Splunk Search

Splunk Search
Community Activity
msarro
Hey everyone, I am trying to get a rex written that will suck out a few key items from data that I'm taking into splu...
by msarro Builder in Splunk Search 04-07-2011
0 3
0
3
jgauthier
All, I am correlating two non-related data types. Email to ERP Customers. I am going to accomplish this by referen...
by jgauthier Contributor in Splunk Search 04-07-2011
0 1
0
1
jason_hubbard
I have tried creating a Search macro with a stats command and *any* of the stats arguments return with an "Error in '...
by jason_hubbard Path Finder in Splunk Search 04-07-2011
0 4
0
4
kevintelford
We used to have a dashboard driven by a simple query that would show a value per hour for all of our index servers. ...
by kevintelford Path Finder in Splunk Search 04-07-2011
0 2
0
2
cafissimo
Hello, please, I would like to know why, for a search head that is on top of two splunk indexers indexing 300 gb/day ...
by cafissimo Communicator in Splunk Search 04-07-2011
2 2
2
2
arapozo
In windows events on a lot of cases you get a result code from them in hex notation, then you have to look them up an...
by arapozo Explorer in Splunk Search 04-07-2011
1 3
1
3
seanlon11
I have the following query: host=wps03 mc_getLDAPGroupsTimer | table time host username mc_getLDAPGroupsTimer | sor...
by seanlon11 Path Finder in Splunk Search 04-07-2011
5 2
5
2
jgauthier
I am running a search like so: sourcetype="stuff here" | timechart span=1h sum(bytes) as Total by limit=10 username ...
by jgauthier Contributor in Splunk Search 04-07-2011
1 2
1
2
ytl
i'm trying to generate a search where i can summarize its info into a table. specifically i'm trying to detect link f...
by ytl Path Finder in Splunk Search 04-07-2011
0 3
0
3
williamsweat
Hello, I'm trying to use collect and the subsequent stash file to save time on a large search query. The documentat...
by williamsweat Path Finder in Splunk Search 04-07-2011
1 5
1
5
ytl
i have a longish regex to weed out pertinent fields from some asa output. they generally follow the same format, howe...
by ytl Path Finder in Splunk Search 04-06-2011
0 1
0
1
williamsweat
... and can I change the character length or is it hard-coded? Thanks
by williamsweat Path Finder in Splunk Search 04-06-2011
1 4
1
4
simuvid
Hi folks, I have following search param in a HiddenSearch: <param name="search">index="overall" src_ip="*" si...
by simuvid Splunk Employee Splunk Employee in Splunk Search 04-06-2011
0 1
0
1
Ossian
I'm rather new to Splunk. One of the things I have been tasked with is the tracking of API commands sent in URLs to u...
by Ossian Explorer in Splunk Search 04-06-2011
2 4
2
4
pugnacity
hi, currently we use as a central syslog server with logcheck. every hour the server will generate a mail with messa...
by pugnacity New Member in Splunk Search 04-06-2011
0 2
0
2
1dbenzo
What file would you edit to extract that field automatically in the future?
by 1dbenzo Explorer in Splunk Search 04-06-2011
0 1
0
1
sideview
So I have a dashboard and I want to display the most recent value of fieldA, for each value of fieldB and fieldC, sh...
by SplunkTrust SplunkTrust in Splunk Search 04-06-2011
0 4
0
4
1dbenzo
Can anybody explain to me how 'transaction' command works in a step by step written format?
by 1dbenzo Explorer in Splunk Search 04-06-2011
0 1
0
1
1dbenzo
How do you perform a field extraction on the fly in Splunk?
by 1dbenzo Explorer in Splunk Search 04-06-2011
0 1
0
1
ualbanytech
Where index retirement policies are concerned, if you define both size and age I assume first policy type hit wins?
by ualbanytech Path Finder in Splunk Search 04-05-2011
0 4
0
4
mctester
We need advice on setting up search head(s). We have set up a distributed search system with 12 indexers and 2 search...
by mctester Communicator in Splunk Search 04-05-2011
1 6
1
6
kochera
Hi, I would like to combine two searches. The first one gives me the session-id which i would like to use in a secon...
by kochera Communicator in Splunk Search 04-05-2011
1 6
1
6
beaumaris
What's the best way to retrieve stats from multiple reports in the summary index? We have a remote client that will ...
by beaumaris Communicator in Splunk Search 04-05-2011
1 4
1
4
bcotton
When trying to run a search from a remote CLI instance, I keep getting a 404. The command-line I'm running is: ./sp...
by bcotton Engager in Splunk Search 04-05-2011
1 1
1
1
dang
I'm using timechart to show the number of connections we have over a collection of servers. When these servers go th...
by dang Path Finder in Splunk Search 04-04-2011
1 4
1
4
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...