| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hello Experts,
  I am new to Splunk and trying to build basic queries in Splunk to build use cases. Currently I am wo...
        
         
           by 
           
                
                    
                        parthou
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-24-2020
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        There are various event codes like eventID = "123" , eventID ="456", eventID = "789" . There are some "appID"   field...
        
         
           by 
           
                
                    
                        ASTARS47
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               07-23-2021
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi Team - I am trying to first search and  then aggregate results from following Splunk logs:
  Raw format: 
  "build...
        
         
           by 
           
                
                    
                        aag
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have a custom generating command that returns events to Splunk, however those events are not parsed, so the kv data...
        
         
           by 
           
                
                    
                        mlf
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-23-2021
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        I have a dashboard with multiple inputs. These inputs are like filters on top of basic search. I want
  1. if phone m...
        
         
           by 
           
                
                    
                        bhavika100
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all, 
  I'm trying to pull out the MAC addresses from a series of records which is mostly working using the follow...
        
         
           by 
           
                
                    
                        martinpugh
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-15-2012
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi All,
  I want to join two indexes and get a result. 
  Search Query -1
  index=Microsoft| eval Event_Date=mvindex(...
        
         
           by 
           
                
                    
                        alexspunkshell
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               07-21-2021
             
           
         
        | 
		
		0
   | 
	  
	  9
	 | |||
| 
        Hello Splunkers, I've been trying to solve this problem for a while now but I am still not able to NOT the contents o...
        
         
           by 
           
                
                    
                        lbogle
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               11-05-2014
             
           
         
        | 
		
		0
   | 
	  
	  10
	 | |||
| 
        Hello Team,
  
    rex field=_raw "string_list=%25(?<new_field1>\w+)%25"
  
   
  Above condition will get a word bet...
        
         
           by 
           
                
                    
                        Rakesh915473
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-23-2021
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hello Team,
  I'm very new to splunk, I have below two logs
  "message": "api.main REQ user1 10.10.44.76 \"GET /api/v...
        
         
           by 
           
                
                    
                        Rakesh915473
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-14-2021
             
           
         
        | 
		
		0
   | 
	  
	  12
	 | |||
| 
        HI,
  As mentioned in the subject, I want to perform operations on a list of values with a single value. To be cleare...
        
         
           by 
           
                
                    
                        jaysonpryde
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi,
  I have a summary index which gets indexed once in a month. I have a query which runs based on current month loo...
        
         
           by 
           
                
                    
                        sangs8788
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-23-2021
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hello my loves I have one quick question
   
  Lets say I have this two stringsAUJ.UEIEJ.829839.239383
  033.4788383....
        
         
           by 
           
                
                    
                        cindygibbs_08
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        My use case is the following, I have login information regarding which ASN a user logged in today on the field ASN an...
        
         
           by 
           
                
                    
                        JRamirezEnosys
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi
  I have the following JSON object.
  I would like to be able to ultimately create a bar chart with the following:...
        
         
           by 
           
                
                    
                        oKeNiDJE
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi,
  I need to know if it is possible to create bar chart with patterns to differentiate along with colors. I alread...
        
         
           by 
           
                
                    
                        mbasharat
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		1
   | 
	  
	  0
	 | |||
| 
        Hello Guys I have a sort of quick question that has been challanging me.
   
  I use this SPL to extract some info
  ...
        
         
           by 
           
                
                    
                        cindygibbs_08
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-13-2021
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I'm trying work with a bunch of system logs that are either ERROR or INFO logs. Each has a unique id # that is specif...
        
         
           by 
           
                
                    
                        muhan421
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Good afternoon, 
  I can't make sense of why I can't extract a definition from a particular csv. I doublechecked perm...
        
         
           by 
           
                
                    
                        victornajduch
                    
                
           
             
             
               Loves-to-Learn Everything
             
           
           in
           Splunk Search
           
           
              
               07-21-2021
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello - This should be a pretty simple search but I am new to Splunk.  
  I want to search events that have occurred ...
        
         
           by 
           
                
                    
                        dboyer313
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               11-14-2017
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How to calculate Latency Over Last Minute, Total Requests/min, LBs with Highest Unhealthy Host % in the load balancer...
        
         
           by 
           
                
                    
                        rajiv_r
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi,
  I have an use case where I have an if condition involving multiple comparisons. Based on its outcome, I  want t...
        
         
           by 
           
                
                    
                        payl_chdhry
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        If I run the below query for last 7 days, and if there is no data in logs matching condition index=abc "searchTerm" f...
        
         
           by 
           
                
                    
                        VS0909
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-22-2021
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Good morning, 
   
  I am trying to group the count by percentile however all is showing in 0% which is in correct: 
...
        
         
           by 
           
                
                    
                        joe06031990
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-21-2021
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hey Everyone, 
  I am trying to search for a field to see how much a customer is spending but there is a letter in fr...
        
         
           by 
           
                
                    
                        Callum_f
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-21-2021
             
           
         
        | 
		
		0
   | 
	  
	  1
	 |