Splunk Search

Splunk Search
Community Activity
sideview
I have an interesting situation where I want to be able to display a little summary table, showing a few statistics ...
by SplunkTrust SplunkTrust in Splunk Search 04-14-2012
0 2
0
2
subhadipc
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by subhadipc Explorer in Splunk Search 04-13-2012
0 3
0
3
mikefoti
The query below displays accurate values for Requests, Accepted, Rejected and %Accepted. | stats count(eval(nps_pac...
by mikefoti Communicator in Splunk Search 04-13-2012
0 10
0
10
anssntaco
When running a timechart over the last 7 days, using span=10m, the timechart will only display roughly the first 3.5...
by anssntaco Path Finder in Splunk Search 04-13-2012
0 1
0
1
nebel
Hi Splunkers, I need the result from first search in another search. First search: sourcetype=win_server | multikv ...
by nebel Communicator in Splunk Search 04-13-2012
0 3
0
3
jgauthier
Ugh! I hate having to ask for query help, but I'm close.. but not close enough. Basically, I have two sets of data....
by jgauthier Contributor in Splunk Search 04-13-2012
0 8
0
8
C4r7m4n
Hello, Does anybody know how to write a search that find events occur at least one per day and these events count as...
by C4r7m4n Path Finder in Splunk Search 04-12-2012
1 9
1
9
ironhalo
We had an event on our splunk server, and there's a gap in some of the logs. The logs are continually written to on ...
by ironhalo Explorer in Splunk Search 04-12-2012
0 1
0
1
tven
<Product> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> </Pro...
by tven Explorer in Splunk Search 04-12-2012
0 1
0
1
rachelneal
I have a rex that returns a series of 5-8 digit IDs: SEARCH "rex field=_raw "2012-\d\d-\d\d,\d,(?\d{1,8})"" RESULT ...
by rachelneal Path Finder in Splunk Search 04-12-2012
1 3
1
3
subhadipc
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by subhadipc Explorer in Splunk Search 04-12-2012
1 1
1
1
dominiquevocat
I am trying to report the number of unique logged in users (field=USERNAME) in a timespan=1h and since i only want un...
by SplunkTrust SplunkTrust in Splunk Search 04-12-2012
0 2
0
2
C4r7m4n
Hello I have two searches: Search A: BGP_NEIGHBOR_STATE_CHANGED source="udp:514" AND ("Established to Idle" OR "Est...
by C4r7m4n Path Finder in Splunk Search 04-12-2012
0 6
0
6
NK_1
I would like to associate the "ip" field with every log line, i.e. Current source log format: 1227.125106.091263 ip...
by NK_1 Path Finder in Splunk Search 04-11-2012
0 2
0
2
boris
What does the regex in my question's title above mean? Source: Search Language Quick Reference Card (on top of page ...
by boris Path Finder in Splunk Search 04-11-2012
0 1
0
1
gregwilliams
I'm trying to return a field based upon a search and within that search extract a variable to search for in another s...
by gregwilliams Path Finder in Splunk Search 04-11-2012
0 5
0
5
lmyoung
I am trying to get the number of denied connections from squid proxy logs from a Cisco Ironport web security applianc...
by lmyoung Engager in Splunk Search 04-11-2012
1 1
1
1
tb582
Hopufully a quick one but I'm looking to search and extract anything between two these fields anyone know how?
by tb582 Explorer in Splunk Search 04-11-2012
0 18
0
18
Sriram
Is there a way to show the status of search jobs while the search is in progress. I have a dashboard with multiple se...
by Sriram Communicator in Splunk Search 04-10-2012
0 8
0
8
sberg
First time posting! --using splunk 4.2.4-- I noticed similar questions on here that were either unanswered or didn't...
by sberg Explorer in Splunk Search 04-10-2012
0 5
0
5
kevinsikora
I'm trying to add search servers to my search head. I'm using the following command: ./splunk add search-server -hos...
by kevinsikora Explorer in Splunk Search 04-10-2012
1 3
1
3
msarro
Hey everyone. Is anyone using Nagios to monitor their splunk instance? I've seen that there was a check_splunk plugin...
by msarro Builder in Splunk Search 04-10-2012
1 2
1
2
sonicZ
I have a lookup on sourcetype=vipservices csv file has values like so jurhash, jurhasfriendlyname somehashvalue, som...
by sonicZ Contributor in Splunk Search 04-10-2012
0 3
0
3
acdevlin
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by acdevlin Communicator in Splunk Search 04-10-2012
2 6
2
6
vbumgarner
I'm using transaction ... | search duration>x to eliminate some noise, but then I want to break the events back ou...
by vbumgarner Contributor in Splunk Search 04-10-2012
6 3
6
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...