Splunk Search

Splunk Search
Community Activity
Gunjan92
I have a situation where in the span of 10 mins there could be a possibility that we didn't get any data from one of ...
by Gunjan92 Engager in Splunk Search 03-15-2020
1 2
1
2
jrodriguezap
Hi everyone Someone who has used the map command who can help me, I am trying to bind the username of the 12 hours be...
by jrodriguezap Contributor in Splunk Search 03-15-2020
0 2
0
2
ajay_semwal
Hi All, I am trying to build the query to get the website hits for each IP, there are 16 servers ip and wanted to ge...
by ajay_semwal New Member in Splunk Search 03-15-2020
0 1
0
1
zinaalbaik
Hi every one. I want to show device names and their status (connected / disconnected) on the map. The color of point...
by zinaalbaik New Member in Splunk Search 03-15-2020
0 1
0
1
vigneshtv
I have categories.csv that contains list of sub-categories in each category Category,Sub_category Biology,Botany Bio...
by vigneshtv Explorer in Splunk Search 03-14-2020
0 5
0
5
vmeleco
I have 2 searches. Search A produces a table output of "UserIP" Search B produces a table output of "FailedDestina...
by vmeleco New Member in Splunk Search 03-14-2020
0 7
0
7
splunk_learner_
I am new to Splunk and still learning.. I have more than 100 queries to run when asked during a daily activity and i...
by splunk_learner_ New Member in Splunk Search 03-14-2020
0 3
0
3
pratapa
User complained that following query is not displaying any events. index=main sourcetype=wms_oracle_sessions | bucke...
by pratapa Explorer in Splunk Search 03-14-2020
0 6
0
6
mmccul_fe
Data resembles this pattern. | makeresults | eval _raw="{\"foo\": [{\"randstring1\": {\"fqdn\" : \"ibar.example.c...
by mmccul_fe Explorer in Splunk Search 03-14-2020
0 5
0
5
vn_g
Query : index=systemdetails source=sytemdetails* Condition = 0 | eval [ search index=systemdetails source=syte...
by vn_g Path Finder in Splunk Search 03-14-2020
0 3
0
3
kirrusk
I'm trying to count values of field in a time chart with every particular point of time using dedup. like this , inde...
by kirrusk Communicator in Splunk Search 03-14-2020
0 1
0
1
bsaujla131984
I am struggling to fetch the data between curly brackets . Have tried multiple rex searches, however still not gettin...
by bsaujla131984 Path Finder in Splunk Search 03-13-2020
0 3
0
3
zaynaly
I have 2 separate searches. search1 = 17 resultssearch2 = 20 results Key column that exists in both searches is "targ...
by zaynaly Explorer in Splunk Search 03-13-2020
0 1
0
1
raje1
Hi, Can i run a search which specify that these type of logs are blocked in palo alto firewall by specific policy. ...
by raje1 Engager in Splunk Search 03-13-2020
0 3
0
3
matoulas
Hi, I have JSON data format that send to Splunk as below: { "timestamp": "2020-03-12T18:18:48+00:00", "siteid": "CPM-...
by matoulas Path Finder in Splunk Search 03-13-2020
0 9
0
9
tahasefiani
Hello, I have this query | loadjob savedsearch="myquery" | where (strftime(_time, "%Y-%m-%d") >= "2020-02-26") A...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 5
0
5
verbal_666
Hi there. Should we have Indexers issue, or SearchHeads ones? We have many many many (more than 200) scheduled saveds...
by verbal_666 Builder in Splunk Search 03-13-2020
0 5
0
5
pench2k19
Hi Ninjas, I have a radio button with two values as STARTING job and RUNNING jobs. I have different query for each ...
by pench2k19 Explorer in Splunk Search 03-13-2020
0 5
0
5
splunkuser2012
I want to search the whole term like shown below, why is it not working ? Do i need to remove the "<" and "//" ? Wha...
by splunkuser2012 Engager in Splunk Search 03-13-2020
1 4
1
4
tarunmalhotra79
The idea is to show up top 3 CPU Averages in a day for last 7 days. Query Using:- index=os sourcetype=ps host="Host...
by tarunmalhotra79 Engager in Splunk Search 03-13-2020
0 2
0
2
tahasefiani
Hello, This is my query | loadjob savedsearch="myquery" | where strftime(_time, "%Y-%m-%d") >= "2020-02-26" | stat...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 4
0
4
hollybross1219
Hi there! I created a hacky Splunk query for some YOY analysis I'm doing. I was wondering if there was a way to halt...
by hollybross1219 Path Finder in Splunk Search 03-13-2020
0 2
0
2
nathanluke86
............. | rex field=user mode=sed "s/./ /g" | eval user=lower(user) | eval date_hour=strftime(_time, "%...
by nathanluke86 Communicator in Splunk Search 03-13-2020
0 1
0
1
MousumiChowdhur
Hello everyone! I have a static lookup which has two fields/columns State and tag. Default value of State is "Enable...
by MousumiChowdhur Contributor in Splunk Search 03-13-2020
0 1
0
1
skirven
Hi! I'm trying to create a search that would return unique values in a record, but in one list. The search "basesear...
by skirven Communicator in Splunk Search 03-13-2020
0 9
0
9
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors