Splunk Search

Splunk Search
Community Activity
yudzhin
Dear Splunkers, I have a flow of events and need to perform alarm when some value, e.g. metricValue is greater than t...
by yudzhin Explorer in Splunk Search 05-21-2021
0 0
0
0
jaibalaraman
Hi team I tried the below spl eval command index=aws Website="*"| stats count(eval(match(User_Agent, "Firefox"))) as ...
by jaibalaraman Path Finder in Splunk Search 05-21-2021
0 6
0
6
wcastillocruz
Hello dear community,I have a splunk search where I look for all the events that occur over a specific period of time...
by wcastillocruz Path Finder in Splunk Search 05-21-2021
0 0
0
0
yogeshpunia66
How to use metrics index to store metrics data from events on SH?Does is it possible to have  multiple values and mul...
by yogeshpunia66 Loves-to-Learn in Splunk Search 05-21-2021
0 0
0
0
nischal45
Need help with a query please:I have ticket data where the life cycle is Assigned, Work in Progress, Fixed, Closed an...
by nischal45 Engager in Splunk Search 05-21-2021
0 3
0
3
georgear7
I have one scheduled report which will provide below table results in email. Requirement is to color the 'Validation ...
by georgear7 Communicator in Splunk Search 05-21-2021
0 2
0
2
DSan
In general terms, I've been trying to create a search that can perform a subsearch using a few fields that are presen...
by DSan New Member in Splunk Search 05-21-2021
0 0
0
0
haripotu
0
1
josephpe
I am trying to find events based on when they were initially logged and grouped by some column. For example,  from th...
by josephpe Explorer in Splunk Search 05-21-2021
0 3
0
3
MaratD
Hi all,I need to create an alert based on a success rate less than a specific value. My data is as follows:store = "s...
by MaratD Explorer in Splunk Search 05-21-2021
0 3
0
3
akankshayadav
I have a file which is being indexed(say today) and then again indexed after updating(say tomorrow). I have to compar...
by akankshayadav Path Finder in Splunk Search 05-21-2021
0 9
0
9
dmbr
Hi Splunkheads, Need some advice here. I have built a simple lookup table and simple search for known bad ip addresse...
by dmbr Explorer in Splunk Search 05-20-2021
0 1
0
1
shreyasathavale
I have admin user and power user (role=power), when i search a particular index (iis_web) it does not return the out...
by shreyasathavale Communicator in Splunk Search 05-20-2021
0 3
0
3
user93
Hi,So I have a goal to count user visits, but the log polls too frequently, so we are going to define a visit by one ...
by user93 Communicator in Splunk Search 05-20-2021
0 3
0
3
kbohlken
I want to add more columns that will show the sessions.  Such as sudo su ssh etc.  Currently I have this:index="name ...
by kbohlken Observer in Splunk Search 05-20-2021
0 1
0
1
johefu
Hello all,Running the following search (direct count) at different times of the day for the same time period I receiv...
by johefu Loves-to-Learn in Splunk Search 05-20-2021
0 2
0
2
Logan20
Hello!!I have a field value that looks like:abcd124567-1609173498I only want to remove abcd-1609173498 and have the 1...
by Logan20 New Member in Splunk Search 05-20-2021
0 1
0
1
splunkerer
I have a data set as seen below.exec                   arguments/bin/shsh-cuname -p ** /dev/null/sbin/ldconfig/bin/sh...
by splunkerer Path Finder in Splunk Search 05-20-2021
0 4
0
4
RonD
I am creating a search that detects compliance received from palo alto signatureswe are receving 4 sets of dates:app-...
by RonD Explorer in Splunk Search 05-20-2021
0 2
0
2
Godspeed_74
I am trying to fill the null values and using a datamodel. I want to use tstats and fill null values will "Null" usin...
by Godspeed_74 Loves-to-Learn Lots in Splunk Search 05-20-2021
0 6
0
6
szukacz
Hi team,I'm trying to build a search which will search for the alerts which have been triggered for a hosts during sp...
by szukacz Engager in Splunk Search 05-20-2021
0 3
0
3
Sangu
HiI need to extract hostname or IP address from raw log. My log looks like below:somerandometest  host: abc@email.com...
by Sangu Explorer in Splunk Search 05-20-2021
0 2
0
2
jugarugabi
Hi, I have a csv file that is updated by a script once a minute. The output is similar to: time,queuename,vpn,last-me...
by jugarugabi Path Finder in Splunk Search 05-20-2021
0 4
0
4
srinivasgowda
Hello team, I am trying to ignore the value "Total" if its concurrent Os_type matches "Linux" Below is what I tried.|...
by srinivasgowda Explorer in Splunk Search 05-20-2021
0 3
0
3
stephenreece78
hi all, newbee question here but i can't seem to find an answer. I am trying to create a timechart table grouped tabl...
by stephenreece78 Engager in Splunk Search 05-20-2021
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...