| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        we are using ocp-4.10 deploying splunk/splunk:7.2.2 image but pod is going into crashbakloopoff state and in logs we ...
        
       
         
           by 
           
                
                    
                        maheswari
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               09-23-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        we are doing splunk integartion with ocp-4.10 so need to install splunk but After installation of splunk getting erro...
        
       
         
           by 
           
                
                    
                        maheswari
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               09-23-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hello All, 
  I need help trying to generate the average response times for the below data using tstats command. Need...
        
       
         
           by 
           
                
                    
                        dsenapaty
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-11-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hi Team,I have a field which has the values in the below string format:  HH:MM:SS.3N 
  0:00:43.096 
  22:09:50.174 
...
        
       
         
           by 
           
                
                    
                        kranthimutyala
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               09-20-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello folks, 
  we have some linux machines with UF installed on that connect to our search head. 
  We haven't acces...
        
       
         
           by 
           
                
                    
                        linspec9721
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi, I am looking to grab a hand at turning 8 product charts into one table with Sparkline's if possible for trend tra...
        
       
         
           by 
           
                
                    
                        Altoid17
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hello All, 
  I need help trying to generate the P95,P99,P75, mean and median response times for the below data using...
        
       
         
           by 
           
                
                    
                        dsenapaty
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I want no results of a search to display until the search has completed. The search I am running displays any users w...
        
       
         
           by 
           
                
                    
                        pwilson
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello 
  I have a query that running a rest command, one of the fields is "action.email.to"also i have a lookup table...
        
       
         
           by 
           
                
                    
                        sarit_s
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               09-19-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        I see an interesting Simple XML idiom below:
  
   <input type="multiselect" token="multiselect_lines" searchWhenChan...
        
       
         
           by 
           
                
                    
                        yshen
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        I'm looking for a way to set a token when the column exists (regardless of value).  Tried these with no luck.  
  <ev...
        
       
         
           by 
           
                
                    
                        timgren
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I have a dropdown whose value once input needs to be used in two different ways in the same search query. One of the ...
        
       
         
           by 
           
                
                    
                        thenormalone
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        My rex search is returning all the rows instead of the one being searched. What am I doing wrong? 
  
   index=cloudw...
        
       
         
           by 
           
                
                    
                        Jeet
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi, I have a scenario where I receive multiple requests which contain same field value basically OrderNumber. So the ...
        
       
         
           by 
           
                
                    
                        shashank_24
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Currently I am trying to extract the crossReferenceId value using below rex query.  Its working fine and I can extrac...
        
       
         
           by 
           
                
                    
                        ravir_jbp
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        A notable event triggered 30000 notables how can i delete them all?
        
       
         
           by 
           
                
                    
                        Basavaraj
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Want to create search to get info from lookup file if event field contains data from two field in lookup file. 
  log...
        
       
         
           by 
           
                
                    
                        Abhineet
                    
                
           
             
             
               Loves-to-Learn Everything
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi, everyone.Need some help for detection exclusion setting. Want to exclude detections of  the files which are appli...
        
       
         
           by 
           
                
                    
                        Ange
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-22-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hello dear Splunk experts!
  I've stuck with one search and can't figure how to do this. 
  Did a lot of searching he...
        
       
         
           by 
           
                
                    
                        siriosus
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello  - I am getting the below error. I am trying to add pipe "|"  for all the results. 
   Error : Failed to parse ...
        
       
         
           by 
           
                
                    
                        kc_prane
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-30-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Here is my search: 
  source="WinEventLog:Security" EventCode=540 | timechart span=1h count by User 
  This gives me ...
        
       
         
           by 
           
                
                    
                        hartfoml
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               04-04-2012
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  13
	 
 | |||
| 
      
        Hi Team! 
  Someone please explain to me what each parameter is responsible for in such a search tag: 
  <search><que...
        
       
         
           by 
           
                
                    
                        NickGrava
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I want to exclude duration results if greater than 7 days. So i used search NOT but it is not working. 
  Can someone...
        
       
         
           by 
           
                
                    
                        alexspunkshell
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have a query which results in a table:
    
    
   "some words" | stats dc(host) as host_count by zone, region 
  ...
        
       
         
           by 
           
                
                    
                        charming_fish
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        HI Team,I am getting 2 hr time span only if i mentioned the 1 or 3 or 4 hours span too in the visualization line char...
        
       
         
           by 
           
                
                    
                        Anud
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               09-21-2022
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 |