Splunk Search

Splunk Search
Community Activity
morethanyell
Hi, This search string have helped us a lot during investigation. It paints a timechart / graphicall representation ...
by morethanyell Builder in Splunk Search 12-04-2019
0 1
0
1
nkumar6
index= abc source=xyz|table JOBS,DAY,COUNT,START,END This is my current search which returns me result as: JOBS ...
by nkumar6 Explorer in Splunk Search 12-04-2019
0 2
0
2
ayush8878
Hi, I have a use case where i need to join result of two septate logs on the basis of common field(breadcrumbId). Be...
by ayush8878 New Member in Splunk Search 12-04-2019
0 4
0
4
saurabhkunte
HI All, I am hoping one of you can help me figure out how to calculate time duration between the below sample events...
by saurabhkunte Path Finder in Splunk Search 12-04-2019
0 6
0
6
dpatiladobe
I am trying to plot chart by ObjectName , Date by Duration. And wanted to sort them by Date desc and Duration desc. I...
by dpatiladobe Explorer in Splunk Search 12-04-2019
0 6
0
6
rick4039
Using Splunk Cloud - 7.0.11 My goal is to create a search and generate a table that I can use with MLTK. I'm searchi...
by rick4039 Explorer in Splunk Search 12-04-2019
0 8
0
8
maddenm2
ProxyName=PLB and ("/policies" OR "/bills") stats count by ProxyName I want the string "/policies" or "/bills" to...
by maddenm2 New Member in Splunk Search 12-04-2019
0 2
0
2
chinmayc469
I have a pivot report built on data set. When i open the report, the results are coming clearly but when i opened the...
by chinmayc469 Explorer in Splunk Search 12-04-2019
0 1
0
1
djreschke
Good afternoon everyone, Can someone point me in the right direction to creating an alert when a windows account is ...
by djreschke Communicator in Splunk Search 12-04-2019
0 3
0
3
benzmmrmnn86
I have an alert using a subsearch that was working a few weeks ago. Now all of a sudden i cannot get any subsearchs ...
by benzmmrmnn86 New Member in Splunk Search 12-04-2019
0 3
0
3
shwetamis
Below is my data 2019-12-03 14:20:55,679 ------------------ Begin Request ----------------- How do I extract begin ...
by shwetamis Explorer in Splunk Search 12-04-2019
0 7
0
7
pavanraghav
When I am using this : chart count over Created_Month by Status |table Created_Month,year,Relevant,Missing,Non_Relev...
by pavanraghav Explorer in Splunk Search 12-04-2019
0 19
0
19
maria_n
I am trying to extract fields Environment and Service with below search and receiving the error 'SearchParser': Missi...
by maria_n Explorer in Splunk Search 12-04-2019
0 3
0
3
piefragnisp
We have to model a regex in order to extract in Splunk (at index time) some fileds from our event. These fields will ...
by piefragnisp Explorer in Splunk Search 12-04-2019
0 8
0
8
GDude
Is it possible to highlight values in a row with condition by another value from another field without js/css? In the...
by GDude New Member in Splunk Search 12-04-2019
0 7
0
7
markhvesta
I have a search that is joining two sourcetypes that has multiple fields that have the same name. I want to join on ...
by markhvesta Path Finder in Splunk Search 12-03-2019
0 3
0
3
danielbb
We wonder what is better for this query - index=_audit action=alert_fired ss_app=<app name> | stats count as Total...
by danielbb Motivator in Splunk Search 12-03-2019
0 2
0
2
helge
I would like to use the Simple XML format rule to specify the formatting of table columns as documented here, e.g.: ...
by helge Builder in Splunk Search 12-03-2019
0 7
0
7
cheriemilk
Hi Team, I have several fields which values are array. For example, event1: ktf2="[Background_Criteria,Profile_Cr...
by cheriemilk Path Finder in Splunk Search 12-03-2019
1 1
1
1
kunwarjit
I am trying to use the token passed through the time input in a dashboard to a search query. In this specific example...
by kunwarjit Engager in Splunk Search 12-03-2019
0 3
0
3
ryangillan
I have the following as my search but wanted to see if a log does not update for X hours then send an alert. If the l...
by ryangillan Explorer in Splunk Search 12-03-2019
0 5
0
5
sylim_splunk
upgraded to 7.3 and they can no longer see all 208 indexes that we have when editing roles. When you edit a role and...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 12-03-2019
0 4
0
4
indeed_2000
Hi, I have IBM Informix schema and want to extract data with Splunk from it like this: table name | Index | Trig...
by indeed_2000 Motivator in Splunk Search 12-03-2019
0 16
0
16
afolabia
I'm having errors resolving several missing lookup tables. Any help to resolve these will be appreciated. The lookup...
by afolabia Path Finder in Splunk Search 12-03-2019
0 2
0
2
ehowardl3
I have a three-node search head cluster, when I create a field extraction through the GUI, it takes hours for it to b...
by ehowardl3 Path Finder in Splunk Search 12-03-2019
1 4
1
4
Get Updates on the Splunk Community!

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...

Recap | Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Recap | Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...
Top Solution Authors