Splunk Search

Splunk Search
Community Activity
tkw03
Hello I have a structured data source that puts out data in a table with headers and a footer row with a total. I go...
by tkw03 Communicator in Splunk Search 03-18-2020
0 2
0
2
luke222010
Hello Splunkers! I have the following fields being populated by 1000s of values every 1 minute: Name Cost E.g. Luk...
by luke222010 Engager in Splunk Search 03-18-2020
0 2
0
2
jip31
hello I use the stats command below in order to count the number of index on which an host collect events | stats dc...
by jip31 Motivator in Splunk Search 03-18-2020
0 2
0
2
dminev1
Hello Splunk Community, I am trying to create dashboard with the following query but the query returns no results. I...
by dminev1 Explorer in Splunk Search 03-18-2020
0 7
0
7
dblagojevic
Hi all, I have .csv file with the multiple columns. But only one will be used to compare results, name of that colu...
by dblagojevic Engager in Splunk Search 03-18-2020
0 4
0
4
jip31
hi I use the serch below wich match the data present in 2 indexes following by host In LastLogonBoot, the field "host...
by jip31 Motivator in Splunk Search 03-17-2020
0 11
0
11
nickrally2009
I have this search, where I am charting usage over id field (which is on x-axis) split by two columns - two values o...
by nickrally2009 Explorer in Splunk Search 03-17-2020
0 6
0
6
reverse
Assuming there are 2 columns - Date & count and there are duplicates date. How to dedup on Date and pick the maximum...
by reverse Contributor in Splunk Search 03-17-2020
0 3
0
3
sriyechuri
eventtype="*" "screen" OR "ui1" | stats count AS TotalEvents by product | appendcols [search eventtype="*" "ui2" OR...
by sriyechuri New Member in Splunk Search 03-17-2020
0 8
0
8
tsheets13
I need to create a search to count the number of events in each geographic are of our network. Each geo area will co...
by tsheets13 Communicator in Splunk Search 03-17-2020
0 6
0
6
panulpet
Related to this question: https://answers.splunk.com/answers/807988/splunk-search-show-results-from-json.html I bas...
by panulpet Loves-to-Learn in Splunk Search 03-17-2020
0 12
0
12
627412
I manage to extract the data from Splunk below: ID SignalStrength TimeStamp 01 3 ...
by 627412 New Member in Splunk Search 03-17-2020
0 1
0
1
khojas02
I have a sample data as below Assigned Analyst Assigned Date John ...
by khojas02 Engager in Splunk Search 03-17-2020
0 8
0
8
jonglim
i'm trying to join these 2 tables. table 1 : index ="A" sourcetype = A WITH fields deviceName, physicalElementId, ph...
by jonglim New Member in Splunk Search 03-17-2020
0 5
0
5
uthornander_spl
Hi I have a dataset that isn't entirely clean so I first do some trim to get rid of a trailing comma (,). That didn't...
by uthornander_spl Splunk Employee Splunk Employee in Splunk Search 03-17-2020
0 3
0
3
nilbak1
I am running below Query | makeresults| eval data="Brand1,File1,123;Brand1,File2,456;Brand2,File1,789;Brand2,File2,1...
by nilbak1 Communicator in Splunk Search 03-16-2020
0 4
0
4
splunk_venkat
Hi, I am working on a splunk query to pull the records from daily basis depends on timinging. For example 30m and 6...
by splunk_venkat New Member in Splunk Search 03-16-2020
0 0
0
0
vikram1583
search 1...|table src_ip search 2: tag=authentication user!=*$ src_ip=xx.xx.xx.xx | head 1 | table user src_ip ...
by vikram1583 Explorer in Splunk Search 03-16-2020
0 2
0
2
khojas02
Hello Everyone!! I have a sample data as below Analyst Span A ...
by khojas02 Engager in Splunk Search 03-16-2020
0 1
0
1
daniel333
All, Member of our management team is concerned about a Splunk Forwarder with a number of processes and threads. Cu...
by daniel333 Builder in Splunk Search 03-16-2020
0 1
0
1
itsmevic
Quick background: I'm looking for SSO logins by users that have authenticated via NTLM. Issue: I copied a snippet...
by itsmevic Communicator in Splunk Search 03-16-2020
0 1
0
1
shivanandbm
Hi all, I am finding duplicate events during search operation. I am bit confused on where the issue is lies and how ...
by shivanandbm Explorer in Splunk Search 03-16-2020
0 7
0
7
frbuser
Query index::dlp | bucket _time span=1d | stats count(EVENT_DESCRIPTION) AS "Count" BY _time,User_Name,EV...
by frbuser Path Finder in Splunk Search 03-16-2020
0 1
0
1
riqbal47010
I have below query index=f5 partition="/Common/-" | rex "Username\s+'(?(.*))'" | eval Username=coalesce(Usernam...
by riqbal47010 Path Finder in Splunk Search 03-16-2020
0 6
0
6
ddrillic
When running an inline search the results limit is high as we have in limits.conf the following. [searchresults] max...
by ddrillic Ultra Champion in Splunk Search 03-16-2020
2 5
2
5
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...