Splunk Search

Splunk Search
Community Activity
hbazan
Hi there, We need to know when is the first occurrence of a certain value, and show a list of items that appeared las...
by hbazan Path Finder in Splunk Search 05-23-2011
0 6
0
6
DotTest37
Im extracting values on a field with this Reg ex: <technology[^>]*>(?P<Technology>[^<]+) It returns different valu...
by DotTest37 Path Finder in Splunk Search 05-23-2011
0 2
0
2
DotTest37
I have an Automatic Lookup working just fine. Some of the values Im matching doesn't exist yet on the CSV table (they...
by DotTest37 Path Finder in Splunk Search 05-23-2011
1 1
1
1
marendra
Hi All, I need to match two value from different logs but same field name. How can I do that? Example I have Ironpor...
by marendra Explorer in Splunk Search 05-23-2011
0 2
0
2
tkadale
I have shown time-chart for 2 fields. The Query is as follows: timechart max(input_error) , max(output_error) by ho...
by tkadale Path Finder in Splunk Search 05-22-2011
2 2
2
2
jblaine
I'm having no success making sense of lookups. Some work, some don't, and I can't figure out why. Let's take an obv...
by jblaine Explorer in Splunk Search 05-22-2011
0 4
0
4
mwtimken
When I attempt to run the searches "Cisco Firewall - Denies Over Last 24 Hours" or "Cisco Firewall - Accepts Over Las...
by mwtimken New Member in Splunk Search 05-21-2011
0 2
0
2
zsimic
My accept rate stays at 0% even though I have 3 out of 5 questions where I accepted an answer. Looks like there's a b...
by zsimic Path Finder in Splunk Search 05-21-2011
2 2
2
2
tedder
These searches: index=foo | delta a as a_delta | where a_delta < 0 index=foo | delta b as b_delta | where b_d...
by tedder Communicator in Splunk Search 05-20-2011
0 1
0
1
DTERM
I have a splunk instance with many serviceName's in the logs. Is there a query where I can extract the top 15 of each...
by DTERM Contributor in Splunk Search 05-20-2011
0 2
0
2
msarro
Hey everyone. We have a number of different sources. Each needs to be correlated with the others using either an ingr...
by msarro Builder in Splunk Search 05-20-2011
0 1
0
1
alexiri
I used to have an index-time field extraction on one of my source types in order to get the error code of the message...
by alexiri Communicator in Splunk Search 05-20-2011
0 4
0
4
pmr
Need some help on search string to calculate 10 minute average and generate alert. say for example Virtual memory usa...
by pmr Explorer in Splunk Search 05-20-2011
0 3
0
3
phoenixdigital
Hi All, I understand that real time charting works on data as it arrives so you will not see anything on the chart u...
by phoenixdigital Builder in Splunk Search 05-19-2011
2 4
2
4
zsimic
How to search for a whole word? I try searching for something like "something", but I get matches for many things sta...
by zsimic Path Finder in Splunk Search 05-19-2011
1 2
1
2
msarro
Hey everyone. I am working on trying to assemble a regular expression to pull fields out of a set of CSV files. The i...
by msarro Builder in Splunk Search 05-19-2011
0 11
0
11
DTERM
index="named" 'earliest="@d-1h latest=@d+11'" I'm trying to get all events that happened yesterday between 11 AM and...
by DTERM Contributor in Splunk Search 05-19-2011
1 1
1
1
williamsweat
Hello, Is there a way to create an index alert based on when the last event was received? I see the values I want t...
by williamsweat Path Finder in Splunk Search 05-19-2011
0 4
0
4
splunkrags
Hi, I have a continuous stream of response times for a given service. A fraction of these responses can be very hig...
by splunkrags Engager in Splunk Search 05-19-2011
0 1
0
1
phoenixdigital
So I have created some single values and gauges which I hope to update with live data. However they dont seem to upda...
by phoenixdigital Builder in Splunk Search 05-19-2011
0 6
0
6
torustad
In the logfile (server.log from GlassFish): [#|2011-05-16T17:13:37.622+0200|WARNING|glassfish3.0.1|javax.enterprise....
by torustad Path Finder in Splunk Search 05-19-2011
1 4
1
4
aymericbrun
Hi, How can i login into MS-DOS to make a search ? I wrote in a DOS window: splunk.exe search 'host="..."' -maxout...
by aymericbrun Explorer in Splunk Search 05-19-2011
1 2
1
2
rgcox1
I'm trying to make a search that finds failed WindowsUpdate events that do not have a corresponding successful event....
by rgcox1 Communicator in Splunk Search 05-18-2011
0 3
0
3
torustad
In the loggfile: [#|2011-05-18T11:03:35.375+0200|SEVERE|sun-appserver2.1|com.sun.xml.ws.server.sei.EndpointMethodHan...
by torustad Path Finder in Splunk Search 05-18-2011
1 1
1
1
westneat
I'm running into an issue where I'm unable to run searches from the searches and reports drop down because the name o...
by westneat New Member in Splunk Search 05-18-2011
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...