Splunk Search

Splunk Search
Community Activity
bapun18
Hi I want to improve my search for better search performance, please find the attachment enclosed.![alt text
by bapun18 Communicator in Splunk Search 11-01-2019
0 8
0
8
mozukun3
お世話になります。 サーチ文の書き方についてご教示ください。 まず、以下の検索結果を出しています。 ・サーチ文 「soucetype="test1" | table host, user, state」 ・サーチ結果 ------...
by mozukun3 New Member in Splunk Search 11-01-2019
0 5
0
5
ktn01
Hello, I have events in the following format: 20/08/19 16:34:17 login1 command RunAsUsers="web,tomcat,embed" wit...
by ktn01 Path Finder in Splunk Search 11-01-2019
0 2
0
2
Robbie1194
Hi guys, I was wondering if anyone knew of a method of appending data to a lookup, but not overwriting anything in ...
by Robbie1194 Communicator in Splunk Search 11-01-2019
0 2
0
2
bsaujla131984
I have created an alert which basically checks the occurrence in particular keyword in two log files , however there ...
by bsaujla131984 Path Finder in Splunk Search 11-01-2019
0 1
0
1
ahuseid
I need to join two searches on a common field in which I want a value of the left search matches all the values of t...
by ahuseid New Member in Splunk Search 11-01-2019
0 6
0
6
ajtalbot1
Simple search to look at the battery status on my UPS: UPS_BATT | timechart max(UPS_BATT) span=1m But the UPS_BATT...
by ajtalbot1 Engager in Splunk Search 11-01-2019
0 4
0
4
akki2428
Hi, I would want to search for all results for this specific string pattern 'record has not been created for id XXXXX...
by akki2428 New Member in Splunk Search 11-01-2019
0 9
0
9
daniel_splunk
Have a search with many subsearch and append command like below pattern. | makeresults | eval abcd="acded" | appe...
by daniel_splunk Splunk Employee Splunk Employee in Splunk Search 11-01-2019
0 1
0
1
mansel_scheffel
Hi, Is there any benefit to using the old method when using summary indexing? Basically I would like to the know dif...
by mansel_scheffel Explorer in Splunk Search 11-01-2019
0 6
0
6
kdulhan
Hi All, I have some search criteria followed by stats as: Search ns=app1 Error | stats sum(eval(AcctNo="'1000394'")...
by kdulhan Explorer in Splunk Search 10-31-2019
1 8
1
8
rashi83
I need to display a table with 4 columns and date is like this: Colum A Col B Col C Col D x ...
by rashi83 Path Finder in Splunk Search 10-31-2019
0 2
0
2
raghu0463
Hi, Can I write my search as: index=idx1 host != (a,b,c) | stats count by host The thing is I want to filter some ...
by raghu0463 Explorer in Splunk Search 10-31-2019
0 1
0
1
jscraig2006
I've created several macros with a tstat query. when running the macro through the UI, no results are displayed. When...
by jscraig2006 Communicator in Splunk Search 10-31-2019
0 1
0
1
harshparikhxlrd
I'm trying to remove characters after a certain string in my search string. I am still getting the strings after "3"...
by harshparikhxlrd Path Finder in Splunk Search 10-31-2019
0 2
0
2
DanielleM
I am calculating monthly averages and have an issue where on a single day in October there was an error in the data. ...
by DanielleM Explorer in Splunk Search 10-31-2019
0 2
0
2
rmmiller
I have a query using streamstats that is on the intensive side because I'm not dealing with nicely-formatted data. (...
by rmmiller Contributor in Splunk Search 10-31-2019
0 9
0
9
alancalvitti
In a search executed via Python SDK, the stat list truncates results to 100 results, despite the fact that count=0. ...
by alancalvitti Path Finder in Splunk Search 10-31-2019
0 9
0
9
dabroma5
Hi Team, I would like to create a named field to filter Ethernet port numbers. My expression: \beth\d*(?:-\d+)*(?:/\...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 5
0
5
dabroma5
Hi Team I need to filter logs to catch switches port numbers. I use Splunk Cloud, my expression: \beth\d*(?:-\d+)...
by dabroma5 Explorer in Splunk Search 10-31-2019
0 7
0
7
pench2k19
Hi Ninjas, I have the following values for host name field . appra94a0350 appra92a0350 appra84a0201 appra25a0201 ap...
by pench2k19 Explorer in Splunk Search 10-31-2019
0 2
0
2
jnahuelperez35
Hi Guys! i've got the next situation Trying to replace some characters in this events: \device\harddiskvolume4\wind...
by jnahuelperez35 Path Finder in Splunk Search 10-31-2019
2 3
2
3
totaro
Hi, i was hoping to extract all the fields after "CommandInvocation" that appears in the PS log but i wasnt able to e...
by totaro Explorer in Splunk Search 10-31-2019
0 2
0
2
andrewtrobec
Hello all, I am trying to index a subset of a very painful log which has header and footer noise and whose events st...
by andrewtrobec Motivator in Splunk Search 10-31-2019
0 2
0
2
bleung93
I have this search to display sourcetypes by index. | metasearch index=* sourcetype=* | stats values(sourcetype) as ...
by bleung93 Path Finder in Splunk Search 10-31-2019
0 2
0
2
Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...