Splunk Search

Splunk Search
Community Activity
Lowell
I would like to be able to create a custom search command that uses an eval-expression as an argument. (Similar to ...
by Lowell Super Champion in Splunk Search 11-14-2011
2 5
2
5
cpuppet
is there anyways to show a whole month of graph with a time span of 5 min window splunk has reduce the chart to 4 day...
by cpuppet Path Finder in Splunk Search 11-14-2011
0 5
0
5
Dark_Ichigo
For some reason, Splunk IRC considers me to be a Spam? No matter what I do it seems to be going back to this conclus...
by Dark_Ichigo Builder in Splunk Search 11-14-2011
0 4
0
4
mrdaniel
I would like to search for a * in my searchresult, more specific i would like to get all entries that is "select *" t...
by mrdaniel Explorer in Splunk Search 11-13-2011
1 1
1
1
Starlette
Is there a smart way to list field values as input without rendering the events? Example : I want to list the hosts ...
by Starlette Contributor in Splunk Search 11-12-2011
1 3
1
3
chris
I'm not sure if this is the right way to do what I want, but we are trying to build dashboards for users that look at...
by chris Motivator in Splunk Search 11-12-2011
2 1
2
1
LCM
Hi all, A though one for me, but maybe an easy one for you! I want to count error messages and show it in a table pe...
by LCM Contributor in Splunk Search 11-11-2011
0 1
0
1
timbCFCA
I'm attempting to map when the count of two event IDs - 4634 and 4624 is different over a time period. These events c...
by timbCFCA Path Finder in Splunk Search 11-11-2011
0 2
0
2
bfernandez
I am trying to extract some data from a script output. Sample: SERVICE_NAME: WebTrends - Data Retention Service DISPL...
by bfernandez Communicator in Splunk Search 11-11-2011
0 2
0
2
khyoung7410
Hi In timechart, how to Search for the values >n ? (ex) search : weblog " * | strcat clientip "@" uri A_COMBO | ti...
by khyoung7410 Communicator in Splunk Search 11-11-2011
0 2
0
2
keshab
search SessionID="*" | stats range(_time) AS Session_Duration_sec by SessionID I got the each session duration using...
by keshab Path Finder in Splunk Search 11-11-2011
1 2
1
2
mchan
Newbie to splunk, but I want to aggregate the log entries below based upon if it's the same ip address and request ur...
by mchan New Member in Splunk Search 11-10-2011
0 2
0
2
lpolo
I have the following log: 01/02/2011:00:00:01 q=UP 01/02/2011:00:00:02 q=UP A 01/02/2011:00:00:03 q=UP AL 01/02/2...
by lpolo Motivator in Splunk Search 11-10-2011
0 10
0
10
mcbradford
I have a dashboard with a few table views. I want the first event to be the most recent event (so sort by most recen...
by mcbradford Contributor in Splunk Search 11-10-2011
0 5
0
5
adityapavan18
Hi Is it possible to find the Average of only the best 50% transactions(i.e top 50% of less transaction times). I c...
by adityapavan18 Contributor in Splunk Search 11-10-2011
0 5
0
5
tven7
index=tbb sourcetype=tbb_server "No UserSession exists with the primary key" |eval delta=_time/3|stats count as erro...
by tven7 Path Finder in Splunk Search 11-10-2011
1 1
1
1
xiaoyuew
i have create a dashboard with multiple views on it, i would like to navigate them through the hyperlinks, so when i ...
by xiaoyuew Path Finder in Splunk Search 11-10-2011
0 1
0
1
tdnguyen1
Hi, I am new two splunk. I am wondering is there a way to calculate the delta of RXdropped from 5 minutes apart. 10...
by tdnguyen1 Explorer in Splunk Search 11-09-2011
1 5
1
5
Sqig
Hi. I have a need to include the start and end of the searched-for time range in the search results themselves. Ulti...
by Sqig Path Finder in Splunk Search 11-09-2011
0 2
0
2
steveirogers
I am running Splunk 4.2.3. I have a directory called "/var/log/atpco" which contains numerous log files. I have play...
by steveirogers Communicator in Splunk Search 11-09-2011
0 4
0
4
asingla
I am using dedup in my search and my time criteria is real time. The events are coming every minute but the results a...
by asingla Communicator in Splunk Search 11-09-2011
0 1
0
1
royhvaara
in inputs.conf: [tcp://:9995] connection_host = dns sourcetype = tcp:9995 source = tcp:9995 in props.conf: [sourc...
by royhvaara Engager in Splunk Search 11-09-2011
0 1
0
1
joejag
I would like to organise my saved searches into subfolders in the drop down on the search app. I noticed that the "E...
by joejag New Member in Splunk Search 11-09-2011
0 3
0
3
TheMarkHodgkins
Pardon my newbie'ness  Does anyone have an example where Search results are matched to table entries (simple CSV sh...
by TheMarkHodgkins Explorer in Splunk Search 11-09-2011
0 1
0
1
gooza
Hi, I'd like to add knowledge to our splunk data and divide ips or computers to different groups like test/productio...
by gooza Communicator in Splunk Search 11-08-2011
1 4
1
4
Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...