| Thread Info | |||||
|---|---|---|---|---|---|
| 
        I am writing a query which will give total time taken by a log/event for execution in milliseconds :
  index=xyz clus...
        
         
           by 
           
                
                    
                        Bhavika
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Splunk Search
           
           
              
               06-27-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Below is one of my fields. Quite complex,  I know It could be divided to more atomic values .. but it is not 
   [Au...
        
         
           by 
           
                
                    
                        kp_pl
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-27-2024
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi, I need help in extracting the time gaps in a multi-value field represented as Date.
  My data output looks like t...
        
         
           by 
           
                
                    
                        Steve_A200
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-26-2024
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Removing FQDN from field values
  Hi all, can anyone help me with framing the SPL query for the below requirement.
  ...
        
         
           by 
           
                
                    
                        RanjiRaje
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-26-2024
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have a lookup that has saved all apps installed on our deployment server. I need a query that checks all apps in th...
        
         
           by 
           
                
                    
                        Chris_Urman
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               06-26-2024
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello,
  I have an index with events, where events belong to a transaction (transaction_id). I am interested in trans...
        
         
           by 
           
                
                    
                        cjoelly
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Splunk Search
           
           
              
               06-26-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, is there a way of ignoring the time zone in the searches? Currently, Splunk will reinterpret the difference in ti...
        
         
           by 
           
                
                    
                        echalex
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               04-11-2012
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        "Find event in one search, get related events by time in another search"Found some related questions but could not fo...
        
         
           by 
           
                
                    
                        GEB
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hello Splunk team, I was troubleshooting one query with anomalydetection command (https://docs.splunk.com/Documentati...
        
         
           by 
           
                
                    
                        anna11
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               06-26-2024
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        I would like to extract the Message, Timestamp, and serial fields
  Then I would like to plot the target: Temp(315600...
        
         
           by 
           
                
                    
                        nkavouris
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Let's say I have a database that is pulled from an application on a daily basis into Splunk and accessed via DBXquery...
        
         
           by 
           
                
                    
                        LearningGuy
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi Splunkers, currently we are managing an Enterprise Splunk environment previously managed by another company. As sa...
        
         
           by 
           
                
                    
                        SplunkExplorer
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        How do I format a returned int into a phone number with the hyphen using the eval random function. 
   
  What I have...
        
         
           by 
           
                
                    
                        Substance82
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Still it find me difficult to understand logic of joining two indexes. Below the query which is almost suits my needs...
        
         
           by 
           
                
                    
                        kp_pl
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello!I have the following search: 
  
   | mstats avg(*) as * WHERE index=indexhere host=hosthere span=1 by host |ti...
        
         
           by 
           
                
                    
                        ChristofferK
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        index="ss-stg-dkp" cluster_name="*" AND namespace=dcx AND (label_app="composite-*" ) sourcetype="kube:container:main"...
        
         
           by 
           
                
                    
                        rahulmittal2391
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               06-25-2024
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Dears,
   
  I am trying to calculate how the total duration each user spends connected through VPN, their total onli...
        
         
           by 
           
                
                    
                        ibralah93
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Hi team,
  I need to extract the highlighted field in the below messege using regex... I have tried Splunk inbuilt fi...
        
         
           by 
           
                
                    
                        parthiban
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I have a dashboard X consisting of multiple panels (A, B, C) each populated with dynamic tokens. Panel A consists of ...
        
         
           by 
           
                
                    
                        cherrypick
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello everyone, I am a newbie in this field, I am looking forward to your help.
  I am using Eventgen to create data ...
        
         
           by 
           
                
                    
                        OnePiece
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        index=XXX sourcetype=XXX [|inputlookup Edge_Nodes_All.csv where Environment="*" AND host="*" |fields host] |fields cl...
        
         
           by 
           
                
                    
                        bmanikya
                    
                
           
             
             
               Loves-to-Learn Everything
             
           
           in
           Splunk Search
           
           
              
               06-12-2024
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all
  I have a search that works for a range of a few days (eg earliest=-7d@d), but when running for alltime it br...
        
         
           by 
           
                
                    
                        dataisbeautiful
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               06-24-2024
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        hi, i currently have this data and i would like to see if i can extract the date and time and see if it can display t...
        
         
           by 
           
                
                    
                        thaghost99
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-19-2024
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I see some post about rules for splunk logs.
  But I don't find a list of rules. My applications logs a  lot of lines...
        
         
           by 
           
                
                    
                        mclane41
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-23-2024
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  I want to create alert based on file received. Everyday at randomly we used to receive files. 
  ex. file name...
        
         
           by 
           
                
                    
                        Dharani
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-13-2024
             
           
         
        | 
		
		0
   | 
	  
	  6
	 |