Splunk Search

Splunk Search
Community Activity
nosignal
Hi. I'm new to Splunk. I've got basic import and searching working on the windows install, but I want to get the fiel...
by nosignal Explorer in Splunk Search 10-29-2012
0 1
0
1
abhayneilam
I have 2 keywords and I am running query : index="maa" | table Name Age Location | rex field="Location" (?(?i)"kol")...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 9
0
9
abhayneilam
index="usb_weekly_data" |rex field="src_file_name" (?(?i)"presentation") | stats count as First by key_word above qu...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 2
0
2
jangid
I want to create a bar chart with these following search eventtype="et_system_metrics" Stage=A* | stats count(eval...
by jangid Builder in Splunk Search 10-29-2012
0 6
0
6
jangid
What is the wrong in this sub search ? Individually both are working fine. eventtype="et_system_metrics" Stage=A* A...
by jangid Builder in Splunk Search 10-29-2012
0 4
0
4
MuS
Dear Doc Team, if one uses the link to Answers on top of the docs.splunk.com page, you end up at docs.splunk.com/Ans...
by SplunkTrust SplunkTrust in Splunk Search 10-29-2012
5 1
5
1
abhayneilam
I am giving the following search : index="maa" | table Name Age Location | rex field="Location" (?(?i)"delhi") | eva...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 10
0
10
abhayneilam
Hi, I have a query as follows : index="maa" |rex field="Location" (?(?i)"delhi") | eval ONE=lower(ONE) |stats count...
by abhayneilam Contributor in Splunk Search 10-29-2012
0 3
0
3
gohar
Related to http://splunk-base.splunk.com/answers/7581/best-way-to-search-using-a-lookup-table I want this inverse sc...
by gohar Explorer in Splunk Search 10-27-2012
1 2
1
2
abhayneilam
Hi, I am running the below query and want to print 0 for the keyword that is not matched , can this be possible to g...
by abhayneilam Contributor in Splunk Search 10-27-2012
0 2
0
2
hirsts
I have a challenge that I'm hoping someone can help with. There are around 24,000,000 events being indexed per 24 ho...
by hirsts Path Finder in Splunk Search 10-26-2012
0 2
0
2
madanashok
Hi, Just have a look at this code < module name="HiddenSearch" layoutPanel="panel_row2_col1" autoRun="True"> <...
by madanashok Path Finder in Splunk Search 10-26-2012
0 2
0
2
johnebgood
Hello, I have logs coming in that look like the following: (Tab between columns) server1.something.com ApacheLog ...
by johnebgood Path Finder in Splunk Search 10-26-2012
1 4
1
4
rakesh_498115
Hi. I have search query that query returns certains fields . these information will vary according to the realtime d...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 2
0
2
dspracklen
My problem with this is that the saved search takes longer than 60 seconds to run, so I only get partial answers if I...
by dspracklen Path Finder in Splunk Search 10-26-2012
1 3
1
3
rakesh_498115
Hi.. I know that the dolloar $ is used for variables . like $a or $b something like this.In splunk i have seen in fe...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 1
0
1
bkcarter
I need to create a transform stanza that will seperate some events depending on which domain they originate from. ...
by bkcarter Path Finder in Splunk Search 10-26-2012
0 1
0
1
giridhar_tm
This is a question on the OData App. I have a search that lists the output as a table, when I save this search and a...
by giridhar_tm Engager in Splunk Search 10-26-2012
1 2
1
2
theouhuios
Hello I am trying to calculate the mean of a field and it's strange that splunk cal the mean in a completely differe...
by theouhuios Motivator in Splunk Search 10-26-2012
0 2
0
2
rakesh_498115
Hi.. I have search query which gives me a ouput of certain fields say A,B,C and we know that splunk has two default ...
by rakesh_498115 Motivator in Splunk Search 10-26-2012
0 4
0
4
henryt1
So I wasn't really sure how to do this after reading the documentation, but I'm running the following search: (host=...
by henryt1 Path Finder in Splunk Search 10-26-2012
0 2
0
2
abhayneilam
I have a report like this : keyword "one" "two" "three" mumbai 5 3 2 kolkata 2 2 1 chennai ...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
abhayneilam
Hi I have a field called "src_file_name" in which I have only four values as follows: evaluation vehicle policy wor...
by abhayneilam Contributor in Splunk Search 10-26-2012
0 3
0
3
freephoneid
Hi, I've following entry in my savedsearches.conf: [My_Summary_Query] action.email.inline = 1 action.email.reportSe...
by freephoneid Path Finder in Splunk Search 10-25-2012
0 5
0
5
ericp56
Hello, Let me provide an explanation of what I am trying to do: Here are some log entries. I put the field names a...
by ericp56 Explorer in Splunk Search 10-25-2012
0 2
0
2
Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...