| 0 | 1 | |||
| I try to use the query eval ID = if(ORG="MC",ID=substr(ID,-6),0) Basically, I want in my result, if ORG="MC", I want ... by phamxuantung Communicator in Splunk Search 12-13-2021 0 1 | 0 | 1 | ||
| Team,I'm newbie in writing Splunk queries. Could you please provide me guidance how to design a SPL for below use cas... by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-13-2021 0 7 | 0 | 7 | ||
| Hello!Could somebody please suggest if it is possible to do a map search search more effectively?What I am trying to ... by AndreiIssakov Explorer in Splunk Search 12-13-2021 0 6 | 0 | 6 | ||
| Hello, As an admin, I tried to delete a lookup table file. I had copied all the apps back to the search head cluster... by tkw03 Communicator in Splunk Search 12-13-2021 2 3 | 2 | 3 | ||
| We save hash values from our ids and I want to search for them. I would expected I can do it this way:index=blub id=s... by pk87 Engager in Splunk Search 12-13-2021 0 9 | 0 | 9 | ||
| Hi,I have two tables and in first table it contains 13 columns and from second table only one column i need to add to... by Narendra045 Explorer in Splunk Search 12-13-2021 0 3 | 0 | 3 | ||
| When running the following search for a 24hr period it is always being auto-finalized due to disk usage limit of 100M... by nateNpgh Loves-to-Learn Lots in Splunk Search 12-13-2021 0 13 | 0 | 13 | ||
| TYPEMonthKPI_1KPI_2GLOBALOct'217624LOCALOct'214667 I'm searching the table like | search TYPE="GLOBAL" | search Mont... by lostcauz3 Path Finder in Splunk Search 12-12-2021 0 2 | 0 | 2 | ||
| Hi there,I have 2 separate queries that I built using Rex.1. This query captures the logg on and logg off status of t... by GRC Path Finder in Splunk Search 12-11-2021 0 2 | 0 | 2 | ||
| I am encountering an issue when using a subsearch in a tstats query. Specifically, I am seeing the count of events in... by GindiKhangura Explorer in Splunk Search 12-10-2021 0 3 | 0 | 3 | ||
| Hi, hoping to get some more insight on my current problem. My problem is the following I am using a where clause to c... by splunk3341 Loves-to-Learn Lots in Splunk Search 12-10-2021 0 2 | 0 | 2 | ||
| I am attempting to use a search from IT Essentials Learn named "Alert when host stops reporting data - Linux - IT Ess... by jackjack Path Finder in Splunk Search 12-10-2021 0 3 | 0 | 3 | ||
| RAWDATA:user_namemachine_nameevent_namelogon_timeuser1machine1logon12/9/2021 7:20user1machine1logout12/9/2021 7:22use... by psmp Explorer in Splunk Search 12-10-2021 0 10 | 0 | 10 | ||
| Hi, I would have this need, that is to carry out a search that extracts all users who use iphone with SO = 9. * and t... by giorgioanastasi Explorer in Splunk Search 12-10-2021 0 7 | 0 | 7 | ||
| Hi everyone, I'm new here and having a problem filtering of numbers from a message. message: Generated non direct de... by radi09 Engager in Splunk Search 12-10-2021 0 7 | 0 | 7 | ||
| Aloha, We’ve a reporting requirement to create a Pie chart using 2 input files. So far we’ve successfully created Ba... by marceloalejandr Path Finder in Splunk Search 12-10-2021 0 9 | 0 | 9 | ||
| Need to declare in spl Include only those file that has ended with date not .bz2 (I don’t want to use NOT) Here is s... by indeed_2000 Motivator in Splunk Search 12-10-2021 0 3 | 0 | 3 | ||
| Hi,I'm trying to get wildcard lookups to work using the "lookup" function. I've followed guidance to set up the "Matc... by geomore Explorer in Splunk Search 12-10-2021 0 7 | 0 | 7 | ||
| I hate hardcoding dynamic things. Sooner or later those thing break. I have data with fields ... forecast_2020=400, f... by usd0872 Path Finder in Splunk Search 12-10-2021 0 4 | 0 | 4 | ||
| Hello there.I was wondering... is there any way to generate _events_ in search?I mean, I know of the makeresults comm... by PickleRick SplunkTrust 0 6 | 0 | 6 | ||
| | makeresults| eval _raw = "user_name machine_name event_name logon_timeuser1 machine1 logon 12/9/2021 7:20user1 mach... by psmp Explorer in Splunk Search 12-09-2021 0 3 | 0 | 3 | ||
| Hey I am having difficulties trying to extract fields from my splint logs. They are in the format of’{“field”: “value... by Alanshiau717 New Member in Splunk Search 12-09-2021 0 1 | 0 | 1 | ||
| Hi,When we use sedcmd command to mask data it is Indexed time extractions and when we use transforms to mask data it ... by VijaySrrie Builder in Splunk Search 12-09-2021 0 2 | 0 | 2 | ||
| I have a date column that I'm trying to convert to %m/%d/%Y. The date stamp is a little complex but I got it to work ... by rhilderbrand1 Observer in Splunk Search 12-09-2021 0 4 | 0 | 4 |