Splunk Search

Splunk Search
Community Activity
cphair
I am looking at maximum processor usage by specific processes on a group of clients. By using stats max on my data (...
by cphair Builder in Splunk Search 06-07-2012
0 4
0
4
LauraBre
Hello, I want to create a line chart with the number of D2T, number of T2D,... On the same chart, I want to have a l...
by LauraBre Communicator in Splunk Search 06-07-2012
0 3
0
3
attgjh1
EDIT1: ive tweaked my regex abit. now i can extract the 'optional' fields i want. but im stumped at this particular l...
by attgjh1 Communicator in Splunk Search 06-06-2012
0 4
0
4
howyagoin
Hi, Looking for tips/hints on the best way to extract a value from a sub-search, including the timestamp that the is...
by howyagoin Contributor in Splunk Search 06-06-2012
0 1
0
1
rakesh_498115
Hi.. My search query displays the search results in the form of a table like this... SearchParameter A B C D E...
by rakesh_498115 Motivator in Splunk Search 06-06-2012
0 10
0
10
khhenderson
I am unfamiliar with regex. I need to separate every field in the _raw data from this line. 06/06 12:46:17 metrics L...
by khhenderson Path Finder in Splunk Search 06-06-2012
0 5
0
5
annebeate
Hi, After upgrading splunk forwarder from version 4.2.1 to 4.3.1, the Splunk indexer does not receive any data. The ...
by annebeate Path Finder in Splunk Search 06-06-2012
2 3
2
3
jangid
My log file is similar to below and search is I0530 14:28:10.394402 29432 tafc_logger_c.cpp:42] demoprogram.b:9 [ma...
by jangid Builder in Splunk Search 06-06-2012
0 6
0
6
khhenderson
This is kind of a newbie question. I found the iplocation command and have had some success with it but. The searche...
by khhenderson Path Finder in Splunk Search 06-06-2012
0 1
0
1
jangid
Simple question - I don't want to display all lines starts with "E or I or W or F" what's wrong with above regular ex...
by jangid Builder in Splunk Search 06-06-2012
0 1
0
1
fuster_j
I'm looking for the regex for extracted fields in a custom built app. I cannot find them in any props.conf and trans...
by fuster_j Path Finder in Splunk Search 06-06-2012
0 2
0
2
iamniks
Hi, i am using the below search command in a splunk view as given below. index=re sourcetype="clearcase_Log" "Troub...
by iamniks Explorer in Splunk Search 06-06-2012
0 8
0
8
asarolkar
I have a log entry that looks like this 2009-10-02 16:52:30 To USA-XXX F 2 &STR where XXX is the account number - I...
by asarolkar Builder in Splunk Search 06-05-2012
0 2
0
2
elenzil
hm, my question seems very similar to this one: http://bit.ly/M4yZl2 , but differs in the details. i have an extant ...
by elenzil Path Finder in Splunk Search 06-05-2012
0 2
0
2
fuster_j
I'm having problem extracting field below. I'm trying to extract "count_r5=" but the Interactive Field Exaction is g...
by fuster_j Path Finder in Splunk Search 06-05-2012
0 2
0
2
terryloar
I'm charting some events BY Host which gives me the correct counts for each host. I would like to also display a "% T...
by terryloar Path Finder in Splunk Search 06-05-2012
0 2
0
2
nebel
Hi there, I want to avoid to copy via scp files on my cloudsearch for using them in lookups. Is it possible to creat...
by nebel Communicator in Splunk Search 06-05-2012
0 1
0
1
rakesh_498115
Hi I have created 21 eventypes for my requirement.In tat 21 eventypes when i write a query only few eventtypes are ...
by rakesh_498115 Motivator in Splunk Search 06-05-2012
0 2
0
2
attgjh1
A sample sequence of my log goes something like this 07/03/2011 15:26,07/03/2011 15:26,...,... Refresh Process is st...
by attgjh1 Communicator in Splunk Search 06-04-2012
0 5
0
5
a212830
Hi, How would I chart a percentage of values? I want to count the number of events that match a criteria, and then d...
by a212830 Champion in Splunk Search 06-04-2012
1 4
1
4
tyronetv
I have to identical servers. One acts as an indexing server and one as a user access search portal. I am constantly...
by tyronetv Communicator in Splunk Search 06-04-2012
1 2
1
2
BryanBerry
This is really tricky to explain, so please bear with me. I'm open to different display approaches, so if you disagre...
by BryanBerry Path Finder in Splunk Search 06-04-2012
1 4
1
4
Jason
I have a bunch of events bunched into transactions, and I am trying to use the latest (time-wise) value of a field, s...
by Jason Motivator in Splunk Search 06-04-2012
1 3
1
3
elenzil
this one is a bit off the wall. is there a variable i can use that represents the time range currently selected in t...
by elenzil Path Finder in Splunk Search 06-04-2012
3 5
3
5
Jason
Is the number of events reported as totalCount in | metadata... the lifetime running total of the events for that (s...
by Jason Motivator in Splunk Search 06-04-2012
1 3
1
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors