Splunk Search

Splunk Search
Community Activity
agar1122
I have this kind of data, Event IDEvent StepStatus 1001SUCCESS 1002SUCCESS 1003FAILURE 1004FAILURE 1005SUCCESS 1006FA...
by agar1122 New Member in Splunk Search 08-28-2020
0 1
0
1
mvasquez21
My boss has asked me to create a chart that shows the number of fired alerts (y-axis) by day of the month (x-axis). I...
by mvasquez21 Path Finder in Splunk Search 08-28-2020
0 6
0
6
mvasquez21
My boss has asked me to create a chart that shows the number of fired alerts (y-axis) by day of the month (x-axis). I...
by mvasquez21 Path Finder in Splunk Search 08-28-2020
0 3
0
3
dkgs
Hi,In a single event, we have a field named username which is occurring multiple time in the events in raw data and u...
by dkgs Communicator in Splunk Search 08-28-2020
0 3
0
3
Petri-X
Hi all,I searching web server's centralized logs and getting results from multiple servers. But those servers belongs...
by Petri-X Explorer in Splunk Search 08-28-2020
0 4
0
4
adcom26
Hello when i make a search i got an hour plus 
by adcom26 Explorer in Splunk Search 08-28-2020
0 6
0
6
HeinzWaescher
HI, I want to create tables that are easier to read and round the numbers to hundreds or thousands. Like 22113 -> 221...
by HeinzWaescher Motivator in Splunk Search 08-28-2020
0 6
0
6
Vicky84
I want to keep updating new records to Splunk lookup table and not writing records again for existing users, even if ...
by Vicky84 Explorer in Splunk Search 08-28-2020
0 6
0
6
CyberCyberSec
I am trying to run a query where it compares a search result field against a field in the lookup table. I was able to...
by CyberCyberSec Loves-to-Learn in Splunk Search 08-27-2020
0 4
0
4
kaeleyt
Hi all,My team is embarking on the Summary Indexing journey as our environment is getting larger. We have various ten...
by kaeleyt Path Finder in Splunk Search 08-27-2020
0 1
0
1
unbelievable_ma
Hi,Let's say I can get this table using some Splunk query.idstages1key1,100key2,200key3,300 2key1,50key2,150key3,2503...
by unbelievable_ma Explorer in Splunk Search 08-27-2020
0 4
0
4
irvindominguezs
"https://api.internal.t-mobile.com/customer-credit/v3/pre-screen-credit-offer/personal": Read timed out; nested excep...
by irvindominguezs Explorer in Splunk Search 08-27-2020
0 1
0
1
ldefoor
First off, I am very new to Splunk and that may be my downfall. Our latest Splunk guru has left and this fell to me r...
by ldefoor New Member in Splunk Search 08-27-2020
0 5
0
5
net1993
HelloI have this command:| metadata type=sourcetypes index=wineventlogThe problem is that there are returned multiple...
by net1993 Path Finder in Splunk Search 08-27-2020
0 2
0
2
dkgs
Hello,We need to find the highest CPU consumed Process in the windows machine, not the total highest cpu.Please help ...
by dkgs Communicator in Splunk Search 08-27-2020
0 4
0
4
tromero3
I have a search that outputs a table with two columns, one for log source one for total count (using stats count). I'...
by tromero3 Path Finder in Splunk Search 08-27-2020
0 2
0
2
lauraG85
Hi everybody,I've attached an error that occurs recently on the splunk infrastructure based on a SHC of 3 members and...
by lauraG85 Engager in Splunk Search 08-27-2020
0 1
0
1
uptoNoGood
HiWe have multiple automated tests running with different IDs and jenkins build number. One testid, build can have mu...
by uptoNoGood Explorer in Splunk Search 08-27-2020
0 0
0
0
hartfoml
This statement works: | eval Reason = if (Failure_Code = "0x12", "Account disabled, expired, locked out, logon hours...
by hartfoml Motivator in Splunk Search 08-27-2020
4 14
4
14
aa70627
I'm trying to get list of all fields in a index and oddly enough there's missing fields through the two methods below...
by aa70627 Communicator in Splunk Search 08-27-2020
0 2
0
2
gowtham08091
Hello,I would need to add the splunk search results to an existing lookup table.  Example.I have a splunk lookup tabl...
by gowtham08091 Explorer in Splunk Search 08-27-2020
0 2
0
2
Pajkow
Hi all, got the problem with sort,When I change the time format from default e.g. 2020-05-08 19:46:20 to this :08/05/...
by Pajkow Engager in Splunk Search 08-27-2020
0 1
0
1
k31453
Hi, I have base search which has appname field which lists all apps I have on splunk instance. I would like to output...
by k31453 Explorer in Splunk Search 08-27-2020
0 3
0
3
FraserC1
Hi,The search I have returns two events.One event has the following field:patches{}.name - This is patches that are t...
by FraserC1 Path Finder in Splunk Search 08-27-2020
0 2
0
2
foxychen
 8/24 updateI'm sorry, I didn't describe the problem well.I re-corrected the description.I need to find "parent" in t...
by foxychen Engager in Splunk Search 08-27-2020
0 7
0
7
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors