Splunk Search

Splunk Search
Community Activity
mozukun3
お世話になります。 サーチ文の書き方についてご教示ください。 まず、以下の検索結果を出しています。 ・サーチ文 「soucetype="test1" | table host, user, state」 ・サーチ結果 ------...
by mozukun3 New Member in Splunk Search 11-01-2019
0 5
0
5
ktn01
Hello, I have events in the following format: 20/08/19 16:34:17 login1 command RunAsUsers="web,tomcat,embed" wit...
by ktn01 Path Finder in Splunk Search 11-01-2019
0 2
0
2
Robbie1194
Hi guys, I was wondering if anyone knew of a method of appending data to a lookup, but not overwriting anything in ...
by Robbie1194 Communicator in Splunk Search 11-01-2019
0 2
0
2
bsaujla131984
I have created an alert which basically checks the occurrence in particular keyword in two log files , however there ...
by bsaujla131984 Path Finder in Splunk Search 11-01-2019
0 1
0
1
ahuseid
I need to join two searches on a common field in which I want a value of the left search matches all the values of t...
by ahuseid New Member in Splunk Search 11-01-2019
0 6
0
6
ajtalbot1
Simple search to look at the battery status on my UPS: UPS_BATT | timechart max(UPS_BATT) span=1m But the UPS_BATT...
by ajtalbot1 Engager in Splunk Search 11-01-2019
0 4
0
4
akki2428
Hi, I would want to search for all results for this specific string pattern 'record has not been created for id XXXXX...
by akki2428 New Member in Splunk Search 11-01-2019
0 9
0
9
daniel_splunk
Have a search with many subsearch and append command like below pattern. | makeresults | eval abcd="acded" | appe...
by daniel_splunk Splunk Employee Splunk Employee in Splunk Search 11-01-2019
0 1
0
1
mansel_scheffel
Hi, Is there any benefit to using the old method when using summary indexing? Basically I would like to the know dif...
by mansel_scheffel Explorer in Splunk Search 11-01-2019
0 6
0
6
kdulhan
Hi All, I have some search criteria followed by stats as: Search ns=app1 Error | stats sum(eval(AcctNo="'1000394'")...
by kdulhan Explorer in Splunk Search 10-31-2019
1 8
1
8
rashi83
I need to display a table with 4 columns and date is like this: Colum A Col B Col C Col D x ...
by rashi83 Path Finder in Splunk Search 10-31-2019
0 2
0
2
raghu0463
Hi, Can I write my search as: index=idx1 host != (a,b,c) | stats count by host The thing is I want to filter some ...
by raghu0463 Explorer in Splunk Search 10-31-2019
0 1
0
1
jscraig2006
I've created several macros with a tstat query. when running the macro through the UI, no results are displayed. When...
by jscraig2006 Communicator in Splunk Search 10-31-2019
0 1
0
1
harshparikhxlrd
I'm trying to remove characters after a certain string in my search string. I am still getting the strings after "3"...
by harshparikhxlrd Path Finder in Splunk Search 10-31-2019
0 2
0
2
DanielleM
I am calculating monthly averages and have an issue where on a single day in October there was an error in the data. ...
by DanielleM Explorer in Splunk Search 10-31-2019
0 2
0
2
rmmiller
I have a query using streamstats that is on the intensive side because I'm not dealing with nicely-formatted data. (...
by rmmiller Contributor in Splunk Search 10-31-2019
0 9
0
9
alancalvitti
In a search executed via Python SDK, the stat list truncates results to 100 results, despite the fact that count=0. ...
by alancalvitti Path Finder in Splunk Search 10-31-2019
0 9
0
9
dabroma5
Hi Team, I would like to create a named field to filter Ethernet port numbers. My expression: \beth\d*(?:-\d+)*(?:/\...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 5
0
5
dabroma5
Hi Team I need to filter logs to catch switches port numbers. I use Splunk Cloud, my expression: \beth\d*(?:-\d+)...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 7
0
7
pench2k19
Hi Ninjas, I have the following values for host name field . appra94a0350 appra92a0350 appra84a0201 appra25a0201 ap...
by pench2k19 Explorer in Splunk Search 10-31-2019
0 2
0
2
jnahuelperez35
Hi Guys! i've got the next situation Trying to replace some characters in this events: \device\harddiskvolume4\wind...
by jnahuelperez35 Path Finder in Splunk Search 10-31-2019
2 3
2
3
totaro
Hi, i was hoping to extract all the fields after "CommandInvocation" that appears in the PS log but i wasnt able to e...
by totaro Explorer in Splunk Search 10-31-2019
0 2
0
2
andrewtrobec
Hello all, I am trying to index a subset of a very painful log which has header and footer noise and whose events st...
by andrewtrobec Motivator in Splunk Search 10-31-2019
0 2
0
2
bleung93
I have this search to display sourcetypes by index. | metasearch index=* sourcetype=* | stats values(sourcetype) as ...
by bleung93 Path Finder in Splunk Search 10-31-2019
0 2
0
2
prakash007
I'm using this regex to mask cc data in props.cof on a Heavy Forwarder....need help in validating.... log format ...
by prakash007 Builder in Splunk Search 10-30-2019
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...