Splunk Search

Splunk Search
Community Activity
a212830
Hi, I want to create a report on syslog messages received from the same file, which come from different types of dev...
by a212830 Champion in Splunk Search 12-28-2012
0 1
0
1
chablist
I'm trying to output the reliability for a channel over a time period. My sample log file looks like this: channel...
by chablist New Member in Splunk Search 12-28-2012
0 3
0
3
msmapper
Hi all, I would like to create a search that would only look at a certain minute or few seconds on the half hour ove...
by msmapper Path Finder in Splunk Search 12-28-2012
0 3
0
3
pjc
I'm fairly new to Splunk queries, so apologies if this is overly simplistic. I have a query looking at apache logs i...
by pjc Engager in Splunk Search 12-28-2012
1 4
1
4
xvxt006
Hi, i am using the below search query to get uri commands from the access logs. But result includes page resources as...
by xvxt006 Contributor in Splunk Search 12-28-2012
0 3
0
3
thiliphk
How do we determine the need for increasing diskspace on /Splunkidx. Do we have any formula ?
by thiliphk New Member in Splunk Search 12-28-2012
0 1
0
1
robK123
I have this search: (index=infrastructure-os OR index=main) sudo "incorrect password attempt*" |rex field=_raw "sudo...
by robK123 Explorer in Splunk Search 12-28-2012
0 4
0
4
sriva6
Hi, I have application logs which read something like this Blah bla blah File Descriptor: 1234 Blah bla blah File De...
by sriva6 New Member in Splunk Search 12-28-2012
0 4
0
4
splunk_learner
Hi, I want search query to read my index name and sourcetype name from config file.So that if there is any change in ...
by splunk_learner Explorer in Splunk Search 12-28-2012
0 3
0
3
kdwooo
Hi, I stuck in connection error message as follows: (indicated in Italic font below...) The following error message ...
by kdwooo New Member in Splunk Search 12-28-2012
0 1
0
1
jslee
I have two fiels. Deny and Monitor. I want to draw timechart added by SUM field. Can i add SUM field? _time A ...
by jslee Explorer in Splunk Search 12-27-2012
0 3
0
3
samsplunkd
Hi, I have a search say "foo" and it is scheduled to summary index to index named "bar". As a scheduled search, it i...
by samsplunkd Path Finder in Splunk Search 12-27-2012
0 3
0
3
dadi
I've 2 big searches that I need to join. Currently I use this paradigm for joining: search1 OR search2 | stats by jo...
by dadi Path Finder in Splunk Search 12-27-2012
1 3
1
3
Voltaire
The logs are being imported through syslog-ng into one nginx log file on a forwarder.The Challenge is Splunk sees al...
by Voltaire Communicator in Splunk Search 12-26-2012
0 1
0
1
Splunk_U
I want to create a sreach string that will provide the avegCPU util, PeakCPU util, AvgMem util and PeakMem util. I ha...
by Splunk_U Path Finder in Splunk Search 12-26-2012
0 1
0
1
olivier_romain
Hello, I am trying to build an application dealing with statistics with Splunk. However, I can't find the right way ...
by olivier_romain Engager in Splunk Search 12-26-2012
0 1
0
1
123omo
I want to know how long it takes to complete a search from the start. Is there any way?
by 123omo Observer in Splunk Search 12-26-2012
0 3
0
3
Voltaire
5:56:04.000 PM Dec 17 17:56:04 as1.br0.la.somecompany.com nginx: 68.232.40.28 - - [17/Dec/2012:17:56:04 -0800] "G...
by Voltaire Communicator in Splunk Search 12-26-2012
0 2
0
2
splunk_learner
Hi , I have events in following format Subject Maths English Science Marks1 95 98 96 Marks2 9 8 ...
by splunk_learner Explorer in Splunk Search 12-25-2012
0 2
0
2
123omo
I want to know the length of time it takes to capture specific data. Is there any way?
by 123omo Observer in Splunk Search 12-25-2012
0 1
0
1
vistasyslog
I have three Firewalls splunking, and I cannot see a src_ip or the URL fields in the search base. Is there a way to g...
by vistasyslog New Member in Splunk Search 12-24-2012
0 4
0
4
Alan_Bradley
what are the steps to get running jobid in splunk. after gettign the jobid can i put it in https://localhost:8089/ser...
by Alan_Bradley Path Finder in Splunk Search 12-24-2012
0 2
0
2
vaibhavagg2006
Hi, I wanted to know what is the best technique used for creating fields for multiple sourcetypes. For example if i h...
by vaibhavagg2006 Communicator in Splunk Search 12-24-2012
0 1
0
1
ma_anand1984
index=test_index | stats min(_time) AS earliest max(_time) AS latest | eval duration=latest-earliest | table duration...
by ma_anand1984 Contributor in Splunk Search 12-24-2012
0 1
0
1
jcisha
The question again. (The question before, but did not respond.) I would like to know how to change the time to run t...
by jcisha Path Finder in Splunk Search 12-23-2012
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...