Splunk Search

Splunk Search
Community Activity
totaro
Hi i currently have the following line in my search that search for system.net.webclient: |rex max_match=0 "(?<modul...
by totaro Explorer in Splunk Search 12-08-2019
0 3
0
3
nathant089
Is there anyone else having issues contacting Splunk support today where each time you call it either rings out or di...
by nathant089 New Member in Splunk Search 12-08-2019
0 1
0
1
kanamarlapudive
Hi team, I have two log events as mentioned below, i am trying to find out response time difference based on timesta...
by kanamarlapudive New Member in Splunk Search 12-08-2019
0 21
0
21
mo_shahin
I am trying to visualize the deviation between a correlation rule's scheduled time and the time it was run. went thr...
by mo_shahin Engager in Splunk Search 12-07-2019
0 1
0
1
sendijsd
Hello, fellow Splunkers. I am currently trying to create a stacked timechart column using a simple search query: tim...
by sendijsd Engager in Splunk Search 12-07-2019
0 2
0
2
Beaker77
Hey there Splunkers! Similar to the question "How is the Size value on the job page calculated and logged in Splunk?...
by Beaker77 Explorer in Splunk Search 12-07-2019
0 3
0
3
sherrysafdar
I have an issue where events are indexed into multiple indexes partially. Now the problem is that Example: - Som...
by sherrysafdar Explorer in Splunk Search 12-07-2019
0 1
0
1
rcastello
Hello, I'm attempting to build a detailed table complete with timestamp, account name, eventcode, and host. We found...
by rcastello Explorer in Splunk Search 12-07-2019
0 1
0
1
kkuminsky
In the following Windows event log message field Account Name appears twice with different values. When I build a rep...
by kkuminsky Path Finder in Splunk Search 12-06-2019
3 12
3
12
landen99
When using NOT TERM, please keep in mind the following bug (see the answer for the workaround): index=myindex NOT TE...
by landen99 Motivator in Splunk Search 12-06-2019
0 5
0
5
kvanwagoner
I'm sure this will be easy for you guys but I"m struggling with it.. I need to modify this query to look for both the...
by kvanwagoner New Member in Splunk Search 12-06-2019
0 3
0
3
lucas4394
I wonder what the difference between last and max in timestamp if I want to return the most recent time from a lookup...
by lucas4394 Path Finder in Splunk Search 12-06-2019
0 2
0
2
unitedmarsupial
We have periodic events of the same kind and I want to count the time (duration) and the number of other events (even...
by unitedmarsupial Path Finder in Splunk Search 12-06-2019
0 3
0
3
Tylerdygert
Hello, I am running into an issue with some spath and mvexpand functions in splunk. I get the following error: "outp...
by Tylerdygert Path Finder in Splunk Search 12-06-2019
0 9
0
9
danielbb
The following works just fine - | makeresults | eval temp="IP-Group={xxxx} {yyyy} {zzz}" | rex field=temp max_...
by danielbb Motivator in Splunk Search 12-06-2019
0 3
0
3
bullbo
I have a search that displays new accounts created over the past 30 days and another that displays accounts deleted o...
by bullbo Engager in Splunk Search 12-06-2019
0 4
0
4
prettysunshinez
Hi, I have lookup file with the columns(fields) Name SubName. Now I wanted to run a query,which looks for the presen...
by prettysunshinez Explorer in Splunk Search 12-06-2019
0 4
0
4
pschildein
Hi, I have a large CSV lookup (~200MB and 6+ million lines). As I need the lookup information for eventtypes I tried...
by pschildein Explorer in Splunk Search 12-06-2019
1 0
1
0
rajeshjlnt
I am building a table query to list down tickets against applications. Where tickets are stored in sourcetype 'a' and...
by rajeshjlnt Path Finder in Splunk Search 12-06-2019
0 10
0
10
essibong1
Can any one help with a search language that could determine full disks and system logins after core hours?
by essibong1 New Member in Splunk Search 12-06-2019
0 1
0
1
arrowecssupport
This is my search I am trying to use in an event type so I can tag my events. index = mail | eval Subject=coalesce(S...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 6
0
6
arrowecssupport
I am running the search "index="os_var_log" | stats count" and getting this error after upgrading to Version 8 From v...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 0
0
0
gravi
Hi, I have nested json with Payload and the payload values are not consistent . First Format: { Activity: Logger...
by gravi Explorer in Splunk Search 12-06-2019
0 3
0
3
aswin_asok
i, One of my value in table is being passed as an Boolean expression as below (assignment_group = 1213App_Developmen...
by aswin_asok Explorer in Splunk Search 12-06-2019
0 0
0
0
user93
I want to search an exact phrase, but surronded by wildcards. I want to be able to do this with and without specifyin...
by user93 Communicator in Splunk Search 12-06-2019
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors