Splunk Search

Splunk Search
Community Activity
mbasharat
Hi all,I have below situation. Actual query is much longer so I just need the logic.cve is the multivalue field. It i...
by mbasharat Builder in Splunk Search 08-06-2020
0 0
0
0
icosine
How do I combine a field with similar value (where one value might or might not exist in one of the field) and use st...
by icosine Engager in Splunk Search 08-06-2020
0 2
0
2
sylim_splunk
If a report is accelerated in the search app, are the other apps supposed to benefit from its acceleration? The repor...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 08-06-2020
2 1
2
1
tbrown
I have a transaction of events. In the first event of the transaction, it contains an event that I am using| rex fiel...
by tbrown Path Finder in Splunk Search 08-06-2020
0 1
0
1
ohbuckeyeio
I have a search that performs a basic dbxquery connection and SQL search.  If the database table were to be dropped o...
by ohbuckeyeio Communicator in Splunk Search 08-06-2020
0 0
0
0
baustin612
I have a search that is giving me this data set:ID             status       Stampalex         esb            15959898...
by baustin612 Explorer in Splunk Search 08-06-2020
0 4
0
4
Username1
So my data structure has four columns: "Month", "Status", "Accepted", "Value". As the title suggest I'm trying to det...
by Username1 Path Finder in Splunk Search 08-06-2020
0 11
0
11
dwibedi03
There is a command fields in my logs and consists of unix commands.One value is /usr/bin/ssh -q -o ConnectTimeout=5 -...
by dwibedi03 Explorer in Splunk Search 08-06-2020
0 6
0
6
Username1
Hey community I have my data in both MySQL and in Splunk. I'm trying to mimic the MySQL queries in Splunk so I can ma...
by Username1 Path Finder in Splunk Search 08-06-2020
0 8
0
8
bburns2122
I am trying to get the Date (altering _time in a specific format shown below), number of events (which I am using sta...
by bburns2122 Explorer in Splunk Search 08-06-2020
0 7
0
7
noman377
Hi, I have a stat on eventtype like thisindex=xyz | stats count by eventtypeThis query generates:All_logs  = 14Error ...
by noman377 Explorer in Splunk Search 08-06-2020
0 5
0
5
jiaqya
I need to take one peer down for maintenance, so i do splunk stop on it.cluster handles and brings cluster back to va...
by jiaqya Builder in Splunk Search 08-06-2020
0 9
0
9
surekhasplunk
Hi,I have below in column default_message1st regex :default_message= <14>shell: cmd by abcd: mkdir testcan you please...
by surekhasplunk Communicator in Splunk Search 08-06-2020
0 3
0
3
rkris
I've created a dropdown input field that shows the user accounts that are locked out And this is the search string th...
by rkris Explorer in Splunk Search 08-06-2020
0 2
0
2
Yokova
Hello All, I am looking for a solution to establish a kind of IT inventory, based on logins. Is there any working sol...
by Yokova New Member in Splunk Search 08-05-2020
0 1
0
1
qiuxiaoping
hello , i have many logs like:"_time1 user=A eventid =45""_time2 user=A eventid=46""_time3 user=A eventid=48""_time4 ...
by qiuxiaoping New Member in Splunk Search 08-05-2020
0 5
0
5
splunkuserCA1
I need help on doing cumulative percentiles, such as p90, over a period of time. This is different from rolling avera...
by splunkuserCA1 Path Finder in Splunk Search 08-05-2020
0 3
0
3
RajanRaj
I want to compare (OWNER)(TABLE_NAME) to (OWNER_New)(TABLE_NAME_New). And once the value matched then want to find di...
by RajanRaj New Member in Splunk Search 08-05-2020
0 1
0
1
Jeronimo317
Hi, I am very new to SPLUNK and inherited an environment without much documentation. Can anyone help with the followi...
by Jeronimo317 Explorer in Splunk Search 08-05-2020
0 1
0
1
summerura
Hi Splunkers, some examples from our logs.. [Time:11:03:01] [Function:upload] [User:aaa][Time:11:03:10] [Function:upl...
by summerura Explorer in Splunk Search 08-05-2020
0 1
0
1
alexspunkshell
Hi Guys, Syslog is sent to forwarder IP through TCP 514 port. I am unable to receive those syslog in forwarder or ind...
by alexspunkshell Contributor in Splunk Search 08-05-2020
0 2
0
2
dpdwibedy
Hi There,Need help to find the  status code error rate  where  status code is >400.I have below Query to time chart t...
by dpdwibedy Explorer in Splunk Search 08-05-2020
0 4
0
4
jerinvarghese
Hi All, Need help in getting the data for those Downtime > 15 mins. below is the query am using.  index=opennms "uei....
by jerinvarghese Communicator in Splunk Search 08-05-2020
0 3
0
3
brc55
Hello,I'm trying to put a query together to monitor/view emails being sent externally to a personal domain. i.e. john...
by brc55 Explorer in Splunk Search 08-05-2020
0 3
0
3
mcbradford
The following search is not giving me what I want.. sourcetype="sidewinder" action="blocked" direction="internal" | ...
by mcbradford Contributor in Splunk Search 08-05-2020
0 6
0
6
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...