Splunk Search

Splunk Search
Community Activity
erick_costa
I want to do the SQL in Splunk: SELECT TB1.* FROM TB1 JOIN TB2 ON TB2.ID = TB1.ID WHERE TB2.OPTION = "OPTION 1" ...
by erick_costa Path Finder in Splunk Search 08-07-2012
0 4
0
4
gnovak
I can't seem to figure this one out. I have a line in a log like this: 2012-08-07 12:35:49,138 [http-10.40.231.33-4...
by gnovak Builder in Splunk Search 08-07-2012
0 7
0
7
Michael_Schyma1
Is there a way to group several eventcodes so I dont have to keep on repeating myself. I can not seem to get the righ...
by Michael_Schyma1 Contributor in Splunk Search 08-07-2012
0 1
0
1
matthewcanty
http://splunk-base.splunk.com/answers/49712/can-we-sort-command-for-sorting-the-table-records-rowwise Hi All, I hav...
by matthewcanty Communicator in Splunk Search 08-07-2012
0 4
0
4
bckq
I've upgraded my Splunk from version 4.3 to version 4.3.3 and my dashboard view has changed. This is version from 4....
by bckq Path Finder in Splunk Search 08-06-2012
0 1
0
1
DTERM
I need a query that will provide the average duration of tickets for severity levels 0-4. The individual ticket dura...
by DTERM Contributor in Splunk Search 08-06-2012
0 8
0
8
rmcdougal
I am attempting to write a license usage search and I would like to be able to see the usage for the last 7 days. He...
by rmcdougal Path Finder in Splunk Search 08-06-2012
0 1
0
1
wsw70
Hello, Still trying to find a way to manage false positives in a search, I am leaning more and more towards an exte...
by wsw70 Communicator in Splunk Search 08-06-2012
1 3
1
3
bckq
Hi. I have two field Single Value. First is using search: source="/var/log/online-alerts_splunk2.log" online_aname="...
by bckq Path Finder in Splunk Search 08-06-2012
3 6
3
6
Michael_Schyma1
I am trying to extract the privileges that are listed below, but i do not seem to be having luck with the rex that I ...
by Michael_Schyma1 Contributor in Splunk Search 08-06-2012
0 1
0
1
misteryuku
I opened up the splunk search app and added this splunk search command : sourcetype="addedfields" wrap | delete The...
by misteryuku Communicator in Splunk Search 08-06-2012
5 9
5
9
Branden
I'm wondering if someone can provide me with a suggestion on how to handle this (probably straight-forward) scenario....
by Branden Builder in Splunk Search 08-06-2012
0 2
0
2
vbumgarner
Given an event something like: x|y,x1|y1 and an extraction that gives you the multi-valued fields a&b, effectively...
by vbumgarner Contributor in Splunk Search 08-06-2012
1 2
1
2
nirt
Hi All, I have a website which produces statistics and it is shown like this(over 1K lines, so just pasting a few) Ea...
by nirt Path Finder in Splunk Search 08-06-2012
0 4
0
4
anderswesterber
Hi, first time trying to join several logsources in Splunk and it's been a nightmare ;)! Use-case: I got one logsour...
by anderswesterber New Member in Splunk Search 08-06-2012
0 5
0
5
howelsmovingcas
I am looking to create a simple multiline graph from the following logs: Hostname=host1 cpu_percentage=X etc.. Hostn...
by howelsmovingcas New Member in Splunk Search 08-05-2012
0 1
0
1
aaronnicoli
Hi all, I've been working for the last week or two with content keeper logs, they're csv based and contain the follo...
by aaronnicoli Path Finder in Splunk Search 08-05-2012
1 4
1
4
kenchisho
I am trying to build a working hours report with splunk... I have a start date and an end date like so: start_time ...
by kenchisho Path Finder in Splunk Search 08-05-2012
0 3
0
3
bjalex80
I have a user who has created a lookup table and given it app-level permissions. Now the same user wants to add new ...
by bjalex80 Explorer in Splunk Search 08-03-2012
0 1
0
1
LordVoldemort
Another question about getting things to come out in a table. That seems to be my biggest stumbling point with splunk...
by LordVoldemort Explorer in Splunk Search 08-03-2012
0 2
0
2
aniketb
I'm working on a report that uses lot of fields. I would be extracting those fields across many sourcetypes. I have m...
by aniketb Path Finder in Splunk Search 08-03-2012
0 2
0
2
AntonioM
Hello All, I was wondering how is the duration field in the Transaction Command calculated? Is it based on each even...
by AntonioM Explorer in Splunk Search 08-03-2012
0 3
0
3
ytl
i have numerous eventtypes defined and in many cases a logging event may have several eventtypes associated with it. ...
by ytl Path Finder in Splunk Search 08-03-2012
1 5
1
5
crazyeva
There are "date-time" fields other than _time in events: ...^2012/06/30 23:58:20^2012/06/30 23:58:20... we pre extrac...
by crazyeva Contributor in Splunk Search 08-03-2012
0 4
0
4
clyde772
I realize that Splunk creates indexes for lookup tables. Can Splunk really create indexes to maximize lookup perform...
by clyde772 Communicator in Splunk Search 08-02-2012
0 1
0
1
Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...