Splunk Search

Splunk Search
Community Activity
danielbb
We need to decide soon how much storage to allocate to the hot/warm volume versus the cold one. Therefore, I would li...
by danielbb Motivator in Splunk Search 11-05-2019
0 7
0
7
edoardo_vicendo
Hi all, In the middle of a search, I have two string fields, one is called A and the other B (both have the ";" as d...
by edoardo_vicendo Builder in Splunk Search 11-05-2019
1 4
1
4
surekhasplunk
The search I am using is below and in the output for few I am getting 3 records in the filed manage. Please help me t...
by surekhasplunk Communicator in Splunk Search 11-05-2019
0 5
0
5
bineetadas
If a certain incident is in resolved/closed state I want all logs pertaining to that incident to be excluded from the...
by bineetadas New Member in Splunk Search 11-05-2019
0 3
0
3
chrishartsock
Hello, I am currently trying to do a search across two different sourcetypes using the map command: sourcetype=sour...
by chrishartsock Path Finder in Splunk Search 11-05-2019
0 7
0
7
prettysunshinez
Hi, I would want to have the count of a string (say "abcdef"). sometimes the string occurs multiple times in the sam...
by prettysunshinez Explorer in Splunk Search 11-05-2019
0 1
0
1
matimat
Hi, I want to show how many lines contains some value even if no line return. My data : Row 1 : F1: a Row 2 ...
by matimat Explorer in Splunk Search 11-05-2019
1 4
1
4
steffen1
I have the data field "user" with data like: user1, user1, user2, user2, user3, user3, user3, ... How do I get/coun...
by steffen1 Engager in Splunk Search 11-04-2019
0 4
0
4
ayush1906
Hi , My current index when done table shows: Name| Attendance | Class abc | Present | 2A efg ...
by ayush1906 Communicator in Splunk Search 11-04-2019
0 3
0
3
basplunk
How differences named capturing group expression between "(?<name>)" and "(?P<name>)"?
by basplunk New Member in Splunk Search 11-04-2019
0 2
0
2
gndivya
There are 3 different values for one particular field say field1 - "INTPAY\ITS\TD_EFT\can contain other data", "INTPA...
by gndivya Explorer in Splunk Search 11-04-2019
1 2
1
2
lsy9891
Hi how to disable the hover functionality for line charts? I've tried disabling tooltips but it just hides the label-...
by lsy9891 Engager in Splunk Search 11-04-2019
0 0
0
0
amesbury
Is there a way to set sampling for subsearches separately from the main search? For example, given a search of a hug...
by amesbury Engager in Splunk Search 11-04-2019
1 2
1
2
esalesapns2
I created a Splunk Health Dashboard for myself on the server that runs my Monitoring Console. The MC server is not ...
by esalesapns2 Communicator in Splunk Search 11-04-2019
1 1
1
1
danielransell
I'm working on creating either a report with a table or a dashboard to visualize the status of my Windows Audit Polic...
by danielransell Path Finder in Splunk Search 11-04-2019
0 8
0
8
gsureshkumarcse
Hi Team, I am trying to run stats splunk search using c# SDK and getting task cancelled error. Kindly help me on th...
by gsureshkumarcse New Member in Splunk Search 11-04-2019
0 0
0
0
Olli1919
Hello fellow Splunkies, is there a method to programatically list the objects/resources used by (scheduled) searches...
by Olli1919 Path Finder in Splunk Search 11-04-2019
2 9
2
9
bencooper1
Hello, I am trying to compare two time windows in the same index but I would like the chart comparing them to be ba...
by bencooper1 Engager in Splunk Search 11-04-2019
0 3
0
3
damucka
Hello, How would I set the earliest and latest to the last full hour? Example: current time 5:19 pm I want earliest=...
by damucka Builder in Splunk Search 11-04-2019
1 2
1
2
vrmandadi
Below is the regex I am using |rex field=_raw "\d*\-\d*\s\d*\:\d*\:\d*\.\d*\s(?<Primary_Server>[^\s]+)\s*(?<Primary...
by vrmandadi Builder in Splunk Search 11-04-2019
1 3
1
3
jsproesser
I have been toying around with the task of identifying servers on our network with abnormal connection times . We hav...
by jsproesser New Member in Splunk Search 11-04-2019
0 5
0
5
gaurav_maniar
Hi All, is it possible to get list of sourcetype by host and index irrespective of time range? I just want the list ...
by gaurav_maniar Builder in Splunk Search 11-04-2019
0 5
0
5
lyderhansen
I want to highlight an entire row in a table when its clicked. I want this to be persistent so when I click outside t...
by lyderhansen Engager in Splunk Search 11-04-2019
0 2
0
2
NAVEEN_CTS
Hi i have a field A B C D for example with following data A B C D 1 2 3 4 1 2 2 3 2 3 3 4 I want a result ...
by NAVEEN_CTS Path Finder in Splunk Search 11-04-2019
0 1
0
1
harshparikhxlrd
I'm fairly new to splunk and have just learned how to use the rex/regex. I am trying to add a column in my string se...
by harshparikhxlrd Path Finder in Splunk Search 11-04-2019
0 3
0
3
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors