Splunk Search

Splunk Search
Community Activity
lucas4394
We have more than 90% of skipping rate from our datamodel acceleration searches, and most of them show like 99.96% co...
by lucas4394 Path Finder in Splunk Search 01-08-2020
0 0
0
0
nick405060
I want to be able to put a token in my alert title that is derived from a field NOT in the displayed results table. ...
by nick405060 Motivator in Splunk Search 01-08-2020
1 3
1
3
constantinetabs
How do I get the ratio for two values of the same field? When I run the following command: host=web_app action=* fi...
by constantinetabs New Member in Splunk Search 01-08-2020
0 1
0
1
pavanae
I have a query which displays some statistical results. Now I want to add a column macro_match which contains the mat...
by pavanae Builder in Splunk Search 01-08-2020
0 1
0
1
utkarsh_s
Join below 2 indexes on basis of user index=_internal sourcetype=splunkd_ui_access q!="" | rex field=uri_query "disp...
by utkarsh_s New Member in Splunk Search 01-08-2020
0 1
0
1
dbashyam
Hi, How to convert this sumologic query to splunk _collector="M2" "Memory Monitor" | parse ",DB Job-Connection-Poo...
by dbashyam Explorer in Splunk Search 01-08-2020
0 3
0
3
sarwshai
I am using this query "index=oswin* source="WinEventLog:System" (EventCode=6005 OR EventCode=1074 OR EventCode=6006) ...
by sarwshai Communicator in Splunk Search 01-08-2020
0 1
0
1
ftonen
EDIT: The below search suddenly did work, so my issue is solved! So I have two searches in a dashobard, but resultin...
by ftonen Explorer in Splunk Search 01-08-2020
0 7
0
7
martinnepolean
We are trying to do field extraction of the aws dns events, currently we are getting the events with below indexname,...
by martinnepolean Explorer in Splunk Search 01-08-2020
0 6
0
6
sharif_ahmmad
Hello, i have been trying to expand multi value fields from different source-type. Problem is that when i do expand ...
by sharif_ahmmad Explorer in Splunk Search 01-07-2020
0 3
0
3
secuc2r83
Hi, I upgrade in 7.3.3 and i have a problem with one fieldalias I know the ASNEW settings since 7.2.4 restore old b...
by secuc2r83 Path Finder in Splunk Search 01-07-2020
0 0
0
0
siddharth1479
Hi Community, I've been using Splunk enterprise search and reporting since a month now and now when I try to search w...
by siddharth1479 Path Finder in Splunk Search 01-07-2020
0 8
0
8
raj00350
I have 2 columns. First column has values on which my splunk line chart is dependent on. Second column has values onl...
by raj00350 New Member in Splunk Search 01-07-2020
0 2
0
2
Shashank_87
Hi, I want to calculate max TPS on a particular day for last 3 months for some specific URL's. I just have 5 URL's so...
by Shashank_87 Explorer in Splunk Search 01-07-2020
0 0
0
0
jkotula
Wildly frustrated poring over the Splunk documentation -- there are absolutely no good introductions to any topic! An...
by jkotula New Member in Splunk Search 01-07-2020
0 3
0
3
shayhibah
Hi, I am trying to add new evaluation for a field in search-time. For some reason, when I run query from my search h...
by shayhibah Path Finder in Splunk Search 01-07-2020
0 1
0
1
ahmadshakir1952
Trying to expand two multi value field using mvexpand for below scenario: Jhon purchased Mango and Banana both. Co...
by ahmadshakir1952 Explorer in Splunk Search 01-07-2020
0 6
0
6
GadgetGeek
Given the 2 following searches which are both over a 30 day period (and each having multiple countries in the results...
by GadgetGeek Path Finder in Splunk Search 01-07-2020
0 20
0
20
wu_weidong
I'm building a dashboard that shows a stacked column chart of different items sold in the last 6 months (using timech...
by wu_weidong Path Finder in Splunk Search 01-06-2020
0 3
0
3
miburo
As part of a testing plan, we would like to have a tool check syntax of our block of Splunk queries. Are there any ...
by miburo Explorer in Splunk Search 01-06-2020
1 2
1
2
gorbikvv
We are using Splunk Mint SDK in our iOS app. By default it collects a lot of fields listed here - https://docs.splunk...
by gorbikvv New Member in Splunk Search 01-06-2020
0 0
0
0
danielbb
Based on Can I see the top skipped searches? I got a couple of offending queries, with a message such as - The maxim...
by danielbb Motivator in Splunk Search 01-06-2020
0 3
0
3
jeck11
Hello everyone, I have a self-service dashboard running in our Splunk Cloud V6.2 environment which displays indexed...
by jeck11 Path Finder in Splunk Search 01-06-2020
0 0
0
0
lmzheng
I have a subsearch that I use to determine the first occurrence of the issue logged. I currently have an earliest=-4d...
by lmzheng Explorer in Splunk Search 01-06-2020
0 3
0
3
Vijeta
How can I export my search results or send alert results to an AWS S3 bucket?
by Vijeta Influencer in Splunk Search 01-06-2020
0 1
0
1
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors