Splunk Search

Splunk Search
Community Activity
DTERM
I need a query that will provide the average duration of tickets for severity levels 0-4. The individual ticket dura...
by DTERM Contributor in Splunk Search 08-06-2012
0 8
0
8
rmcdougal
I am attempting to write a license usage search and I would like to be able to see the usage for the last 7 days. He...
by rmcdougal Path Finder in Splunk Search 08-06-2012
0 1
0
1
wsw70
Hello, Still trying to find a way to manage false positives in a search, I am leaning more and more towards an exte...
by wsw70 Communicator in Splunk Search 08-06-2012
1 3
1
3
bckq
Hi. I have two field Single Value. First is using search: source="/var/log/online-alerts_splunk2.log" online_aname="...
by bckq Path Finder in Splunk Search 08-06-2012
3 6
3
6
Michael_Schyma1
I am trying to extract the privileges that are listed below, but i do not seem to be having luck with the rex that I ...
by Michael_Schyma1 Contributor in Splunk Search 08-06-2012
0 1
0
1
misteryuku
I opened up the splunk search app and added this splunk search command : sourcetype="addedfields" wrap | delete The...
by misteryuku Communicator in Splunk Search 08-06-2012
5 9
5
9
Branden
I'm wondering if someone can provide me with a suggestion on how to handle this (probably straight-forward) scenario....
by Branden Builder in Splunk Search 08-06-2012
0 2
0
2
vbumgarner
Given an event something like: x|y,x1|y1 and an extraction that gives you the multi-valued fields a&b, effectively...
by vbumgarner Contributor in Splunk Search 08-06-2012
1 2
1
2
nirt
Hi All, I have a website which produces statistics and it is shown like this(over 1K lines, so just pasting a few) Ea...
by nirt Path Finder in Splunk Search 08-06-2012
0 4
0
4
anderswesterber
Hi, first time trying to join several logsources in Splunk and it's been a nightmare ;)! Use-case: I got one logsour...
by anderswesterber New Member in Splunk Search 08-06-2012
0 5
0
5
howelsmovingcas
I am looking to create a simple multiline graph from the following logs: Hostname=host1 cpu_percentage=X etc.. Hostn...
by howelsmovingcas New Member in Splunk Search 08-05-2012
0 1
0
1
aaronnicoli
Hi all, I've been working for the last week or two with content keeper logs, they're csv based and contain the follo...
by aaronnicoli Path Finder in Splunk Search 08-05-2012
1 4
1
4
kenchisho
I am trying to build a working hours report with splunk... I have a start date and an end date like so: start_time ...
by kenchisho Path Finder in Splunk Search 08-05-2012
0 3
0
3
bjalex80
I have a user who has created a lookup table and given it app-level permissions. Now the same user wants to add new ...
by bjalex80 Explorer in Splunk Search 08-03-2012
0 1
0
1
LordVoldemort
Another question about getting things to come out in a table. That seems to be my biggest stumbling point with splunk...
by LordVoldemort Explorer in Splunk Search 08-03-2012
0 2
0
2
aniketb
I'm working on a report that uses lot of fields. I would be extracting those fields across many sourcetypes. I have m...
by aniketb Path Finder in Splunk Search 08-03-2012
0 2
0
2
AntonioM
Hello All, I was wondering how is the duration field in the Transaction Command calculated? Is it based on each even...
by AntonioM Explorer in Splunk Search 08-03-2012
0 3
0
3
ytl
i have numerous eventtypes defined and in many cases a logging event may have several eventtypes associated with it. ...
by ytl Path Finder in Splunk Search 08-03-2012
1 5
1
5
crazyeva
There are "date-time" fields other than _time in events: ...^2012/06/30 23:58:20^2012/06/30 23:58:20... we pre extrac...
by crazyeva Contributor in Splunk Search 08-03-2012
0 4
0
4
clyde772
I realize that Splunk creates indexes for lookup tables. Can Splunk really create indexes to maximize lookup perform...
by clyde772 Communicator in Splunk Search 08-02-2012
0 1
0
1
Marinus
Is it possible to produce a chart like this? A possible data set could be "spending catagories" vs "months"
by Marinus Communicator in Splunk Search 08-02-2012
0 4
0
4
jchampagne
In some of our event logs, the client IP address is recorded with leading information (::ffff:). I would like to tri...
by jchampagne Path Finder in Splunk Search 08-02-2012
0 3
0
3
lancealotx
I have a few queries, dashboards, and now being asked to take it up a notch. We hava a bunch of data points, and I'...
by lancealotx Explorer in Splunk Search 08-02-2012
0 2
0
2
sherman
Hello, I am trying to convert the default time stamp for my events to epoch time, but for that it seems that I have ...
by sherman Engager in Splunk Search 08-02-2012
1 2
1
2
tuxford
Hello I have a chart that works for a time range of 60 minutes and looks like this: sourcetype="access_combined" "*...
by tuxford Path Finder in Splunk Search 08-02-2012
0 5
0
5
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors