Splunk Search

Splunk Search
Community Activity
pinzer
Hi all, i need to select IP address from a search query that "are not" in another search query. How can i do this? th...
by pinzer Path Finder in Splunk Search 09-02-2010
0 8
0
8
adamw
So I have an application that auto-rotates its config files every time it is changed, and uses the following structur...
by adamw Communicator in Splunk Search 09-02-2010
0 1
0
1
sptelars
I would like to add the total amount of time an cs_id spends on the web daily. Ironport provides logs where the time...
by sptelars New Member in Splunk Search 09-02-2010
0 1
0
1
Lowell
Is there any weird issues with using multiple searchmatch() expressions within a single eval command? I have a trans...
by Lowell Super Champion in Splunk Search 09-02-2010
4 2
4
2
Lowell
Is there anyway of emulating a nested subsearch? I know its sometimes possible to rewrite a search to factor-out a s...
by Lowell Super Champion in Splunk Search 09-02-2010
0 5
0
5
the_wolverine
I've got certain events that I want to send to collect. I see the addtime option (defaults to true). What does it d...
by the_wolverine Champion in Splunk Search 09-01-2010
0 2
0
2
pde
I have a small DTrace app that monitors ARP requests and replies, producing output like this: 2010 Sep 1 03:10:08 ...
by pde Path Finder in Splunk Search 09-01-2010
0 2
0
2
vtrujillo
Hi everyone. I'm trying to use the date_hour and date_minute fields (which reads perfectly the hours and minutes of ...
by vtrujillo Explorer in Splunk Search 09-01-2010
0 2
0
2
Jaci
Search fails to correctly return all matching events when performing outer joins. The search below illustrates the pr...
by Jaci Splunk Employee Splunk Employee in Splunk Search 09-01-2010
1 3
1
3
hulahoop
Splunk understands old school BSD-style syslog events effortlessly. For RFC 5424-style events, multiple data structu...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 09-01-2010
0 3
0
3
sriram_sathyamo
In a chart, I need to set major unit to be one week (i.e adjacant tick marks need to be one week apart). How do I do ...
by sriram_sathyamo New Member in Splunk Search 09-01-2010
0 1
0
1
sranga
Hi I was wondering if there is a limit on the count of simultaneous queries/searches/jobs executed in a Splunk ins...
by sranga Path Finder in Splunk Search 08-31-2010
0 2
0
2
Branden
I have the following output: DEV#: 0 DEVICE NAME: vpath0 TYPE: 2107900 POLICY: Optimized SERIAL: 123bac ...
by Branden Builder in Splunk Search 08-31-2010
0 11
0
11
pinzer
Hi all, i need to do a query about the number of login failed and succeeded in a time period. I'm auditing linux and ...
by pinzer Path Finder in Splunk Search 08-31-2010
0 2
0
2
Marinus
I'm building a custom search command that performs some visualizations on a dataset outside of Splunk. It has to pars...
by Marinus Communicator in Splunk Search 08-31-2010
0 6
0
6
Pete_Bassill
How would I go about running a search that compares the output to two searches and reports the difference between the...
by Pete_Bassill Path Finder in Splunk Search 08-31-2010
1 3
1
3
Branden
I have a script that sends something like the following to stdout: DEV#: 0 DEVICE NAME: vpath0 TYPE: 210790...
by Branden Builder in Splunk Search 08-30-2010
1 5
1
5
sondradotcom
Okay, my summary index looks like this: sourcetype="blah" | sistats count by email I'd like to run a query agai...
by sondradotcom Path Finder in Splunk Search 08-30-2010
1 1
1
1
landzaat
Is there a way to show events only if they do not contain a specified field. E.g. 40% of my selected events contain a...
by landzaat Explorer in Splunk Search 08-30-2010
12 1
12
1
DyJohnnY
Hi, We now have a setup in which we use splunk like this. Forwarders deployed on windows Domain Controllers, that re...
by DyJohnnY Explorer in Splunk Search 08-30-2010
1 4
1
4
MikeyG
I have a search time field extraction for CISCO system messages named MsgClassID. I uploaded from Manager a CISCOevt_...
by MikeyG Explorer in Splunk Search 08-28-2010
0 1
0
1
sondradotcom
I'm trying to figure out how to calculate a percent of total such that: search string | stats count percent by email...
by sondradotcom Path Finder in Splunk Search 08-28-2010
3 3
3
3
gfriedmann
We index data from about 2000 different hosts. logs are relayed in via a TCP syslog source. Whenever a user goes to ...
by gfriedmann Communicator in Splunk Search 08-28-2010
0 2
0
2
BunnyHop
I've tried to filter native event logs being indexed using the [WinEventLog...] sourcetype. Here are the config: pr...
by BunnyHop Contributor in Splunk Search 08-28-2010
1 5
1
5
dominiquevocat
Hi, i have a couple of logfiles where there is one important "field" that splunk does not recognize because it is no...
by SplunkTrust SplunkTrust in Splunk Search 08-27-2010
1 3
1
3
Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...