Splunk Search

Splunk Search
Community Activity
MuS
Dear Doc Team, if one uses the link to Answers on top of the docs.splunk.com page, you end up at docs.splunk.com/Ans...
by SplunkTrust SplunkTrust in Splunk Search 10-29-2012
5 1
5
1
abhayneilam
I am giving the following search : index="maa" | table Name Age Location | rex field="Location" (?(?i)"delhi") | eva...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 10
0
10
abhayneilam
Hi, I have a query as follows : index="maa" |rex field="Location" (?(?i)"delhi") | eval ONE=lower(ONE) |stats count...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 3
0
3
gohar
Related to http://splunk-base.splunk.com/answers/7581/best-way-to-search-using-a-lookup-table I want this inverse sc...
by gohar Explorer in Splunk Search 10-27-2012
1 2
1
2
abhayneilam
Hi, I am running the below query and want to print 0 for the keyword that is not matched , can this be possible to g...
by abhayneilam Contributor in Splunk Search 10-27-2012
0 2
0
2
hirsts
I have a challenge that I'm hoping someone can help with. There are around 24,000,000 events being indexed per 24 ho...
by hirsts Path Finder in Splunk Search 10-26-2012
0 2
0
2
madanashok
Hi, Just have a look at this code < module name="HiddenSearch" layoutPanel="panel_row2_col1" autoRun="True"> <...
by madanashok Path Finder in Splunk Search 10-26-2012
0 2
0
2
johnebgood
Hello, I have logs coming in that look like the following: (Tab between columns) server1.something.com ApacheLog ...
by johnebgood Path Finder in Splunk Search 10-26-2012
1 4
1
4
rakesh_498115
Hi. I have search query that query returns certains fields . these information will vary according to the realtime d...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 2
0
2
dspracklen
My problem with this is that the saved search takes longer than 60 seconds to run, so I only get partial answers if I...
by dspracklen Path Finder in Splunk Search 10-26-2012
1 3
1
3
rakesh_498115
Hi.. I know that the dolloar $ is used for variables . like $a or $b something like this.In splunk i have seen in fe...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 1
0
1
bkcarter
I need to create a transform stanza that will seperate some events depending on which domain they originate from. ...
by bkcarter Path Finder in Splunk Search 10-26-2012
0 1
0
1
giridhar_tm
This is a question on the OData App. I have a search that lists the output as a table, when I save this search and a...
by giridhar_tm Engager in Splunk Search 10-26-2012
1 2
1
2
theouhuios
Hello I am trying to calculate the mean of a field and it's strange that splunk cal the mean in a completely differe...
by theouhuios Motivator in Splunk Search 10-26-2012
0 2
0
2
rakesh_498115
Hi.. I have search query which gives me a ouput of certain fields say A,B,C and we know that splunk has two default ...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 4
0
4
henryt1
So I wasn't really sure how to do this after reading the documentation, but I'm running the following search: (host=...
by henryt1 Path Finder in Splunk Search 10-26-2012
0 2
0
2
abhayneilam
I have a report like this : keyword "one" "two" "three" mumbai 5 3 2 kolkata 2 2 1 chennai ...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
abhayneilam
Hi I have a field called "src_file_name" in which I have only four values as follows: evaluation vehicle policy wor...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
freephoneid
Hi, I've following entry in my savedsearches.conf: [My_Summary_Query] action.email.inline = 1 action.email.reportSe...
by freephoneid Path Finder in Splunk Search 10-25-2012
0 5
0
5
ericp56
Hello, Let me provide an explanation of what I am trying to do: Here are some log entries. I put the field names a...
by ericp56 Explorer in Splunk Search 10-25-2012
0 2
0
2
jbat
The following produces a count of 0 for "Other": |stats count AS Contacts, count(eval((in_value=1 AND duratio...
by jbat Engager in Splunk Search 10-25-2012
0 3
0
3
nowakdaw
Hello All, I am wondering if anyone knows if Splunk, or a splunk app can accomplish customizing your table. For e...
by nowakdaw Path Finder in Splunk Search 10-25-2012
0 4
0
4
abhayneilam
Hi, I have a file which contains few fields which are '|' separated, Now I have certain values in file which looks l...
by abhayneilam Contributor in Splunk Search 10-25-2012
0 2
0
2
rakesh_498115
HI.. can i replace the _raw data value with my default data value only for the display purpose only ??
by rakesh_498115 Motivator in Splunk Search 10-25-2012
0 4
0
4
JelianeL
| eval totalCount = cCounter + lCounter | eventstats max(totalCount) as maxTotal | table id, time, message, cCoun...
by JelianeL Explorer in Splunk Search 10-24-2012
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...