Splunk Search

Splunk Search
Community Activity
itsmevic
What is the difference between a normal search in Splunk and a search that incorporates the REST command?
by itsmevic Communicator in Splunk Search 01-03-2020
0 4
0
4
palisetty
Why does when we run timechart, search mode changes to verbose? I ran this with smart mode and suddenly see it in ver...
by palisetty Communicator in Splunk Search 01-03-2020
0 1
0
1
bmendez0428
I'm somewhat new to Splunk. I have a dashboard displaying a table with data. I have code that fills in the columns ...
by bmendez0428 Explorer in Splunk Search 01-03-2020
0 2
0
2
palisetty
@gcusello @woodcock @richgalloway Why do we need two functions for the same functionality? 'dedup' displays unique v...
by palisetty Communicator in Splunk Search 01-03-2020
0 2
0
2
anz999
Tried to use the below query but unfortunately events are grouped with reference to _time index=omi_UAT host=* sour...
by anz999 Loves-to-Learn Lots in Splunk Search 01-03-2020
0 3
0
3
VijaySrrie
Hi Please help me with the regex for below 1) Hostname 2) IP address 3) UserID (for eg: vijay_111) 4) mail id
by VijaySrrie Builder in Splunk Search 01-03-2020
0 5
0
5
60150134
Hi Everyone, Thanks for your support too. I have indexed data of staff events from a source. One field in that da...
by 60150134 New Member in Splunk Search 01-03-2020
0 1
0
1
shayhibah
Hi, I am wondering if its possible t change value of field based on condition at index time. For example: If the l...
by shayhibah Path Finder in Splunk Search 01-03-2020
0 3
0
3
umairahmad3985
When I run my custom search command, the results in Splunk's Statistics tab are appearing in a weird UI. The column a...
by umairahmad3985 Path Finder in Splunk Search 01-02-2020
0 2
0
2
palisetty
I know that '@' rounds off to the nearest time. For example, if we have 9:37, shouldn't it round off to 10 instead of...
by palisetty Communicator in Splunk Search 01-02-2020
0 12
0
12
mumblingsages
All, I love Splunk as it makes tons of things super simple. Until it comes time to use the date time picker with any ...
by mumblingsages Path Finder in Splunk Search 01-02-2020
0 8
0
8
drmorgan78
I have a search that returns the time of the first instance of a specific event (field "firstaction") by date (field ...
by drmorgan78 New Member in Splunk Search 01-02-2020
0 8
0
8
childroland
I am trying to build a query to find outliers using avg and stdev on a perfmon counter but the counter is not a value...
by childroland Explorer in Splunk Search 01-02-2020
0 11
0
11
unitedmarsupial
Suppose, one has an alert defined for checking multiple application-instances. Can the actions defined for the alert...
by unitedmarsupial Path Finder in Splunk Search 01-02-2020
0 11
0
11
disillusioned
I have a search: index=lab-testresults sourcetype=lab-testresults type=testCase and inside of the testCase I have a f...
by disillusioned New Member in Splunk Search 01-02-2020
0 2
0
2
vwilson3
Greetings, I've been trying to tweak an inherited report to only show the results where the count of events is blank...
by vwilson3 Path Finder in Splunk Search 01-02-2020
0 5
0
5
palisetty
I have sum (field) which has been piped into stats sum of another field, Not sure what is happening here. Kindly help...
by palisetty Communicator in Splunk Search 01-02-2020
0 7
0
7
matt1t
All, I've been banging my head against the wall on this. Maybe its not possible, I don't know. I'm doing a multi se...
by matt1t Explorer in Splunk Search 01-02-2020
0 2
0
2
Deprasad
I have a report generated with following fields, Field 1 , Field 2, Field 3. I have to create an alert based on the...
by Deprasad Path Finder in Splunk Search 01-02-2020
0 2
0
2
palisetty
@gcusello I have multiple count functions in the same search component. What does it mean by that? What is really ha...
by palisetty Communicator in Splunk Search 01-02-2020
0 1
0
1
tahasefiani
Hi everyone, I'm trying this search but apparently Splunk doesn't have the same logic as SQl. Can someone give me he...
by tahasefiani Explorer in Splunk Search 01-02-2020
0 3
0
3
jlkokko
I have the following search: index="main" |rename Proj_repo AS Project | multireport [ stats values(Project) AS Proj...
by jlkokko Path Finder in Splunk Search 01-02-2020
0 7
0
7
palisetty
(T/F) Using NOT and != would return the same results. For me, the answer is false but quizlet says true. I say false ...
by palisetty Communicator in Splunk Search 01-01-2020
1 4
1
4
stephenreece
Hi all, hope there is a way to do the following. I am trying to find out how many events it takes for a user to go f...
by stephenreece New Member in Splunk Search 01-01-2020
0 8
0
8
bhavya49
{ [-] detailMap: { [-] critical: false result: 0 totalCnt: 5 txnCountWithIgnoredIRC: 0 wa...
by bhavya49 New Member in Splunk Search 01-01-2020
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...