Splunk Search

Splunk Search
Community Activity
jangid
I have following log in xml format <tec><items><item><name>Status</name><value>Online</value></item><item><name>Comp...
by jangid Builder in Splunk Search 10-30-2012
1 1
1
1
nosignal
Hi. I'm new to Splunk. I've got basic import and searching working on the windows install, but I want to get the fiel...
by nosignal Explorer in Splunk Search 10-29-2012
0 1
0
1
abhayneilam
I have 2 keywords and I am running query : index="maa" | table Name Age Location | rex field="Location" (?(?i)"kol")...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 9
0
9
abhayneilam
index="usb_weekly_data" |rex field="src_file_name" (?(?i)"presentation") | stats count as First by key_word above qu...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 2
0
2
jangid
I want to create a bar chart with these following search eventtype="et_system_metrics" Stage=A* | stats count(eval...
by jangid Builder in Splunk Search 10-29-2012
0 6
0
6
jangid
What is the wrong in this sub search ? Individually both are working fine. eventtype="et_system_metrics" Stage=A* A...
by jangid Builder in Splunk Search 10-29-2012
0 4
0
4
MuS
Dear Doc Team, if one uses the link to Answers on top of the docs.splunk.com page, you end up at docs.splunk.com/Ans...
by SplunkTrust SplunkTrust in Splunk Search 10-29-2012
5 1
5
1
abhayneilam
I am giving the following search : index="maa" | table Name Age Location | rex field="Location" (?(?i)"delhi") | eva...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 10
0
10
abhayneilam
Hi, I have a query as follows : index="maa" |rex field="Location" (?(?i)"delhi") | eval ONE=lower(ONE) |stats count...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 3
0
3
gohar
Related to http://splunk-base.splunk.com/answers/7581/best-way-to-search-using-a-lookup-table I want this inverse sc...
by gohar Explorer in Splunk Search 10-27-2012
1 2
1
2
abhayneilam
Hi, I am running the below query and want to print 0 for the keyword that is not matched , can this be possible to g...
by abhayneilam Contributor in Splunk Search 10-27-2012
0 2
0
2
hirsts
I have a challenge that I'm hoping someone can help with. There are around 24,000,000 events being indexed per 24 ho...
by hirsts Path Finder in Splunk Search 10-26-2012
0 2
0
2
madanashok
Hi, Just have a look at this code < module name="HiddenSearch" layoutPanel="panel_row2_col1" autoRun="True"> <...
by madanashok Path Finder in Splunk Search 10-26-2012
0 2
0
2
johnebgood
Hello, I have logs coming in that look like the following: (Tab between columns) server1.something.com ApacheLog ...
by johnebgood Path Finder in Splunk Search 10-26-2012
1 4
1
4
rakesh_498115
Hi. I have search query that query returns certains fields . these information will vary according to the realtime d...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 2
0
2
dspracklen
My problem with this is that the saved search takes longer than 60 seconds to run, so I only get partial answers if I...
by dspracklen Path Finder in Splunk Search 10-26-2012
1 3
1
3
rakesh_498115
Hi.. I know that the dolloar $ is used for variables . like $a or $b something like this.In splunk i have seen in fe...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 1
0
1
bkcarter
I need to create a transform stanza that will seperate some events depending on which domain they originate from. ...
by bkcarter Path Finder in Splunk Search 10-26-2012
0 1
0
1
giridhar_tm
This is a question on the OData App. I have a search that lists the output as a table, when I save this search and a...
by giridhar_tm Engager in Splunk Search 10-26-2012
1 2
1
2
theouhuios
Hello I am trying to calculate the mean of a field and it's strange that splunk cal the mean in a completely differe...
by theouhuios Motivator in Splunk Search 10-26-2012
0 2
0
2
rakesh_498115
Hi.. I have search query which gives me a ouput of certain fields say A,B,C and we know that splunk has two default ...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 4
0
4
henryt1
So I wasn't really sure how to do this after reading the documentation, but I'm running the following search: (host=...
by henryt1 Path Finder in Splunk Search 10-26-2012
0 2
0
2
abhayneilam
I have a report like this : keyword "one" "two" "three" mumbai 5 3 2 kolkata 2 2 1 chennai ...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
abhayneilam
Hi I have a field called "src_file_name" in which I have only four values as follows: evaluation vehicle policy wor...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
freephoneid
Hi, I've following entry in my savedsearches.conf: [My_Summary_Query] action.email.inline = 1 action.email.reportSe...
by freephoneid Path Finder in Splunk Search 10-25-2012
0 5
0
5
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...