Splunk Search

Splunk Search
Community Activity
tromero3
I have a search that outputs a table with two columns, one for log source one for total count (using stats count). I'...
by tromero3 Path Finder in Splunk Search 08-27-2020
0 2
0
2
lauraG85
Hi everybody,I've attached an error that occurs recently on the splunk infrastructure based on a SHC of 3 members and...
by lauraG85 Engager in Splunk Search 08-27-2020
0 1
0
1
uptoNoGood
HiWe have multiple automated tests running with different IDs and jenkins build number. One testid, build can have mu...
by uptoNoGood Explorer in Splunk Search 08-27-2020
0 0
0
0
hartfoml
This statement works: | eval Reason = if (Failure_Code = "0x12", "Account disabled, expired, locked out, logon hours...
by hartfoml Motivator in Splunk Search 08-27-2020
4 14
4
14
aa70627
I'm trying to get list of all fields in a index and oddly enough there's missing fields through the two methods below...
by aa70627 Communicator in Splunk Search 08-27-2020
0 2
0
2
gowtham08091
Hello,I would need to add the splunk search results to an existing lookup table.  Example.I have a splunk lookup tabl...
by gowtham08091 Explorer in Splunk Search 08-27-2020
0 2
0
2
Pajkow
Hi all, got the problem with sort,When I change the time format from default e.g. 2020-05-08 19:46:20 to this :08/05/...
by Pajkow Engager in Splunk Search 08-27-2020
0 1
0
1
k31453
Hi, I have base search which has appname field which lists all apps I have on splunk instance. I would like to output...
by k31453 Explorer in Splunk Search 08-27-2020
0 3
0
3
FraserC1
Hi,The search I have returns two events.One event has the following field:patches{}.name - This is patches that are t...
by FraserC1 Path Finder in Splunk Search 08-27-2020
0 2
0
2
foxychen
 8/24 updateI'm sorry, I didn't describe the problem well.I re-corrected the description.I need to find "parent" in t...
by foxychen Engager in Splunk Search 08-27-2020
0 7
0
7
Snehaan
Hi All,I have a search string like below: index=qrp STAGE IN ("*_LDD",TRADE_EVENT,SOPHIS_TRANS,SOPHIS_INSTR,ORDER_EVE...
by Snehaan Explorer in Splunk Search 08-27-2020
0 3
0
3
vijayakumarkb
I have a time format issue with Splunk logs . events are not coming correctly against the correct timestamp. in props...
by vijayakumarkb Explorer in Splunk Search 08-27-2020
0 14
0
14
Madere
Hi All,I followed Ian's blog (https://blog.arcusdata.io/splunk-mltk-to-predict-kb-articles) and it is a nice blog.But...
by Madere Observer in Splunk Search 08-27-2020
0 0
0
0
richhart_1963
I'm trying to use a lookup table to find records in my database, but I'm not having much luck. It may just be that I'...
by richhart_1963 Engager in Splunk Search 08-27-2020
0 3
0
3
alexruiz22
why am I getting "Encountered the following error while trying to save: An object with name=prices_lookup already exi...
by alexruiz22 New Member in Splunk Search 08-26-2020
0 0
0
0
splunkiesplunkh
Hi, I am looking to use predict command with multiple fields without typing all their names. For example I know it c...
by splunkiesplunkh Explorer in Splunk Search 08-26-2020
1 10
1
10
irishmanjb
Hello SplunkersI have an IIS log  that I am testing against and I have a need to test for a specified rangeThe _time ...
by irishmanjb Path Finder in Splunk Search 08-26-2020
0 17
0
17
UMDTERPS
We have a CSV with a field called application and another called IP. Within the field ip there are ip addresses and ...
by UMDTERPS Communicator in Splunk Search 08-26-2020
0 8
0
8
anirban_nag
I've a lookup file which have a mount list with respective servers. Now I have a script which logs the mount availabl...
by anirban_nag Explorer in Splunk Search 08-26-2020
1 6
1
6
unbelievable_ma
Hi,I have some documents that looks like this:  { "document_id": "some-id", "status": "some-status", "fields": ...
by unbelievable_ma Explorer in Splunk Search 08-26-2020
0 6
0
6
isoutamo
Hifor some reason fieldformat didn't work with foreach x,y,z. Sometimes it works mostly didn't. Here is same which di...
by SplunkTrust SplunkTrust in Splunk Search 08-26-2020
0 8
0
8
astatrial
Hi all,I have the Splunk_TA_windows and i noticed that there are multiple transforms-extract for field named src. For...
by astatrial Contributor in Splunk Search 08-26-2020
0 1
0
1
oompaloompa
I have an API that logs the start and end of each request. What I'd like to make sure I'm monitoring is the requests ...
by oompaloompa Loves-to-Learn Lots in Splunk Search 08-26-2020
0 1
0
1
winknotes
The following query is being used to model IOPs before and after moving a load from one disk array to another.  The "...
by winknotes Path Finder in Splunk Search 08-26-2020
0 6
0
6
vinod0313
HelloI have log like belowFEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadVa...
by vinod0313 Explorer in Splunk Search 08-26-2020
0 8
0
8
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...