Splunk Search

Splunk Search
Community Activity
earriaga
I have a working search that uses a look up, that is like this: index=MyIndex [| inputlookup MyCSVFile | stat...
by earriaga Path Finder in Splunk Search 11-09-2022
0 1
0
1
cdson
Hello!  I have a csv file where there are two fields called "Customers First Name" and "Customers Last Name".  I was ...
by cdson Explorer in Splunk Search 11-09-2022
0 2
0
2
sistemistiposta
Hello,    I have recently upgraded from Splunk 7 to Splunk 8.2.4. After the upgrade, I noticed that some transform co...
by sistemistiposta Path Finder in Splunk Search 11-09-2022
0 23
0
23
AKG11
Hi, I am trying to build a query where I need Job duration.  Each job could run multiple time and its start/end time ...
by AKG11 Path Finder in Splunk Search 11-09-2022
0 3
0
3
vishalduttauk
Hi there, I have a requirement where I have a large number of events which was uploaded on the 4th November but that ...
by vishalduttauk Communicator in Splunk Search 11-09-2022
0 7
0
7
Dworsnop
Hi all, I need some help sorting an eval field by one of it's components per below. ...   | eventstats count(ID) AS c...
by Dworsnop Path Finder in Splunk Search 11-09-2022
0 8
0
8
wrongquery
So based off my original query that shows 100+ hosts, I would like to generate a list of the hosts in statistics but ...
by wrongquery Explorer in Splunk Search 11-09-2022
0 6
0
6
olawalePS
I am trying to create an alert that triggers when the location field of a login event from a user changes. so if a us...
by olawalePS Path Finder in Splunk Search 11-09-2022
0 1
0
1
frnSpLrnr11
Hello,   I have this search results:       Error for user flow: AAAAA - user: BBBB - Msg: {\"_errorCode\":Z, \"_messa...
by frnSpLrnr11 Engager in Splunk Search 11-08-2022
0 2
0
2
JM_dataguy
I'm trying to get an accurate percentile representation from a dataset of hourly metrics, excluding outliers.  The da...
by JM_dataguy New Member in Splunk Search 11-08-2022
0 2
0
2
RexPei
Hello Splunkers,    I am trying to compare two multi value ID columns, and return true when at least of the values ma...
by RexPei New Member in Splunk Search 11-08-2022
0 3
0
3
dionrivera
Hi Team. I have a splunk query with a list of IP addressses(Client_IP). I also have a lookup file with the IP ranges(...
by dionrivera Communicator in Splunk Search 11-08-2022
0 1
0
1
imranshs
My doubt is that I can see,My Volume used today = 0 MB ( 0%  of quota ). Why It's showing as 0 MB, I tried many queri...
by imranshs Engager in Splunk Search 11-08-2022
0 3
0
3
daniel333
All, We're looking to open Splunk up some and let developers submit TAs and apps and what not without admin involve...
by daniel333 Builder in Splunk Search 11-08-2022
0 1
0
1
_pravin
Hi Community, I have a search query where I am trying to get values for the search from the results of another query....
by _pravin Contributor in Splunk Search 11-08-2022
0 2
0
2
jiaqya
i know that setting RF=2 ensures 2 copies of buckets on available indexers. so this consume 2X times of space/disk.no...
by jiaqya Builder in Splunk Search 11-08-2022
2 10
2
10
wanda619
How to set a report hourly for time frame between 26th to 5th of each month?
by wanda619 Path Finder in Splunk Search 11-08-2022
0 7
0
7
navan1
Hi All, How to find more than 3 heartbeat failure with failure reason from same host in a day  and put in a table?I a...
by navan1 Explorer in Splunk Search 11-08-2022
0 2
0
2
MaxJ
I run large searches at the start of each month. Generally I use the saved search commands to retrieve the results on...
by MaxJ New Member in Splunk Search 11-08-2022
0 2
0
2
sidtalup27
Hello,My requirement is if the field "fields.summary" contains events that contain ".DT", then I want to create a new...
by sidtalup27 Explorer in Splunk Search 11-08-2022
0 1
0
1
Aryc090908
Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _t...
by Aryc090908 Explorer in Splunk Search 11-08-2022
0 4
0
4
replicant
I have a dashboard that uses a dbxquery in the base search.  I would like to make the dashboard "bilingual".Is it pos...
by replicant Engager in Splunk Search 11-08-2022
0 3
0
3
mananzeh
i have 2 csv file first one has name and idsecond one has the id only i can extract the common id but i couldn’t find...
by mananzeh New Member in Splunk Search 11-08-2022
0 1
0
1
metylkinandrey
Good afternoon! I'm noticing that my time format in the messages I send to /services/collector/raw isn't being parsed...
by metylkinandrey Communicator in Splunk Search 11-08-2022
0 8
0
8
DavideASR
Hi, I'm trying to extract string "domain.com" from <mail@domain.com> How can i extract string between "@" and ">" ? T...
by DavideASR Engager in Splunk Search 11-08-2022
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...