Splunk Search

Splunk Search
Community Activity
tsheets13
I have a value in my events called type, which is a single digit integer (1, 2, 3, etc.) I would like to create a new...
by tsheets13 Communicator in Splunk Search 03-05-2020
0 2
0
2
maria_n
Hi Everyone Sample logs: {"kubernetes":{"container_name":"sign-template-services","namespace_name":"merch-ps-signs-...
by maria_n Explorer in Splunk Search 03-05-2020
0 3
0
3
harishalipaka
Hi All, I have data like below Drive Free_Space C:,D: 500 GB,450 GB E:,D: 25...
by harishalipaka Motivator in Splunk Search 03-05-2020
0 3
0
3
cisaksen
The requirements state that all cluster systems must run the same OS. Does this include the same OS version level of...
by cisaksen Explorer in Splunk Search 03-05-2020
0 1
0
1
julianniemeyer
I am experimenting on a test system and have a simple shell script that consists of one line to call Python 3 to run ...
by julianniemeyer New Member in Splunk Search 03-05-2020
0 0
0
0
DomenicoFumarol
Hello everyone,I have the challenge to compare two date fields, one coming from a search and the other one is reporte...
by DomenicoFumarol Explorer in Splunk Search 03-05-2020
0 2
0
2
tahasefiani
Hello, i Have this query that i want to improve | loadjob savedsearch="myquery" | where (strftime(_time, "%Y-%m-%d"...
by tahasefiani Explorer in Splunk Search 03-05-2020
0 7
0
7
anouar_jben
Hello, I have the below query which works fine: {My search} | rename user_id as User | stats max(asctime) as "Last ...
by anouar_jben Explorer in Splunk Search 03-05-2020
0 5
0
5
jwalzerpitt
How would I calculate the percentage increase/decrease, for indexes on a per-day basis? Thx
by jwalzerpitt Influencer in Splunk Search 03-05-2020
1 8
1
8
iqbalintouch
Hi, is there anyway to pull a report to get the data of log where DEBUG level log is enabled, based on the index and...
by iqbalintouch Path Finder in Splunk Search 03-04-2020
0 0
0
0
jiaqya
i would like one user to edit xml code or change query on the panels/dashboard of his app alone. what is the capabil...
by jiaqya Builder in Splunk Search 03-04-2020
0 2
0
2
jip31
hi I use the search below in order to count the number of degradation by model This search is a scheduled search and...
by jip31 Motivator in Splunk Search 03-04-2020
0 11
0
11
Jayanthi6397
Hi, I have given a query to return me a list of details as below , however the results for all of 30 days are not pop...
by Jayanthi6397 New Member in Splunk Search 03-04-2020
0 4
0
4
vikram1583
Hi, i have an event having white spaces in between i want to trim it the data is coming from db connect i don't ha...
by vikram1583 Explorer in Splunk Search 03-04-2020
0 1
0
1
sajoseph
HI , I have a log file where it has a sequence of activity of users. I am trying to parse that log. Splunk is parsing...
by sajoseph Explorer in Splunk Search 03-04-2020
3 3
3
3
heidihart
Hi, I have built out an AD inputlookup that includes lastlogon dates. When I attempt to find only those users with ...
by heidihart Engager in Splunk Search 03-04-2020
0 3
0
3
tbasima1
Dear all, hope to find here some help. I've tried now several things including searching in the answers here but don...
by tbasima1 Explorer in Splunk Search 03-04-2020
1 11
1
11
msrama5
Hello, I have the following where not query returning rows that exists in sub search, following is the query environm...
by msrama5 Explorer in Splunk Search 03-04-2020
0 3
0
3
moskalenkoas
Hi all! Ive got a strange problem with data loss,but not all - its just for a peroid of time. Here is example of m...
by moskalenkoas New Member in Splunk Search 03-04-2020
0 1
0
1
jlieberg
I have a data set similar to the following: "_time",source,increment "2020-02-26","third", "2020-02-25","third","yes...
by jlieberg Engager in Splunk Search 03-04-2020
0 2
0
2
alekseisaiko
Hi there! I need a query, that will show me Top Sourcetype Sizes by Day, where sourcetype=kubernetes_logs, and the ku...
by alekseisaiko Path Finder in Splunk Search 03-04-2020
0 3
0
3
alex1895
Here is the search: index=* sourcetype=Vectra-CEF vendor="Vectra Networks" cat!="HOST SCORING" |eval check_cat=case(...
by alex1895 Path Finder in Splunk Search 03-04-2020
0 8
0
8
manderson7
Data example: <Asset href="/company/rest-1.v1/Data/Story/2530981/6709286" id="Story:2530981:6709286"><Attribute name...
by manderson7 Contributor in Splunk Search 03-04-2020
0 6
0
6
franciscof
I need to sum several dates that are on a single field to then divide it with another field to get an average date. D...
by franciscof Explorer in Splunk Search 03-04-2020
0 1
0
1
franciscof
I need to perform a subtraction between two date fields in order to get a specific age. How can I do this?
by franciscof Explorer in Splunk Search 03-04-2020
0 2
0
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...