aakanksha Path Finder in Splunk Search 12-30-2012
0 3
0
3
Volto
I have a search that gives me the event counts for each host every hour and compares that count against a running ave...
by Volto Path Finder in Splunk Search 12-29-2012
0 1
0
1
a212830
Hi, I want to create a report on syslog messages received from the same file, which come from different types of dev...
by a212830 Champion in Splunk Search 12-28-2012
0 1
0
1
chablist
I'm trying to output the reliability for a channel over a time period. My sample log file looks like this: channel...
by chablist New Member in Splunk Search 12-28-2012
0 3
0
3
msmapper
Hi all, I would like to create a search that would only look at a certain minute or few seconds on the half hour ove...
by msmapper Path Finder in Splunk Search 12-28-2012
0 3
0
3
pjc
I'm fairly new to Splunk queries, so apologies if this is overly simplistic. I have a query looking at apache logs i...
by pjc Engager in Splunk Search 12-28-2012
1 4
1
4
xvxt006
Hi, i am using the below search query to get uri commands from the access logs. But result includes page resources as...
by xvxt006 Contributor in Splunk Search 12-28-2012
0 3
0
3
thiliphk
How do we determine the need for increasing diskspace on /Splunkidx. Do we have any formula ?
by thiliphk New Member in Splunk Search 12-28-2012
0 1
0
1
robK123
I have this search: (index=infrastructure-os OR index=main) sudo "incorrect password attempt*" |rex field=_raw "sudo...
by robK123 Explorer in Splunk Search 12-28-2012
0 4
0
4
sriva6
Hi, I have application logs which read something like this Blah bla blah File Descriptor: 1234 Blah bla blah File De...
by sriva6 New Member in Splunk Search 12-28-2012
0 4
0
4
splunk_learner
Hi, I want search query to read my index name and sourcetype name from config file.So that if there is any change in ...
by splunk_learner Explorer in Splunk Search 12-28-2012
0 3
0
3
kdwooo
Hi, I stuck in connection error message as follows: (indicated in Italic font below...) The following error message ...
by kdwooo New Member in Splunk Search 12-28-2012
0 1
0
1
jslee
I have two fiels. Deny and Monitor. I want to draw timechart added by SUM field. Can i add SUM field? _time A ...
by jslee Explorer in Splunk Search 12-27-2012
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...