Splunk Search

Splunk Search
Community Activity
daniel_splunk
Have a search with many subsearch and append command like below pattern. | makeresults | eval abcd="acded" | appe...
by daniel_splunk Splunk Employee Splunk Employee in Splunk Search 11-01-2019
0 1
0
1
mansel_scheffel
Hi, Is there any benefit to using the old method when using summary indexing? Basically I would like to the know dif...
by mansel_scheffel Explorer in Splunk Search 11-01-2019
0 6
0
6
kdulhan
Hi All, I have some search criteria followed by stats as: Search ns=app1 Error | stats sum(eval(AcctNo="'1000394'")...
by kdulhan Explorer in Splunk Search 10-31-2019
1 8
1
8
rashi83
I need to display a table with 4 columns and date is like this: Colum A Col B Col C Col D x ...
by rashi83 Path Finder in Splunk Search 10-31-2019
0 2
0
2
raghu0463
Hi, Can I write my search as: index=idx1 host != (a,b,c) | stats count by host The thing is I want to filter some ...
by raghu0463 Explorer in Splunk Search 10-31-2019
0 1
0
1
jscraig2006
I've created several macros with a tstat query. when running the macro through the UI, no results are displayed. When...
by jscraig2006 Communicator in Splunk Search 10-31-2019
0 1
0
1
harshparikhxlrd
I'm trying to remove characters after a certain string in my search string. I am still getting the strings after "3"...
by harshparikhxlrd Path Finder in Splunk Search 10-31-2019
0 2
0
2
DanielleM
I am calculating monthly averages and have an issue where on a single day in October there was an error in the data. ...
by DanielleM Explorer in Splunk Search 10-31-2019
0 2
0
2
rmmiller
I have a query using streamstats that is on the intensive side because I'm not dealing with nicely-formatted data. (...
by rmmiller Contributor in Splunk Search 10-31-2019
0 9
0
9
alancalvitti
In a search executed via Python SDK, the stat list truncates results to 100 results, despite the fact that count=0. ...
by alancalvitti Path Finder in Splunk Search 10-31-2019
0 9
0
9
dabroma5
Hi Team, I would like to create a named field to filter Ethernet port numbers. My expression: \beth\d*(?:-\d+)*(?:/\...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 5
0
5
dabroma5
Hi Team I need to filter logs to catch switches port numbers. I use Splunk Cloud, my expression: \beth\d*(?:-\d+)...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 7
0
7
pench2k19
Hi Ninjas, I have the following values for host name field . appra94a0350 appra92a0350 appra84a0201 appra25a0201 ap...
by pench2k19 Explorer in Splunk Search 10-31-2019
0 2
0
2
jnahuelperez35
Hi Guys! i've got the next situation Trying to replace some characters in this events: \device\harddiskvolume4\wind...
by jnahuelperez35 Path Finder in Splunk Search 10-31-2019
2 3
2
3
totaro
Hi, i was hoping to extract all the fields after "CommandInvocation" that appears in the PS log but i wasnt able to e...
by totaro Explorer in Splunk Search 10-31-2019
0 2
0
2
andrewtrobec
Hello all, I am trying to index a subset of a very painful log which has header and footer noise and whose events st...
by andrewtrobec Motivator in Splunk Search 10-31-2019
0 2
0
2
bleung93
I have this search to display sourcetypes by index. | metasearch index=* sourcetype=* | stats values(sourcetype) as ...
by bleung93 Path Finder in Splunk Search 10-31-2019
0 2
0
2
prakash007
I'm using this regex to mask cc data in props.cof on a Heavy Forwarder....need help in validating.... log format ...
by prakash007 Builder in Splunk Search 10-30-2019
0 5
0
5
entpnerd
I have a field in my query called Attempt that is either a non-negative integer or a special value "null". I use the ...
by entpnerd Explorer in Splunk Search 10-30-2019
0 1
0
1
vb1612
Hi , my search output is like mysearch | table col1 col2 col3 I want col4 as max(col1,col2) Thanks
by vb1612 New Member in Splunk Search 10-30-2019
0 1
0
1
stasiakm
Trying to find the definition of the various values of the Blocked field. Yes and No are self explanatory, but I have...
by stasiakm New Member in Splunk Search 10-30-2019
0 1
0
1
rhugo
Please help me extract NGN4000000 from L15= so I can have a field of TotalCash_In_ATM=NGN4000000. 2019-10-29 12:...
by rhugo Observer in Splunk Search 10-30-2019
0 5
0
5
watsm10
I'm producing a report for some service owners. It is designed to give them a breakdown of successes and failures spl...
by watsm10 Communicator in Splunk Search 10-30-2019
1 10
1
10
mahenderj
Hi, I wanted to search result as count from two log statements. one log statement has value "...Out of stock ..." a...
by mahenderj New Member in Splunk Search 10-30-2019
0 3
0
3
nukarajusundeep
index=concourse sourcetype="deployments: csv" if project = * and team=$team$ | stats count by project, team elif team...
by nukarajusundeep New Member in Splunk Search 10-30-2019
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...