Splunk Search

Splunk Search
Community Activity
rilee
I have the following sample data returned that I'd like to extract 2 fields out of it: 1) The value after the "T "  a...
by rilee Explorer in Splunk Search 06-30-2021
0 3
0
3
cmarrott
  <query>"$ps_fn$" |rex field=message "(?<Http>HttpStatus): (?<status>\\d+)" | eval status=(status, "4%")...
by cmarrott Explorer in Splunk Search 06-30-2021
0 5
0
5
keithyap
I have multiple deployment servers.The global deployment server is to distribute basic configurations and also config...
by keithyap Path Finder in Splunk Search 06-30-2021
0 5
0
5
ervinsmith
Creating a dashboard to track when users badge into and out of different areas.Problem: If I do a basic search for a ...
by ervinsmith Explorer in Splunk Search 06-30-2021
0 2
0
2
hemantbhatta
As I am indexing the data, I notice that apart from the 'sources' that are appearing correctly (/var/log/filename.gz ...
by hemantbhatta Explorer in Splunk Search 06-30-2021
0 5
0
5
dtccsundar
Hi ,My wish to get the difference between yesterday and todays Pass % and fail % for different sourcetypes .I have tr...
by dtccsundar Path Finder in Splunk Search 06-30-2021
0 4
0
4
felipesodre
Hi there,First of all, thank you for any comment.I am looking for a way to identify if I have any index missing acros...
by felipesodre Path Finder in Splunk Search 06-30-2021
0 1
0
1
neeravmathur
Hi Team,We noticed that every time a Indexer is restarted, the search head and the Indexer itself pops up with a mess...
by neeravmathur Path Finder in Splunk Search 06-30-2021
0 0
0
0
splunkrocks2014
Hi. I have a lookup object named user_email which contains a notified email list. If there is at least an event foun...
by splunkrocks2014 Communicator in Splunk Search 06-30-2021
0 5
0
5
pavaninpdl
Hi team, I have search results with CUID is the email(I will append my company domain to CUID, so that mail will go...
by pavaninpdl New Member in Splunk Search 06-30-2021
0 4
0
4
AssafLowenstein
Hi, The question was asked before but I couldn't find a good answer anywhere. Here goes... I have a search result wi...
by AssafLowenstein Explorer in Splunk Search 06-30-2021
0 5
0
5
kalianov
Hi splunkers !!! Need help. I used eval to create a field with the email address for some users: search myquery.......
by kalianov Path Finder in Splunk Search 06-30-2021
0 6
0
6
mikeyty07
I am trying to make a report based on the url, and avg response that certain url is taking. I am able to get the logs...
by mikeyty07 Communicator in Splunk Search 06-29-2021
0 8
0
8
ebs
Hi,I want to look at each response_time value for each Tier, and count the amount of response times that are above an...
by ebs Communicator in Splunk Search 06-29-2021
0 6
0
6
mrrijo
Following produces values for a and b in Splunk 8.2.0, but in 8.0.1, values of a is emptyIs there any changes in beha...
by mrrijo New Member in Splunk Search 06-29-2021
0 2
0
2
simpkins1958
User with these capabilities fails, but ADMIN user works. This SPL works fine when logged in as ADMIN, but does not ...
by simpkins1958 Contributor in Splunk Search 06-29-2021
0 4
0
4
bhilim
Hello ,I would really appreciate  your help in creating a splunk search query to find out the anomaly over size from ...
by bhilim Loves-to-Learn Lots in Splunk Search 06-29-2021
0 2
0
2
thenormalone
In one of the search strings, I have an event from which i extract the correlation ids and in turn want to search thr...
by thenormalone Path Finder in Splunk Search 06-29-2021
0 3
0
3
middlemiddle
I want to set dynamic SLA's for File Processing.  In order to do this I need to:1. get the earliest HH:MM:SS the job ...
by middlemiddle Explorer in Splunk Search 06-29-2021
0 4
0
4
cesaccenturefed
I'm trying to do a search that finds IPv6 addresses. Currently our field src_ip has both IPv4 and IPv6 in it. How can...
by cesaccenturefed Path Finder in Splunk Search 06-29-2021
2 5
2
5
appu
log1 : user_id , status=interrupt,log2 : user_id, status = successHi All,I want to find user_ids that failed due to a...
by appu Explorer in Splunk Search 06-29-2021
0 1
0
1
qysplunk
Hi, I have 2 sample logs and I need to combine them into 1 query to grab the "Accesses" values,Due to the log format ...
by qysplunk Loves-to-Learn Lots in Splunk Search 06-29-2021
0 0
0
0
TheBravoSierra
Below is an example of what I want to accomplish: If x="example" and y="success", return true for this segment. If x=...
by TheBravoSierra Path Finder in Splunk Search 06-29-2021
0 1
0
1
RedHonda03
We have data which is not being indexed that needs to be searched. I've been told by our Splunk admin team that the d...
by RedHonda03 Explorer in Splunk Search 06-29-2021
0 3
0
3
sarwshai
Hi There,How do i Exclude Source IP and Destination IP from results if they belong to same private ip range? For e.g....
by sarwshai Communicator in Splunk Search 06-29-2021
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...