Splunk Search

Splunk Search
Community Activity
vrmandadi
Hello Splunkers, I have a query where I did a  |stats values(abc) as abc command over time .I got the below results ....
by vrmandadi Builder in Splunk Search 04-19-2022
0 13
0
13
SplunkDash
Hello, I have events with complex/inconsistence data structure. Need to extract field 2 values under 2 different fiel...
by SplunkDash Motivator in Splunk Search 04-19-2022
0 1
0
1
PavanSeerapu
To get the percentage increase of threshold value and to build a dashboard out of it to show as red if it is increase...
by PavanSeerapu Explorer in Splunk Search 04-19-2022
0 2
0
2
BernardEAI
We are trying to create a data model with a custom _time field. We created the data model, and added a calculated fie...
by BernardEAI Communicator in Splunk Search 04-19-2022
0 1
0
1
jbrenner
I have two Splunk queries, each of which uses the _rex command to extract the join field. Example:       QUERY 1 inde...
by jbrenner Path Finder in Splunk Search 04-19-2022
0 3
0
3
indeed_2000
Hi How can I monitor java applications with splunk, I try nmon but it only give whole java process, not specific pid!...
by indeed_2000 Motivator in Splunk Search 04-19-2022
0 3
0
3
arnavkumarsaxen
My logs are in the format: My-Application Log: Some-Key= 99, SomeOtherKey= 231, SomeOtherKey2= 1231, Some Different K...
by arnavkumarsaxen Explorer in Splunk Search 04-19-2022
0 6
0
6
jinishshah
Hello, so I have an input on my dashboard page of either month"01-2022,02-2022" and also quarter"Q1-2022". So dependi...
by jinishshah Explorer in Splunk Search 04-19-2022
0 9
0
9
gheribhai1234
Hey Team,I have Million records to search for.Record Structure is given below.My requirement is to get length of aVal...
by gheribhai1234 Engager in Splunk Search 04-19-2022
0 13
0
13
msg4sunil
index=app1 [search index=app1 "orderid"| fields id] How do I modify the above query wherein "search index=app1 "order...
by msg4sunil Path Finder in Splunk Search 04-18-2022
0 8
0
8
bapun18
I want to specify a field that contains time as earliest and another field as latest so that my spl will be executed ...
by bapun18 Communicator in Splunk Search 04-18-2022
0 2
0
2
neerajs_81
Gentlemen,We are on Splunk Cloud.In my raw events coming from AWS , splunk by default shows a field called "category"...
by neerajs_81 Builder in Splunk Search 04-18-2022
0 4
0
4
jking81
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1...
by jking81 Explorer in Splunk Search 04-18-2022
0 2
0
2
bcwlk
Does anyone know of a way to reverse the order of the automatic start/end values used for bucket creation when workin...
by bcwlk Explorer in Splunk Search 04-18-2022
0 7
0
7
humblelearner
Hi all, I want to set a condition "credential.helper= ", notice there is a trailing space after the "=".  What I want...
by humblelearner Observer in Splunk Search 04-18-2022
0 2
0
2
ddrillic
I have a lookup table from which I need to remove a couple of lines. How can I do it?
by ddrillic Ultra Champion in Splunk Search 04-18-2022
0 3
0
3
Qerro
Don't show a result where the src_ip is X and dest_ip is Y  index=test    host=test  source=test conn_state=sf   | ev...
by Qerro Loves-to-Learn in Splunk Search 04-18-2022
0 2
0
2
POR160893
Hi, I need to use Linear Regression to predict network volumes at the moment.The index I am using has a number of cat...
by POR160893 Builder in Splunk Search 04-18-2022
0 0
0
0
danielbb
We have the following command that works well -    | transaction job_name startswith=STARTING keeporphans=true   Is i...
by danielbb Motivator in Splunk Search 04-18-2022
0 2
0
2
jpfrancetic
Hi Splunk Community, I have 2 tables I am attempting to merge together. Both tables are in csvs that I am trying to p...
by jpfrancetic Path Finder in Splunk Search 04-18-2022
0 2
0
2
Hendrik2509
Hello,I have configured a custom indexed field via transforms.conf and props.conf as following:transforms.conf:  (/ap...
by Hendrik2509 Engager in Splunk Search 04-18-2022
0 1
0
1
ccloutralex
I have a fairly large(3,400 records) search result that randomly contains non-ascii characters in any one of the 20 f...
by ccloutralex Observer in Splunk Search 04-18-2022
0 2
0
2
wlin
Hi Team, Because the data storage time of Splunk is limited, we have a scheduled task to export data from Splunk to A...
by wlin Loves-to-Learn Lots in Splunk Search 04-18-2022
0 0
0
0
delly_fofie
Hello, I have a dashboard with two different time filters. The first time filter is used to filter the _time filter T...
by delly_fofie Engager in Splunk Search 04-17-2022
0 3
0
3
Jaylon
timechart [stats count|eval app=$A$|eval search=case(app=="*","span=30m count by B",app!="*","span=30m count by C")] ...
by Jaylon Loves-to-Learn Lots in Splunk Search 04-17-2022
0 3
0
3
Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...