Splunk Search

Splunk Search
Community Activity
_pravin
Hi Community, I have a search query where I am trying to get values for the search from the results of another query....
by _pravin Contributor in Splunk Search 11-08-2022
0 2
0
2
jiaqya
i know that setting RF=2 ensures 2 copies of buckets on available indexers. so this consume 2X times of space/disk.no...
by jiaqya Builder in Splunk Search 11-08-2022
2 10
2
10
wanda619
How to set a report hourly for time frame between 26th to 5th of each month?
by wanda619 Path Finder in Splunk Search 11-08-2022
0 7
0
7
navan1
Hi All, How to find more than 3 heartbeat failure with failure reason from same host in a day  and put in a table?I a...
by navan1 Explorer in Splunk Search 11-08-2022
0 2
0
2
MaxJ
I run large searches at the start of each month. Generally I use the saved search commands to retrieve the results on...
by MaxJ New Member in Splunk Search 11-08-2022
0 2
0
2
sidtalup27
Hello,My requirement is if the field "fields.summary" contains events that contain ".DT", then I want to create a new...
by sidtalup27 Explorer in Splunk Search 11-08-2022
0 1
0
1
Aryc090908
Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _t...
by Aryc090908 Explorer in Splunk Search 11-08-2022
0 4
0
4
replicant
I have a dashboard that uses a dbxquery in the base search.  I would like to make the dashboard "bilingual".Is it pos...
by replicant Engager in Splunk Search 11-08-2022
0 3
0
3
mananzeh
i have 2 csv file first one has name and idsecond one has the id only i can extract the common id but i couldn’t find...
by mananzeh New Member in Splunk Search 11-08-2022
0 1
0
1
metylkinandrey
Good afternoon! I'm noticing that my time format in the messages I send to /services/collector/raw isn't being parsed...
by metylkinandrey Communicator in Splunk Search 11-08-2022
0 8
0
8
DavideASR
Hi, I'm trying to extract string "domain.com" from <mail@domain.com> How can i extract string between "@" and ">" ? T...
by DavideASR Engager in Splunk Search 11-08-2022
0 1
0
1
_pravin
Hi Community,   I have the below search query     index=_internal [ `set_local_host`] source=*license_usage.log*...
by _pravin Contributor in Splunk Search 11-08-2022
0 4
0
4
danielbb
Hello,Is there a way to convert this query to run with tstats? It is _slow_ when running it for two weeks of data...i...
by danielbb Motivator in Splunk Search 11-08-2022
0 2
0
2
dtccsundar
I have 3 date columns.I have already calculated the difference between current day and the diff is in days are the va...
by dtccsundar Path Finder in Splunk Search 11-08-2022
0 4
0
4
klim
I have a search head cluster and I will have scheduled reports that send data to a summary index. I don't want other ...
by klim Path Finder in Splunk Search 11-07-2022
0 2
0
2
mskrzynski
Hello, can anyone tell me why this configuration isn’t working?I would like to change index name from main to hue, I’...
by mskrzynski Explorer in Splunk Search 11-07-2022
0 10
0
10
Damek
Hello, I am currently using the |append method for some queries, but was curious if there is a better way for me to b...
by Damek Engager in Splunk Search 11-07-2022
0 2
0
2
dmbrcx
Dumb question I cannot find a simple answer to. 藍 If I run a simple timechart search for 7 days, 30 days or 90 days -...
by dmbrcx Explorer in Splunk Search 11-07-2022
0 3
0
3
nabeel652
Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both...
by nabeel652 Builder in Splunk Search 11-07-2022
0 2
0
2
ff170a
I have a dataset with a multiline field called Logs. The field typically has values like the below,     "mId": "Nul...
by ff170a Explorer in Splunk Search 11-07-2022
0 3
0
3
sh254087
I have a table with 1 column and 6 rows which I'll be changing to 1 row and 6 columns using transpose and eventually ...
by sh254087 Communicator in Splunk Search 11-07-2022
0 6
0
6
iamtheclient20
I have a SPL, when first running the result is appearing but once the query is finished the error have shown below: |...
by iamtheclient20 Explorer in Splunk Search 11-07-2022
1 8
1
8
Aryc090908
 Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _...
by Aryc090908 Explorer in Splunk Search 11-07-2022
0 3
0
3
Hisham
Hi, I have generated a search which return list of hosts and the count of events for these host. sometime the host va...
by Hisham Engager in Splunk Search 11-07-2022
0 1
0
1
lennys26
On an existing dashboard I have a rather complex query that generates a timechart on which I am looking to use annota...
by lennys26 Communicator in Splunk Search 11-07-2022
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...