Splunk Search

Splunk Search
Community Activity
stevedefazio
I want to display all of my widgets by their type. Sometimes though, I want to look up a particular widget (via a tex...
by stevedefazio Explorer in Splunk Search 11-19-2019
0 3
0
3
damucka
Hello, I have a column / field called LINE that consists of the several text lines. I would like to format it a bit ...
by damucka Builder in Splunk Search 11-19-2019
0 5
0
5
rczone
I'm a newbie to SPlunk REX trying to do some dashboards and need help in extracting fields of a particular variable i...
by rczone Path Finder in Splunk Search 11-19-2019
0 7
0
7
lmzheng
The original search is selected with the drop down box at the top of the screen. I created a subsearch with earliest...
by lmzheng Explorer in Splunk Search 11-19-2019
1 4
1
4
hariniramesh
I am having an field name called "JOBNAME" which contains some jobname values and some empty values(which means there...
by hariniramesh New Member in Splunk Search 11-19-2019
0 1
0
1
amcb90
The command I am running is: basesearch | eval number = case ( number = "1" , "Number 1" , number = "2" , "Number 2...
by amcb90 Engager in Splunk Search 11-19-2019
0 1
0
1
kamaleshwar
Hello, I'm having the two REX fields and want to search the logs with those fields. Which one matches that field nee...
by kamaleshwar Explorer in Splunk Search 11-19-2019
1 2
1
2
leandromatperei
Hi, I have the following log format, How can I break this multiline event on condition that "2019-11-12T09: 51: 28.2...
by leandromatperei Path Finder in Splunk Search 11-19-2019
0 4
0
4
itsmevic
I'd like to set up a practice Splunk environment so that I can practice various install methods of Splunk (clustering...
by itsmevic Communicator in Splunk Search 11-19-2019
0 2
0
2
jtpryan
I have a search that returns a large amount of information in each row, resulting in many columns, most of which I do...
by jtpryan New Member in Splunk Search 11-19-2019
0 7
0
7
HeinzWaescher
Hi, I've seen it several times but don't know the difference and when to use == instead of = . Like in these samples...
by HeinzWaescher Motivator in Splunk Search 11-19-2019
0 2
0
2
karlduncans
I'm trying to determine a way to report a peak per minute count per day (in this case, the last 30 days) If i run th...
by karlduncans Engager in Splunk Search 11-19-2019
0 4
0
4
mevans292
We are using a CSV input, which generates indexed extractions - some of the field values contain spaces. Here is som...
by mevans292 New Member in Splunk Search 11-19-2019
0 7
0
7
Shashank_87
Hi, I am trying to find the busiest time of the day for last 30 days. What i need is a table like this - Day Peakhou...
by Shashank_87 Explorer in Splunk Search 11-19-2019
0 3
0
3
leandromatperei
Hi, I have the following log format, How can I break this multiline event, with the condition if the date is changed ...
by leandromatperei Path Finder in Splunk Search 11-19-2019
0 4
0
4
nagarajsf
Hello, I'm trying to rename query output and those are string values. expecting output for field MANAGER_NAME would b...
by nagarajsf Explorer in Splunk Search 11-19-2019
0 5
0
5
misteraufziehvo
Hi, the environment uses 170 lookups and during one single search, they get loaded exactly 500 times each wich sums...
by misteraufziehvo New Member in Splunk Search 11-19-2019
0 4
0
4
packet_hunter
is there a way to search who has access to an index without having to dig thru the access controls, roles and users? ...
by packet_hunter Contributor in Splunk Search 11-19-2019
1 3
1
3
a212830
Hi, One of my customers received a "waiting for queued job to start" message today, and it then took about 5 minutes...
by a212830 Champion in Splunk Search 11-18-2019
10 10
10
10
reddevilz
I have an index with multiple fields that I have created using "Extract new fields". The following is the what my cur...
by reddevilz Engager in Splunk Search 11-18-2019
0 1
0
1
adamaso
Hello All I have been looking on the forum for a solution on how to calculate the average weighted. I see several op...
by adamaso New Member in Splunk Search 11-18-2019
0 2
0
2
prot3ctor
Hello. Could anyone help me out? I have a DoB string with the following format dob='2002-01-03' I would like to fo...
by prot3ctor New Member in Splunk Search 11-18-2019
0 7
0
7
mcram52
I've set up the following search with a count of events based on specific time frames over a week span: index=epacka...
by mcram52 New Member in Splunk Search 11-18-2019
0 1
0
1
hanikawadhwa
Hi Splunkers, I am stuck in a situation where I have been provided an input lookup file containing operational hours...
by hanikawadhwa Explorer in Splunk Search 11-18-2019
0 5
0
5
hanikawadhwa
Hi splunkers, I have a situation to read different operational hours of same bin size for the last 3 days Scenario:...
by hanikawadhwa Explorer in Splunk Search 11-18-2019
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...