Splunk Search

Splunk Search
Community Activity
bsaujla131984
I have created an alert which basically checks the occurrence in particular keyword in two log files , however there ...
by bsaujla131984 Path Finder in Splunk Search 11-01-2019
0 1
0
1
ahuseid
I need to join two searches on a common field in which I want a value of the left search matches all the values of t...
by ahuseid New Member in Splunk Search 11-01-2019
0 6
0
6
ajtalbot1
Simple search to look at the battery status on my UPS: UPS_BATT | timechart max(UPS_BATT) span=1m But the UPS_BATT...
by ajtalbot1 Engager in Splunk Search 11-01-2019
0 4
0
4
akki2428
Hi, I would want to search for all results for this specific string pattern 'record has not been created for id XXXXX...
by akki2428 New Member in Splunk Search 11-01-2019
0 9
0
9
daniel_splunk
Have a search with many subsearch and append command like below pattern. | makeresults | eval abcd="acded" | appe...
by daniel_splunk Splunk Employee Splunk Employee in Splunk Search 11-01-2019
0 1
0
1
mansel_scheffel
Hi, Is there any benefit to using the old method when using summary indexing? Basically I would like to the know dif...
by mansel_scheffel Explorer in Splunk Search 11-01-2019
0 6
0
6
kdulhan
Hi All, I have some search criteria followed by stats as: Search ns=app1 Error | stats sum(eval(AcctNo="'1000394'")...
by kdulhan Explorer in Splunk Search 10-31-2019
1 8
1
8
rashi83
I need to display a table with 4 columns and date is like this: Colum A Col B Col C Col D x ...
by rashi83 Path Finder in Splunk Search 10-31-2019
0 2
0
2
raghu0463
Hi, Can I write my search as: index=idx1 host != (a,b,c) | stats count by host The thing is I want to filter some ...
by raghu0463 Explorer in Splunk Search 10-31-2019
0 1
0
1
jscraig2006
I've created several macros with a tstat query. when running the macro through the UI, no results are displayed. When...
by jscraig2006 Communicator in Splunk Search 10-31-2019
0 1
0
1
harshparikhxlrd
I'm trying to remove characters after a certain string in my search string. I am still getting the strings after "3"...
by harshparikhxlrd Path Finder in Splunk Search 10-31-2019
0 2
0
2
DanielleM
I am calculating monthly averages and have an issue where on a single day in October there was an error in the data. ...
by DanielleM Explorer in Splunk Search 10-31-2019
0 2
0
2
rmmiller
I have a query using streamstats that is on the intensive side because I'm not dealing with nicely-formatted data. (...
by rmmiller Contributor in Splunk Search 10-31-2019
0 9
0
9
alancalvitti
In a search executed via Python SDK, the stat list truncates results to 100 results, despite the fact that count=0. ...
by alancalvitti Path Finder in Splunk Search 10-31-2019
0 9
0
9
dabroma5
Hi Team, I would like to create a named field to filter Ethernet port numbers. My expression: \beth\d*(?:-\d+)*(?:/\...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 5
0
5
dabroma5
Hi Team I need to filter logs to catch switches port numbers. I use Splunk Cloud, my expression: \beth\d*(?:-\d+)...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 7
0
7
pench2k19
Hi Ninjas, I have the following values for host name field . appra94a0350 appra92a0350 appra84a0201 appra25a0201 ap...
by pench2k19 Explorer in Splunk Search 10-31-2019
0 2
0
2
jnahuelperez35
Hi Guys! i've got the next situation Trying to replace some characters in this events: \device\harddiskvolume4\wind...
by jnahuelperez35 Path Finder in Splunk Search 10-31-2019
2 3
2
3
totaro
Hi, i was hoping to extract all the fields after "CommandInvocation" that appears in the PS log but i wasnt able to e...
by totaro Explorer in Splunk Search 10-31-2019
0 2
0
2
andrewtrobec
Hello all, I am trying to index a subset of a very painful log which has header and footer noise and whose events st...
by andrewtrobec Motivator in Splunk Search 10-31-2019
0 2
0
2
bleung93
I have this search to display sourcetypes by index. | metasearch index=* sourcetype=* | stats values(sourcetype) as ...
by bleung93 Path Finder in Splunk Search 10-31-2019
0 2
0
2
prakash007
I'm using this regex to mask cc data in props.cof on a Heavy Forwarder....need help in validating.... log format ...
by prakash007 Builder in Splunk Search 10-30-2019
0 5
0
5
entpnerd
I have a field in my query called Attempt that is either a non-negative integer or a special value "null". I use the ...
by entpnerd Explorer in Splunk Search 10-30-2019
0 1
0
1
vb1612
Hi , my search output is like mysearch | table col1 col2 col3 I want col4 as max(col1,col2) Thanks
by vb1612 New Member in Splunk Search 10-30-2019
0 1
0
1
stasiakm
Trying to find the definition of the various values of the Blocked field. Yes and No are self explanatory, but I have...
by stasiakm New Member in Splunk Search 10-30-2019
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors