Splunk Search

Splunk Search
Community Activity
ssaini5
Hello, I am generating the following table in splunk dashboard using the following query from raw data file: Two type...
by ssaini5 Explorer in Splunk Search 09-09-2020
0 1
0
1
bapun18
Hi Folks,i have a requirement to create relevant query in Splunk to retrieve daily count of records from Kafka server...
by bapun18 Communicator in Splunk Search 09-09-2020
0 1
0
1
vishtrip
I have an issue where the raw data shows up with data but when I query it, all the other fields come up as empty.  I ...
by vishtrip New Member in Splunk Search 09-09-2020
0 1
0
1
raytroy
I have tried many ways to get the difference between two numbers. Here is what I have tried. try 1: event=subscript...
by raytroy New Member in Splunk Search 09-09-2020
0 3
0
3
FraserC1
I have the following search:   index="automox" sourcetype="automox:devices" server_group="Windows Server Pilot" | ded...
by FraserC1 Path Finder in Splunk Search 09-09-2020
0 10
0
10
willadams
I have 2 large data sets Data Set 1 (Assets) contains information about devices.  For example the dataset will have t...
by willadams Contributor in Splunk Search 09-09-2020
0 5
0
5
Manasi25
I m using append query multiple times for different searches for same index.Its parsing my job. Please advise solutio...
by Manasi25 Explorer in Splunk Search 09-09-2020
0 13
0
13
Noob_splunker
Basically, I want to get duration based on the time picker.Example, If i select Year to Date in the time picker, i wa...
by Noob_splunker Explorer in Splunk Search 09-09-2020
0 1
0
1
sphiwee
Id like to be able to display only the top Total values, struggling with this
by sphiwee Contributor in Splunk Search 09-09-2020
0 4
0
4
garumaru
Hi Guys,I am working on searching data from Servicenow ticket, and tickets normally have some status for example:#Tic...
by garumaru Explorer in Splunk Search 09-09-2020
0 2
0
2
benhooper
Our data input contains two timestamp fields — creation_time and modification_time — both formatted in line with ISO ...
by benhooper Communicator in Splunk Search 09-09-2020
0 11
0
11
djreschke
I have a scheduled report that runs monthly for the previous month. It runs a cron job 00 08 1 * *. I need to go back...
by djreschke Communicator in Splunk Search 09-08-2020
0 10
0
10
puneetkharband1
I am trying to write splunk search where I have 2 conditions and my query returns the results based on that for examp...
by puneetkharband1 Path Finder in Splunk Search 09-08-2020
0 3
0
3
sy_price
Apologies in advance as im new to SplunkIm trying to put a name to each line below. Each src to dst is a business cli...
by sy_price Engager in Splunk Search 09-08-2020
0 4
0
4
marting456
I created a calculated field in my datamodel, freight_service_error_list_martin, called loggerPackage that is the ext...
by marting456 Explorer in Splunk Search 09-08-2020
0 4
0
4
sahil237888
Hi ,Can anyone help me- how to get average of the all the columns at the bottom.The output should be like - ctime tot...
by sahil237888 Path Finder in Splunk Search 09-08-2020
0 4
0
4
buchs
While I am trying to extract a new field, I get this error Error in 'SearchOperator:loadjob': The search artifact fo...
by buchs Explorer in Splunk Search 09-08-2020
1 10
1
10
cee137
I'm not sure if there is an answer to this question but as of right now, I'm using fieldsummary to get a better under...
by cee137 Explorer in Splunk Search 09-08-2020
0 2
0
2
victorsalazar
Hello Splunk CommunityI would like to know if I can create a new column field from a multivalue fieldMV field = 1, 2,...
by victorsalazar Explorer in Splunk Search 09-08-2020
0 3
0
3
jsven7
I have a lookup table. Let's say the lookup table contains a column called "a". The "a" column contains a list of ind...
by jsven7 Communicator in Splunk Search 09-08-2020
0 3
0
3
cdstealer
Hi,  A bit of a strange one that I can't workout.  I have a deployer server and a search head in one DC and 2 searchh...
by cdstealer Contributor in Splunk Search 09-08-2020
0 8
0
8
pallavi_prabhu_
We have created http event with below command: http://localhost:8088/services/collectorBody:{     "sourcetype":"trial...
by pallavi_prabhu_ Explorer in Splunk Search 09-08-2020
0 5
0
5
mag85032
How do we come to conclusion which Data Model will be applied to specific use case?raw data like id: 8766899, timesta...
by mag85032 Engager in Splunk Search 09-08-2020
0 1
0
1
marcos_eng1
Dear Community, I Have a csv file with no timestamp with the data, I only have a timestamp on the beggining of the fi...
by marcos_eng1 Explorer in Splunk Search 09-08-2020
0 4
0
4
VS0909
"Field1" can have one value as either 'yes' or 'no'. I want to calculate count for 'yes' as count1 and count for 'no'...
by VS0909 Communicator in Splunk Search 09-08-2020
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...