Splunk Search

Splunk Search
Community Activity
gnovak
I have this search which works great. It makes a list for me of load times for each user, and then a total of all ti...
by gnovak Builder in Splunk Search 12-20-2012
0 4
0
4
dannux
Hi Everyone, I have created a dynamic view that display data for the last 24 hours for a particular search. Is it po...
by dannux Path Finder in Splunk Search 12-20-2012
1 1
1
1
aaronkorn
Anyone have an idea to sort a multivalued stacked bar chart based on the value? I already tried | sort -Size. The se...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 12-20-2012
0 3
0
3
smolcj
hi all, i just want to round some values in secs. i tried with round and floor options. but it is not working. i ext...
by smolcj Builder in Splunk Search 12-20-2012
0 10
0
10
mritenburg
Hello, I am trying to craft a regex to match everything between the 25th and 130th character in a line. I am having...
by mritenburg New Member in Splunk Search 12-20-2012
0 3
0
3
sieutruc
Hello, I have a search like : total value of each transaction type for each business day host="test1" sourcetype="O...
by sieutruc Contributor in Splunk Search 12-20-2012
0 6
0
6
slierninja
We setup a search peer in a master/slave scenario and noticed that not all of our fields are present in the search pe...
by slierninja Communicator in Splunk Search 12-20-2012
0 3
0
3
gcoles
I am writing a search that looks at weighted moving averages of data points summarized and logged at 2 minute interva...
by gcoles Communicator in Splunk Search 12-19-2012
3 4
3
4
msarro
Hey everyone. I've got a box with numerous CPU cores, and each has its own field. I need to find the maximum value of...
by msarro Builder in Splunk Search 12-19-2012
4 7
4
7
gnovak
I've been messing with this all morning and still can't get the results I want. Why is this so difficult to achieve?...
by gnovak Builder in Splunk Search 12-19-2012
0 3
0
3
the_wolverine
Would someone please confirm what the unit of time reported by run_time is? Run_time as reported by the scheduler or...
by the_wolverine Champion in Splunk Search 12-19-2012
0 2
0
2
jpass
is it possible to create an input with MySQL connector that watches the database for new results? I do this with a sc...
by jpass Contributor in Splunk Search 12-19-2012
0 1
0
1
alexiri
I'm trying to create a dashboard that will allow a user to select a machine or set of machines and see a timechart of...
by alexiri Communicator in Splunk Search 12-19-2012
2 4
2
4
r999
I have had some data reporting in from event logs from approx 30-40 windows servers. There were some issues on some ...
by r999 Path Finder in Splunk Search 12-19-2012
1 1
1
1
rakesh_498115
Hi.. I have sample log events as follows : event 1 : 12-10-24:0:0:1 RequestOrder OrderNo=107 Product=Samsung... .....
by rakesh_498115 Motivator in Splunk Search 12-19-2012
1 1
1
1
syslogap
Hi, I'm using version 4.2.2 with the search query: host = "JA8*" AND eventtype="firewall*" earliest=7/1/2011:0:0:0...
by syslogap New Member in Splunk Search 12-19-2012
0 4
0
4
BP9906
Hello, How can I make a field extraction match multiple times on a given line? here's an example: datetime=1355871...
by BP9906 Builder in Splunk Search 12-18-2012
0 2
0
2
chablist
I have a log file that always has the same structure of: time1,time2,groupNumber eg: 355350224,338837556,2 135535022...
by chablist New Member in Splunk Search 12-18-2012
0 1
0
1
bshamsian
Using Splunk 4.3 - My data input file is in JSON format with multiple events in each file stored in an events array. ...
by bshamsian Path Finder in Splunk Search 12-18-2012
0 5
0
5
Dark_Ichigo
I calculated an Average for a list of values AVG(numbers), I now have a list of those Averaged numbers with the numbe...
by Dark_Ichigo Builder in Splunk Search 12-18-2012
0 1
0
1
rakesh_498115
Hi. I have created a rex for my field say . MSGID . can this be saved in splunk using Fields Manager. my rex is r...
by rakesh_498115 Motivator in Splunk Search 12-18-2012
0 1
0
1
yanivoren
Hi, I'm using free edition of splunk server, the problem is that every time I start the splunk server, the data is de...
by yanivoren New Member in Splunk Search 12-18-2012
0 1
0
1
tnkoehn
After a delimited field extraction in transforms.conf, I have a field called Gateway_Name that contains, for example,...
by tnkoehn Path Finder in Splunk Search 12-18-2012
1 4
1
4
quatral
Hi everyone, A simple question about the field extractions. Suppose I've got 12 logs with basically some recurrent i...
by quatral Explorer in Splunk Search 12-18-2012
1 3
1
3
ma_anand1984
fieldA is the extracted field already available fieldB is eval field | eval fieldB=* | where fieldA=fieldB Here im...
by ma_anand1984 Contributor in Splunk Search 12-18-2012
0 4
0
4
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...