Splunk Search

Splunk Search
Community Activity
Blu3fish
I've been trying to determine the # of free dhcp leases. I can calculate the total current leases with: index=os ho...
by Blu3fish Path Finder in Splunk Search 08-25-2011
1 4
1
4
zdavitiani_splu
I have a search that returns number of apache processes per host: sourcetype="ps" earliest="-7m" | multikv filter ap...
by zdavitiani_splu Splunk Employee Splunk Employee in Splunk Search 08-25-2011
4 2
4
2
jkfritcher
Greetings, I have inherited a Splunk 4.1 infrastructure and while I am getting up to speed on Splunk, I need assista...
by jkfritcher Engager in Splunk Search 08-25-2011
0 2
0
2
msarro
Hey everyone. The source files I am currently working with each contain a large amount of records. The problem is the...
by msarro Builder in Splunk Search 08-25-2011
0 4
0
4
tailesley
HI, I try to define a field name using the below statement in the search column, however I do not get this filed sto...
by tailesley New Member in Splunk Search 08-24-2011
0 1
0
1
desi
I have two files test1.csv and test2.csv. I indexed them in Splunk and then use them as lookup. These two files are r...
by desi New Member in Splunk Search 08-24-2011
0 1
0
1
sf_user_199
I have some data that looks like this: priority=INFO thread= location= line= field1=OK,field2=OK,field3=OK....fie...
by sf_user_199 Path Finder in Splunk Search 08-24-2011
1 3
1
3
David
I've something of a challenge: How to best generate a single event in a summary index that is based on a transaction ...
by David Splunk Employee Splunk Employee in Splunk Search 08-23-2011
0 11
0
11
jduraes
Hi all, I may be going at this in the completely wrong way, but I'm looking at extracting information from traps sen...
by jduraes Explorer in Splunk Search 08-23-2011
1 5
1
5
desi
Hello, i am trying to run add oneshot from cli but keep getting following error: C:\Program Files\Splunk\bin>splunk ...
by desi New Member in Splunk Search 08-23-2011
0 2
0
2
houxiaoxiao
EventsViewers doesn't support Drilldown. How can modify default click actions? If I click on a segmentation, I would ...
by houxiaoxiao Engager in Splunk Search 08-23-2011
0 1
0
1
noahzstahl
Hello everyone. The scenario: I create a saved search using Splunk webI want to use the search to populate a lookup...
by noahzstahl Engager in Splunk Search 08-23-2011
0 2
0
2
tailesley
HI, Im very new to Splunk, i still learning to get splunk work to provide a high level report to the management to r...
by tailesley New Member in Splunk Search 08-23-2011
0 1
0
1
agthurber
I'm was missing something really simple when trying to set up a new datasource, so i put these steps together as i fo...
by agthurber Explorer in Splunk Search 08-22-2011
7 1
7
1
dang
I'm creating a simple table to show the success rate of an event. I've got the following statement in my splunk sear...
by dang Path Finder in Splunk Search 08-22-2011
0 3
0
3
matze4matze
Hi everyone, I got three Dashboards to list my different sourcetypes. ALL, test, production ALL: | metadata type=s...
by matze4matze Engager in Splunk Search 08-22-2011
0 1
0
1
wtanaka
How can I calculate a graph where: For each point plotted on the graph, the y-axis is a count of the number of disti...
by wtanaka Explorer in Splunk Search 08-19-2011
0 2
0
2
wtanaka
I have a log where each event can be given a boolean field with: | eval myfield=case(n > 0, "A", n=0, "B") So some ...
by wtanaka Explorer in Splunk Search 08-19-2011
2 2
2
2
mikeely
We've got an XML file that is being parsed correctly (and easily - just piped into xmlkv) but one of the fields is nu...
by mikeely Path Finder in Splunk Search 08-19-2011
0 2
0
2
timbCFCA
How can I format the output from a Splunk query? For example I have three fields extracted, A, B, C. I'd like to out...
by timbCFCA Path Finder in Splunk Search 08-19-2011
0 3
0
3
samiomer
Hello, I was wondering if it's possible to schedule a search to run in increments less than 1 minute? Thanks
by samiomer Path Finder in Splunk Search 08-18-2011
2 3
2
3
jcrensh
All, I have a search that is looking for two specific events. One is for new 2008 OS's and up, the other is 2003 OS...
by jcrensh Explorer in Splunk Search 08-18-2011
0 1
0
1
mw
I have a field like this: ... group="Group One,Group2,Some Other Group" ... Using 'makemv delim="," group' is eas...
by mw Splunk Employee Splunk Employee in Splunk Search 08-18-2011
0 4
0
4
Marinus
If I use the metadata command it only gives me keys for the main index, can I call it for other indexes? For example ...
by Marinus Communicator in Splunk Search 08-18-2011
0 2
0
2
DTERM
I have the following two queries: index=MyApp earliest=-30d@d-2h latest=-1d@d+10h | bucket _time span=24h | stats su...
by DTERM Contributor in Splunk Search 08-17-2011
1 6
1
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...