Splunk Search

Splunk Search
Community Activity
jhilton90
So I'm trying to turn a single value number into a percentage but the code just returns a number still. Here's my cod...
by jhilton90 Path Finder in Splunk Search 12-01-2022
0 9
0
9
SplunkDash
Hello, I have use cases to find the Delta between 2 sets of events. We get events once a day, our objective is to fin...
by SplunkDash Motivator in Splunk Search 12-01-2022
0 12
0
12
sekhar463
hi All,can you help with splunk search to get time only from date time.example as 2022/11/28 17:00:00 want to get onl...
by sekhar463 Path Finder in Splunk Search 12-01-2022
0 7
0
7
Nithianandan
Hello Splunkers, Workflows are monitored through splunk. Workflows has different stages like running , paused, cancel...
by Nithianandan Observer in Splunk Search 12-01-2022
0 2
0
2
harsush
index=XX sourcetype=YY source=*/log/abc.log| dedup _time, bppm_message, bppm_nodename sortby -_indextime| rex field=b...
by harsush Path Finder in Splunk Search 12-01-2022
0 3
0
3
prashantsagar73
i have a table who contain multiple keys and value one of them keys{"body"} value are below: "body": "{\n \"Type\" : ...
by prashantsagar73 Explorer in Splunk Search 12-01-2022
0 8
0
8
Chaser
I want to get a search for get sum status error of http_user_agent like second dashboard. I do not know how to sum st...
by Chaser Explorer in Splunk Search 12-01-2022
0 1
0
1
bhupi
Hi Splunkers I am looking to get some help in spl for following use case | makeresults count=4 | streamstats count ...
by bhupi New Member in Splunk Search 12-01-2022
0 1
0
1
Abdullah
Hi Dears, When I search only IPs without field names in Firewall indexes search is fast, like: index="EX" "X.X.X.X" O...
by Abdullah Explorer in Splunk Search 11-30-2022
0 0
0
0
M28
I have 2 sourcetype sourcetype="source1" and sourcetype="source2" This is how sample data looks: source1: CID,Cname,C...
by M28 Explorer in Splunk Search 11-30-2022
1 14
1
14
RNBTT
Hello Splunk Community. I am trying to use Splunk to search for the serial number of the installed hard drive(s). Whe...
by RNBTT New Member in Splunk Search 11-30-2022
0 1
0
1
Zaid
I'm trying to get sparklines with the stats command and I'm getting straight lines in Sparkline instead of dips and r...
by Zaid New Member in Splunk Search 11-30-2022
0 1
0
1
RonD
Hi, I would like to monitor a specific index and get the following information:source - nameoldest searchable event b...
by RonD Explorer in Splunk Search 11-30-2022
0 3
0
3
karu0711
I use mvzip command  index=main sourcetype="ms.356" | eval nested_payload=mvzip(mvzip(flaw, solution),answer) | eval ...
by karu0711 Communicator in Splunk Search 11-30-2022
0 16
0
16
Jagadeesh2022
Hi Friends, I want to convert 2 specific columns to rows and remaining columns should be present. This is my current ...
by Jagadeesh2022 Path Finder in Splunk Search 11-30-2022
0 4
0
4
DarshanBK
Hi All,We have below data extracted in splunk and the ask is , in the "Node" field we need to make first two values a...
by DarshanBK Explorer in Splunk Search 11-30-2022
0 5
0
5
kpavan
Hi All, I have dashboard displaying list of groups asset counts for various business units and recently has some one ...
by kpavan Path Finder in Splunk Search 11-30-2022
0 3
0
3
sekhar463
Hi All,Good day.need help on search query to get below scenario.as we have few jobs we need data to calculate sla bre...
by sekhar463 Path Finder in Splunk Search 11-30-2022
0 0
0
0
jscraig2006
Greetings, I have 2 sourcetypes that I am matching PID. How do I table the remaining values that corresponds to the P...
by jscraig2006 Communicator in Splunk Search 11-30-2022
0 5
0
5
verothor
Hi, I need to subtract -30d from earliest, where earliest is counted by token. I tried to convert token result to uni...
by verothor Path Finder in Splunk Search 11-30-2022
0 2
0
2
greentomatoes
I am currently attempting to create a table that displays the count of one event from the previous month in compariso...
by greentomatoes Engager in Splunk Search 11-30-2022
0 1
0
1
Glasses2
Hi I am not having much luck.I want to find all schedule reports and alerts that use a specific index (e.g. index=foo...
by Glasses2 Communicator in Splunk Search 11-29-2022
0 4
0
4
Splunk_321
I am trying to expand couple of fields (locationId, matchRank) using mvexpand. But it only works for shorter duration...
by Splunk_321 Path Finder in Splunk Search 11-29-2022
0 1
0
1
Jouman
Hi all,I  would like to know how to write a SPL code to solve the issue that is to pick the scenarios follow the 3 lo...
by Jouman Path Finder in Splunk Search 11-29-2022
0 2
0
2
mlm
Hey gents,  I am very new to splunk but does anyone have an idea why my search from datamodel=authentication not gett...
by mlm Explorer in Splunk Search 11-29-2022
0 2
0
2
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors