Splunk Search

Splunk Search
Community Activity
user333
Hello,I am having trouble with filtering fields extracted using rex as follows:rex max_match=0 field=sessions_as_clie...
by user333 Engager in Splunk Search 08-19-2020
0 2
0
2
vinod0313
I have a string like this below{ABC,DEF,GHI,JKL}i am able to show it as below in my result 1. ABC    DEF    GHI    JK...
by vinod0313 Explorer in Splunk Search 08-19-2020
0 1
0
1
beetlegeuse
I'm calling a REST API using curl on a UF to collect data from a remote DataPower appliance; the output is in JSON fo...
by beetlegeuse Path Finder in Splunk Search 08-19-2020
0 2
0
2
benhooper
We're using a REST API to connect to a case / monitoring system and retrieve any data newer than the last run. This d...
by benhooper Communicator in Splunk Search 08-19-2020
0 5
0
5
DCUpro
Hi all,I'm a bit of a newbie to splunk but I was trying to create a dashboard using the stats count by function for a...
by DCUpro Explorer in Splunk Search 08-19-2020
0 2
0
2
surekhasplunk
HiI am using below query to get the details of alarms which has (one Warning and one OK status) or (one Critical and ...
by surekhasplunk Communicator in Splunk Search 08-19-2020
0 8
0
8
Lucie99
Hi everyone, I'm looking for how to add information on a graphical point. My graph shows only an average and an ofnum...
by Lucie99 Explorer in Splunk Search 08-19-2020
0 2
0
2
friskyapple
I've got a few different tables, all csv, that provide different information.The main events table includes a bunch o...
by friskyapple Explorer in Splunk Search 08-19-2020
0 1
0
1
eidil
I am trying to use data models in my subsearch but it seems it returns 0 results.| datamodel disk_forecast C_drive se...
by eidil Explorer in Splunk Search 08-18-2020
0 4
0
4
mitag
Getting this informational message when running "stats count" commands:This search uses deprecated 'stats' command sy...
by mitag Contributor in Splunk Search 08-18-2020
0 12
0
12
chtmai
I have this data coming in every minute to monitor application performance:  { "events": [ { "appId": "mock-app...
by chtmai Explorer in Splunk Search 08-18-2020
0 5
0
5
PN3000
Hi,Data was indexed 4 hours ago. At the time i was able to see the data when searching the relevant index. 4 hours la...
by PN3000 Loves-to-Learn in Splunk Search 08-18-2020
0 2
0
2
mitag
Running a sample search suggested by "Add sparklines to search results" in Splunk Documentation for the latest versio...
by mitag Contributor in Splunk Search 08-18-2020
0 1
0
1
bloizides
I am aware that answers.splunk.com has changed engines and is now community.splunk.com. The migration announcement st...
by bloizides Observer in Splunk Search 08-18-2020
0 4
0
4
daniel_althoff8
Is anyone aware of a dashboard visualization that will allow me to edit a lookup table in the UI? Rather than using L...
by daniel_althoff8 Loves-to-Learn in Splunk Search 08-18-2020
0 0
0
0
vishaltaneja070
License Usage by Each Indexer : Need to find license usage by each indexer.
by vishaltaneja070 Motivator in Splunk Search 08-18-2020
0 2
0
2
vinod0313
I got above result from my splunk query:  index="cx_aws" source="notifications-service"|stats count by tokenValidator...
by vinod0313 Explorer in Splunk Search 08-18-2020
0 1
0
1
goodsellt
Hello! I've been playing around with the timechart command and spanning, however, there is an issue I'm having when ...
by goodsellt Contributor in Splunk Search 08-18-2020
2 17
2
17
sstanlee
Consider the below types of eventsfields  :     OS         transaction      numbersEvents:     Win        purchased  ...
by sstanlee Explorer in Splunk Search 08-18-2020
0 6
0
6
adnankhan5133
We have the following SPL query which generates statuses (i.e. "Success", "Failure", "Warn") for various different "s...
by adnankhan5133 Communicator in Splunk Search 08-18-2020
0 6
0
6
marcluescher
Hi there,digging deeper into the REST API and XML parsing. When running an XML status command on our Ironport I get t...
by marcluescher Explorer in Splunk Search 08-18-2020
0 1
0
1
rleyba828
Hi team, I have a highly simplified set of log entries similar to the sample data below: |makeresults |eval dummy="...
by rleyba828 Explorer in Splunk Search 08-18-2020
0 4
0
4
lstewart_splunk
I have this data_timeEventCodeMessage2020-06-16T19:48:53+00:004136Too late now2020-06-16T19:49:53+00:001234I don't kn...
by lstewart_splunk Splunk Employee Splunk Employee in Splunk Search 08-18-2020
0 3
0
3
codichulo
Heres what i'm trying to accomplish: requestID               status123456                   errored321654            ...
by codichulo Loves-to-Learn in Splunk Search 08-18-2020
0 3
0
3
vrulev_algn
Hi,I can't grasp the concept of dedup_splitvals. I was writing search for a pie chart on my dashboard, something like...
by vrulev_algn Loves-to-Learn in Splunk Search 08-18-2020
0 0
0
0
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...