Splunk Search

Splunk Search
Community Activity
JYTTEJ
I need to calculate average response time (ELT) by service (SVC) if number of trx by service is >5 within the last 4 ...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 3
0
3
Ant1D
Hey, I want to switch off what seems to be a default function in Splunk. I am trying to drill down on the following...
by Ant1D Motivator in Splunk Search 11-18-2010
0 2
0
2
bojanz
Hi, I'm working on a problem where Splunk is not displaying (sometimes) all indexed events. The problematic index h...
by bojanz Communicator in Splunk Search 11-18-2010
0 2
0
2
axsolis
I am trying to create a field that contains information about the type of host based on the host field. For example,...
by axsolis Path Finder in Splunk Search 11-18-2010
1 4
1
4
JYTTEJ
I have log entries looking as follows: Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47,9...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 2
0
2
snowmizer
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by snowmizer Communicator in Splunk Search 11-18-2010
2 5
2
5
msarro
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by msarro Builder in Splunk Search 11-17-2010
2 11
2
11
skippylou
Couldn't see to find a question like this here, but maybe my search for it is no good. What I'd like to do is have a...
by skippylou Communicator in Splunk Search 11-17-2010
1 2
1
2
Marinus
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by Marinus Communicator in Splunk Search 11-17-2010
4 5
4
5
blurblebot
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by blurblebot Communicator in Splunk Search 11-17-2010
1 3
1
3
wmwilson01
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few ...
by wmwilson01 Engager in Splunk Search 11-17-2010
2 2
2
2
sanju005ind
I would like to find All Users that have not logged in for 90 days ans active scheduled searches associated with th...
by sanju005ind Communicator in Splunk Search 11-16-2010
0 1
0
1
flora123
Hi,all I want to use "substr" to get what I want. A=1420014 ... |eval A=if(substr(A, 1,2)="14",replace(A, "14", "0...
by flora123 Path Finder in Splunk Search 11-16-2010
1 2
1
2
sanju005ind
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac. I am ab...
by sanju005ind Communicator in Splunk Search 11-15-2010
0 3
0
3
fedevietti
Dear All, I'm doing a search as the following: sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=24h _...
by fedevietti New Member in Splunk Search 11-13-2010
0 3
0
3
patrickbass
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this: "deny tcp source...
by patrickbass New Member in Splunk Search 11-13-2010
0 1
0
1
nbcohen
Appreciate the answer to my original question, but it leads me to a couple of additional issues: 0) As I write this,...
by nbcohen Explorer in Splunk Search 11-12-2010
0 2
0
2
Simeon
I have an extracted field called ruby_completed_call, that extracts the completion time from a ruby log: Processing ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-11-2010
1 2
1
2
wang
I have a log statement that looks list this: ipAddress=1.2.3.4,userId=42,productId=24 Currently I manually first sea...
by wang Path Finder in Splunk Search 11-11-2010
0 1
0
1
sfmandmdev
I have this query- index=myIndex logRecordTypeX=1 (logName="abc" OR logName="def" OR logName="ghi" OR logName="jkl"...
by sfmandmdev Path Finder in Splunk Search 11-10-2010
0 2
0
2
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 4
0
4
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 1
0
1
frussell
As a system administrator, sometime I only need to know a rough idea of how many times something occurred. For exampl...
by frussell New Member in Splunk Search 11-09-2010
0 1
0
1
nbcohen
I am a brand new Splunk user - could use a couple of pointers getting started on reporting... I have a dataset that ...
by nbcohen Explorer in Splunk Search 11-09-2010
0 1
0
1
goat
I'm trying to get a monthly event count for all indexed data on a splunk server. I've searched on how to do it, but I...
by goat Explorer in Splunk Search 11-09-2010
2 4
2
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...