Splunk Search

Splunk Search
Community Activity
crmarley20
Hello, Please I need your help,  I have a dedup with a conditional. It happens that I have this table where when the ...
by crmarley20 Explorer in Splunk Search 02-09-2022
0 5
0
5
neethan
This is give me data in integers, I want calculate percentages. How can we do it? | savedsearch cbp_inc_base | eval _...
by neethan Path Finder in Splunk Search 02-08-2022
0 6
0
6
MeMilo09
Hello All, I have a lookup that is a saved as a schedule report that runs once a week.  This schedule report will get...
by MeMilo09 Path Finder in Splunk Search 02-08-2022
0 4
0
4
Sivakesava574
Hi, using logs i am generating some stats that are needed to track the performance of my app on daily basis using the...
by Sivakesava574 Explorer in Splunk Search 02-08-2022
0 3
0
3
blbr123
Hi All, I would like to know which applications are ingesting more data and violating the license.  I tried the below...
by blbr123 Path Finder in Splunk Search 02-08-2022
0 3
0
3
bsanjee
Hi Splunkers, Below is my sample event, [2021-02-06 15:30:03] production.INFO: {"uri":"https:\/\/platform.ringcentral...
by bsanjee Explorer in Splunk Search 02-08-2022
0 9
0
9
stricq
I cannot use any of the fields extracted by spath inside an eval.  The result is always null. Input: (formatted for e...
by stricq Engager in Splunk Search 02-08-2022
0 1
0
1
sahuask
Please help to extract payload data from logs entries and extract the PlatformVersion and PlatformClient values. Need...
by sahuask Loves-to-Learn in Splunk Search 02-08-2022
0 4
0
4
neeltiwari
Hello Team, I need help with a splunk query where I am trying to get the AWS instance ID via lookup table but I am ab...
by neeltiwari Observer in Splunk Search 02-08-2022
0 8
0
8
kirrusk
Hi, using the below query to trigger an alert.| tstats count WHERE index=your_index AND(TMPFIELD="FIELD1" OR TMPFIELD...
by kirrusk Communicator in Splunk Search 02-08-2022
0 1
0
1
PickleRick
Binning/timecharting seems quite straightforward regarding time... unless you want to span day+ ranges. From experien...
by SplunkTrust SplunkTrust in Splunk Search 02-08-2022
0 0
0
0
kirrusk
Hi, I'm trying to trigger an alert for the below scenarios (one alert).scenario one: when there are no events, trigge...
by kirrusk Communicator in Splunk Search 02-08-2022
0 3
0
3
Jennifer
Hi, all!Here's my log file:- the pattern: raw call progress sequence is: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX- the length...
by Jennifer Path Finder in Splunk Search 02-08-2022
0 1
0
1
kirrusk
Hi, I'm trying to exclude events from the time range.  index = _internal | eval Hour=strftime(_time,"%H") | eval Min...
by kirrusk Communicator in Splunk Search 02-07-2022
0 4
0
4
alastairsin
I am building a dashboard using simple xml. I have a populating search that defines inputs for a dropdown list. The ...
by alastairsin Engager in Splunk Search 02-07-2022
0 11
0
11
Stefanie
I have two lookup files.My first lookup file has the columns: ip, host, dnsName. We will call it List1.csvThe second ...
by Stefanie Builder in Splunk Search 02-07-2022
1 2
1
2
bt149
I have a search that is based on two events types - admin_login and admin_change.  Admin_Login has two fields that th...
by bt149 Path Finder in Splunk Search 02-07-2022
0 2
0
2
paulito
Data:SERVICEPERFDATA::'total 120m'=8%;95;97 SERVICECHECKCOMMAND::check_nrpe3!check_cpu!-a!"warn=load > 95" "crit=load...
by paulito Explorer in Splunk Search 02-07-2022
0 3
0
3
sushantnarula
Hi All,I am running a query and getting limited results in Statistics field (10,000).Earlier I was using the | sort c...
by sushantnarula Observer in Splunk Search 02-07-2022
0 0
0
0
avishni01
HelloI have events that include a field of username ( and of course _time) .I would like to count how many users were...
by avishni01 Explorer in Splunk Search 02-07-2022
0 1
0
1
shruti14
Hi , I have to get the below fields extracted from these three logs to create visulisation: Fields i am interested:Ev...
by shruti14 Explorer in Splunk Search 02-07-2022
0 6
0
6
harshal_chakran
Hi all,I have an authorize.conf located in an application, which is usually deployed via Deployer to SH members.There...
by harshal_chakran Builder in Splunk Search 02-07-2022
0 2
0
2
JosephHobbs
I recently started trying to set up some field extracts for a few of our events.  In this case, the logs are pipe del...
by JosephHobbs Path Finder in Splunk Search 02-07-2022
0 6
0
6
falks405
Hello, I have the next query to get data grouped by month by software version using  condition "where"  index=tst | ...
by falks405 Loves-to-Learn Lots in Splunk Search 02-07-2022
0 0
0
0
kajalchopade071
Can we populate the  primary index logs  to summary index .How to populate the logs from primary index to summary ind...
by kajalchopade071 Path Finder in Splunk Search 02-07-2022
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...