Splunk Search

Splunk Search
Community Activity
the_wolverine
I have a simple case where I want to see if the value of one field has shown up as the value of another field. rec=d...
by the_wolverine Champion in Splunk Search 04-23-2010
1 3
1
3
sranga
Hi I was wondering if it is possible to generate a chart based on the following criteria: “Display the top X perce...
by sranga Path Finder in Splunk Search 04-23-2010
2 4
2
4
sranga
Hi Say I have the following log statements (generated throughout the day): id=111,type=2,field1=y id=141,type=2...
by sranga Path Finder in Splunk Search 04-23-2010
1 7
1
7
Justin_Grant
I have indexed the contents of a relational database along with a log file. My log contains these fields: cost - thi...
by Justin_Grant Contributor in Splunk Search 04-22-2010
8 6
8
6
gkanapathy
I thought there was a way to enumerate the enabled and disabled apps from the CLI. Is this so, and if so, what is it?
by gkanapathy Splunk Employee Splunk Employee in Splunk Search 04-22-2010
2 7
2
7
pj
Hi, am looking to pull together a table chart of our threat data that contains 3 columns: threat, totalhosts and uniq...
by pj Contributor in Splunk Search 04-22-2010
1 1
1
1
Yancy
What are some methods of determining anomalous login behavior with Splunk?
by Yancy Path Finder in Splunk Search 04-21-2010
2 3
2
3
mctester
I need to create a custom chart in splunk and be able to tag the results of that search with a ticket number for trac...
by mctester Communicator in Splunk Search 04-21-2010
2 1
2
1
davidha
Hi, I am trying to extract fields of the form [key1=value with spaces] [key2=value with spaces] using the kv search ...
by davidha New Member in Splunk Search 04-21-2010
0 3
0
3
Simon_Shelston
Is it possible to create a field extraction on a field that only exists after piping through multikv? In other words...
by Simon_Shelston Splunk Employee Splunk Employee in Splunk Search 04-21-2010
0 3
0
3
Hazel
Hello, We have an app that pings urls to get the status codes. Each application has a separate url and so i use a s...
by Hazel Communicator in Splunk Search 04-20-2010
3 7
3
7
hulahoop
Currently, Splunk will provide a link to search results in the RSS feed. I guess I want an option like inline=True f...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 04-17-2010
1 1
1
1
sideview
on March 13th, -1mon maps to February 13th, at whatever the current time of day is. And -1mon@d maps to February 13t...
by SplunkTrust SplunkTrust in Splunk Search 04-17-2010
2 1
2
1
thepocketwade
I set up an external field lookup and got it working properly. Today I tried add a second. So far, I can only get o...
by thepocketwade Path Finder in Splunk Search 04-16-2010
2 7
2
7
jrich523
is it possible to do a stacked bar chart where it splits it in two to show how much is https requests and how much is...
by jrich523 Path Finder in Splunk Search 04-15-2010
1 2
1
2
kmattern
Splunk 4.0.10 I have a log file that has 5 fields, date, time, account, received, authorized. It looks like this: 4...
by kmattern Builder in Splunk Search 04-14-2010
0 3
0
3
jrich523
how do i show the average number of hits per minute for each hour? basically i have a system that will, on peak hour...
by jrich523 Path Finder in Splunk Search 04-14-2010
3 1
3
1
Simon
Hi folks I have a directory structure on my server box (with splunk LWF) like this: /foo/bar/node1/server1/SystemOu...
by Simon Contributor in Splunk Search 04-14-2010
1 3
1
3
Marinus
If you have a time range and certain days contain data you'd like to exclude can you drop the days from your search r...
by Marinus Communicator in Splunk Search 04-14-2010
4 2
4
2
netwrkr
I would like to be able to see if a user logs in via ssh but doesn't log out within 30 minutes. For example 12:28:4...
by netwrkr Communicator in Splunk Search 04-14-2010
2 1
2
1
the_wolverine
My understanding is that this is now done via a splunk config file. How?
by the_wolverine Champion in Splunk Search 04-14-2010
2 1
2
1
Alan_Bradley
I see lots of reference to search heads as a way to improve search performance. I can't find a search head section o...
by Alan_Bradley Path Finder in Splunk Search 04-14-2010
0 2
0
2
Ayn
I have a number of hosts that have a certain tag on them (let's say "sensitive"). I want to look for account lockout ...
by Legend in Splunk Search 04-13-2010
1 2
1
2
Yancy
Is it possible with subsearch to pass a list of search results to the outside search? similar to a SQL correlated sub...
by Yancy Path Finder in Splunk Search 04-13-2010
3 3
3
3
andynu
Given a sequence of general to specific events (like product browsing a pages, followed by particular product pages)...
by andynu Engager in Splunk Search 04-13-2010
2 2
2
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...