Splunk Search

Splunk Search
Community Activity
kimmyb
 the transaction is identified as jsessionid .the spl query to find all transactions which lasted less than 5 sec : s...
by kimmyb Loves-to-Learn in Splunk Search 09-23-2022
0 5
0
5
kimmyb
when i was studying about macro i sometimes see that we put our arguments between '      ' and sometimes between $   ...
by kimmyb Loves-to-Learn in Splunk Search 09-23-2022
0 4
0
4
risingflight143
Hi All i am using the below query and it works fine. i.e how many emails were triggered to a Distribution list in a M...
by risingflight143 Explorer in Splunk Search 09-23-2022
0 7
0
7
DPOIRE
I need to round the max(Delay) and avg(Delay) to 3 decimals in the following command:my search | timechart span=5m av...
by DPOIRE Path Finder in Splunk Search 09-23-2022
0 4
0
4
Dim_No
Hi, I'm new as Splunk user,I'm asking your help   I would like to create an easy dashboard with VPN datas. My search...
by Dim_No Loves-to-Learn Everything in Splunk Search 09-23-2022
0 16
0
16
yuanliu
tstats shows an error if I include a JSON field in "where" clause.  Same happens to CSV fields.  For example, if my s...
by SplunkTrust SplunkTrust in Splunk Search 09-23-2022
0 3
0
3
nathanh42
I have a query that extracts useful info from a storage system report. rex "quota list --verbose (?<fs>[A-Z0-9_]+) " ...
by nathanh42 Explorer in Splunk Search 09-23-2022
8 23
8
23
9jamie
I am trying to create a query that returns a table showing counts of different error codes and percentage of transact...
by 9jamie Explorer in Splunk Search 09-23-2022
0 1
0
1
KayBeesKnees83
I have a customer that would like to use Splunk to search for a set of devices by their respective barcodes. The devi...
by KayBeesKnees83 Path Finder in Splunk Search 09-23-2022
0 9
0
9
bapun18
I want to extract as below using universal forwarder props.conf           Whatever data I have before: should be the ...
by bapun18 Communicator in Splunk Search 09-23-2022
0 5
0
5
sjringo
I am performing two searches in an attempt to calculate the duration, but am having some issues. Here is what I have ...
by sjringo Contributor in Splunk Search 09-23-2022
0 6
0
6
kranthimutyala
Hi Team,I have the event in the below format and want to extract the key-value pairs as fields. Please help extract f...
by kranthimutyala Path Finder in Splunk Search 09-23-2022
0 5
0
5
POR160893
Hi,I have a field X with values similar to the following "device-group APCC1_Core_Controller pre-rulebase application...
by POR160893 Builder in Splunk Search 09-23-2022
0 9
0
9
mark_cet
Hi everyone,   I am attempting to implement some logic in my alert searches but I can't seem to figure out how to do ...
by mark_cet Path Finder in Splunk Search 09-23-2022
0 2
0
2
maheswari
we are using ocp-4.10 deploying splunk/splunk:7.2.2 image but pod is going into crashbakloopoff state and in logs we ...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
maheswari
we are doing splunk integartion with ocp-4.10 so need to install splunk but After installation of splunk getting erro...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the average response times for the below data using tstats command. Need he...
by dsenapaty Explorer in Splunk Search 09-23-2022
0 5
0
5
kranthimutyala
Hi Team,I have a field which has the values in the below string format:  HH:MM:SS.3N 0:00:43.096 22:09:50.174 1:59:54...
by kranthimutyala Path Finder in Splunk Search 09-23-2022
0 3
0
3
linspec9721
Hello folks, we have some linux machines with UF installed on that connect to our search head. We haven't access to t...
by linspec9721 Explorer in Splunk Search 09-23-2022
0 2
0
2
Altoid17
Hi, I am looking to grab a hand at turning 8 product charts into one table with Sparkline's if possible for trend tra...
by Altoid17 Explorer in Splunk Search 09-22-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the P95,P99,P75, mean and median response times for the below data using ts...
by dsenapaty Explorer in Splunk Search 09-22-2022
0 1
0
1
pwilson
I want no results of a search to display until the search has completed. The search I am running displays any users w...
by pwilson Explorer in Splunk Search 09-22-2022
0 3
0
3
sarit_s
Hello I have a query that running a rest command, one of the fields is "action.email.to"also i have a lookup table wi...
by sarit_s Communicator in Splunk Search 09-22-2022
0 7
0
7
yshen
I see an interesting Simple XML idiom below:<input type="multiselect" token="multiselect_lines" searchWhenChanged="tr...
by yshen Communicator in Splunk Search 09-22-2022
0 0
0
0
timgren
I'm looking for a way to set a token when the column exists (regardless of value).  Tried these with no luck.  <eval ...
by timgren Path Finder in Splunk Search 09-22-2022
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...