Splunk Search

Splunk Search
Community Activity
MOHITJOSHI
i have a field "avg_time" which i want to display in descending order. tried sort -avg_time but didn't worked eval n...
by MOHITJOSHI Engager in Splunk Search 04-07-2020
0 1
0
1
mnarmada
Hello, I have a data from two different sourcetypes. In that data, I have two specific columns where in I have to ch...
by mnarmada Path Finder in Splunk Search 04-07-2020
0 6
0
6
uhaba
We noticed that Microsoft OWA logs produce a repeating field. How can we make them into individual ones instead of ju...
by uhaba Explorer in Splunk Search 04-07-2020
0 3
0
3
rashi83
I am using HTTP events collector on a search head directly. On this SH I am using API token to connect to get OKTA lo...
by rashi83 Path Finder in Splunk Search 04-07-2020
0 1
0
1
willcwhite
I have an app on a deployment server that takes in XML data, this app includes a props.conf with KV_MODE=xml. When I...
by willcwhite Explorer in Splunk Search 04-07-2020
0 1
0
1
leandromatperei
Hello everyone, I have the attached file that is generated every night through my client's internal system and I nee...
by leandromatperei Path Finder in Splunk Search 04-07-2020
0 6
0
6
antb
Hi and thank you in advance. I've simplified the problem for brevity sake. I'm trying to return multiple fields by ...
by antb Path Finder in Splunk Search 04-07-2020
0 2
0
2
HattrickNZ
hi there THis is my sample data. I want to use the heat map option and highlight the max and min per each column. S...
by HattrickNZ Motivator in Splunk Search 04-07-2020
0 1
0
1
anz999
I would like to do some math operation of retrieved count of each values. Eg: 318*5.5 + 418*2.5 + 54*5 + 83*2 and g...
by anz999 Loves-to-Learn Lots in Splunk Search 04-07-2020
0 3
0
3
iiooiiooiioo
I have this splunk search: host=app-dev-001 terminating | convert timeformat="%Y-%m-%d" ctime(_time) AS date | sort ...
by iiooiiooiioo Explorer in Splunk Search 04-07-2020
0 1
0
1
Jarohnimo
Below are clamav logs, I would like to create two new fields. one called: log_level one callled: message log_level ...
by Jarohnimo Builder in Splunk Search 04-07-2020
0 1
0
1
pgadhari
I am getting below error when the page first loads, after that when I manually select "Last 1 week" in the dropdown, ...
by pgadhari Builder in Splunk Search 04-07-2020
0 4
0
4
jagdeepgupta813
HI All, Please help me to debug the issue to join two searches based on common field. I have two indexes which has ...
by jagdeepgupta813 Explorer in Splunk Search 04-07-2020
0 3
0
3
ryastrebov
Hello! Which method is faster? It seemed to me that the rex method is very slow for a large number of events.
by ryastrebov Communicator in Splunk Search 04-07-2020
1 7
1
7
ohbuckeyeio
Is there a way to dynamically pass a comparison operator as a variable without a macro? I am looking to achieve some...
by ohbuckeyeio Communicator in Splunk Search 04-07-2020
0 4
0
4
Shan
Dear Friends, Need you're help on writing a rex. As per my requirement. what ever value comes before a space need t...
by Shan Builder in Splunk Search 04-07-2020
0 4
0
4
hegdevageesh
I have 2 log files from different sources. Both log files have statements either indicating a "Transaction-Start" or...
by hegdevageesh New Member in Splunk Search 04-07-2020
0 3
0
3
jerinvarghese
Hi All, need help in getting a regex code for the below message. 2020-04-04T15:08:01+00:00 usdaldc <44> %WAAS-HTTPAO...
by jerinvarghese Communicator in Splunk Search 04-07-2020
0 3
0
3
Sfry1981
I have the below search: index=cd source=jenkins pr_number=* | stats count as Total , earliest(_time) as start, lat...
by Sfry1981 Communicator in Splunk Search 04-07-2020
0 2
0
2
Shashank_87
Hi, I am dealing with a situation here. Trying to join 2 queries to find out the peak hour volume in last 90 days on ...
by Shashank_87 Explorer in Splunk Search 04-07-2020
0 9
0
9
pawelzak
I have a log that contains numerical value which is logged irregularly: I would like to calculate (and show on time...
by pawelzak New Member in Splunk Search 04-07-2020
0 4
0
4
zacksoft
I am writing a query which is going to a scheduled report. I have 3 servers/hosts (serv1, serv2, serv3) whose average...
by zacksoft Contributor in Splunk Search 04-07-2020
0 1
0
1
zubairaizatron
How would i find the average value of a certain field per a certain amount of events Example: i have 1000 events and...
by zubairaizatron Explorer in Splunk Search 04-07-2020
0 5
0
5
nw0605
Splunk7.3.3を利用しています。 複数のインデックスを持っています。 インデックス毎の1日あたりのデータ取込み量を確認する方法をご教授いただきたいです。
by nw0605 New Member in Splunk Search 04-07-2020
0 1
0
1
racans
I have a rex as such: | rex field=host "(?<sydney>10-92-3[2-4])" | rex field=host "(?<melbourne>10-92-11[0-2])" wh...
by racans New Member in Splunk Search 04-06-2020
0 1
0
1
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors