Splunk Search

Splunk Search
Community Activity
9jamie
I am trying to create a query that returns a table showing counts of different error codes and percentage of transact...
by 9jamie Explorer in Splunk Search 09-23-2022
0 1
0
1
KayBeesKnees83
I have a customer that would like to use Splunk to search for a set of devices by their respective barcodes. The devi...
by KayBeesKnees83 Path Finder in Splunk Search 09-23-2022
0 9
0
9
bapun18
I want to extract as below using universal forwarder props.conf           Whatever data I have before: should be the ...
by bapun18 Communicator in Splunk Search 09-23-2022
0 5
0
5
sjringo
I am performing two searches in an attempt to calculate the duration, but am having some issues. Here is what I have ...
by sjringo Contributor in Splunk Search 09-23-2022
0 6
0
6
kranthimutyala
Hi Team,I have the event in the below format and want to extract the key-value pairs as fields. Please help extract f...
by kranthimutyala Path Finder in Splunk Search 09-23-2022
0 5
0
5
POR160893
Hi,I have a field X with values similar to the following "device-group APCC1_Core_Controller pre-rulebase application...
by POR160893 Builder in Splunk Search 09-23-2022
0 9
0
9
mark_cet
Hi everyone,   I am attempting to implement some logic in my alert searches but I can't seem to figure out how to do ...
by mark_cet Path Finder in Splunk Search 09-23-2022
0 2
0
2
maheswari
we are using ocp-4.10 deploying splunk/splunk:7.2.2 image but pod is going into crashbakloopoff state and in logs we ...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
maheswari
we are doing splunk integartion with ocp-4.10 so need to install splunk but After installation of splunk getting erro...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the average response times for the below data using tstats command. Need he...
by dsenapaty Explorer in Splunk Search 09-23-2022
0 5
0
5
kranthimutyala
Hi Team,I have a field which has the values in the below string format:  HH:MM:SS.3N 0:00:43.096 22:09:50.174 1:59:54...
by kranthimutyala Path Finder in Splunk Search 09-23-2022
0 3
0
3
linspec9721
Hello folks, we have some linux machines with UF installed on that connect to our search head. We haven't access to t...
by linspec9721 Explorer in Splunk Search 09-23-2022
0 2
0
2
Altoid17
Hi, I am looking to grab a hand at turning 8 product charts into one table with Sparkline's if possible for trend tra...
by Altoid17 Explorer in Splunk Search 09-22-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the P95,P99,P75, mean and median response times for the below data using ts...
by dsenapaty Explorer in Splunk Search 09-22-2022
0 1
0
1
pwilson
I want no results of a search to display until the search has completed. The search I am running displays any users w...
by pwilson Explorer in Splunk Search 09-22-2022
0 3
0
3
sarit_s
Hello I have a query that running a rest command, one of the fields is "action.email.to"also i have a lookup table wi...
by sarit_s Communicator in Splunk Search 09-22-2022
0 7
0
7
yshen
I see an interesting Simple XML idiom below:<input type="multiselect" token="multiselect_lines" searchWhenChanged="tr...
by yshen Communicator in Splunk Search 09-22-2022
0 0
0
0
timgren
I'm looking for a way to set a token when the column exists (regardless of value).  Tried these with no luck.  <eval ...
by timgren Path Finder in Splunk Search 09-22-2022
0 3
0
3
thenormalone
I have a dropdown whose value once input needs to be used in two different ways in the same search query. One of the ...
by thenormalone Path Finder in Splunk Search 09-22-2022
0 4
0
4
Jeet
My rex search is returning all the rows instead of the one being searched. What am I doing wrong? index=cloudwatchlog...
by Jeet Explorer in Splunk Search 09-22-2022
0 3
0
3
shashank_24
Hi, I have a scenario where I receive multiple requests which contain same field value basically OrderNumber. So the ...
by shashank_24 Path Finder in Splunk Search 09-22-2022
0 1
0
1
ravir_jbp
Currently I am trying to extract the crossReferenceId value using below rex query.  Its working fine and I can extrac...
by ravir_jbp Explorer in Splunk Search 09-22-2022
0 3
0
3
Basavaraj
A notable event triggered 30000 notables how can i delete them all?
by Basavaraj Engager in Splunk Search 09-22-2022
0 3
0
3
Abhineet
Want to create search to get info from lookup file if event field contains data from two field in lookup file. log ev...
by Abhineet Loves-to-Learn Everything in Splunk Search 09-22-2022
0 3
0
3
Ange
Hi, everyone.Need some help for detection exclusion setting. Want to exclude detections of  the files which are appli...
by Ange Explorer in Splunk Search 09-22-2022
0 5
0
5
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...