Splunk Search

Splunk Search
Community Activity
vb1612
Hi , my search output is like mysearch | table col1 col2 col3 I want col4 as max(col1,col2) Thanks
by vb1612 New Member in Splunk Search 10-30-2019
0 1
0
1
stasiakm
Trying to find the definition of the various values of the Blocked field. Yes and No are self explanatory, but I have...
by stasiakm New Member in Splunk Search 10-30-2019
0 1
0
1
rhugo
Please help me extract NGN4000000 from L15= so I can have a field of TotalCash_In_ATM=NGN4000000. 2019-10-29 12:...
by rhugo Observer in Splunk Search 10-30-2019
0 5
0
5
watsm10
I'm producing a report for some service owners. It is designed to give them a breakdown of successes and failures spl...
by watsm10 Communicator in Splunk Search 10-30-2019
1 10
1
10
mahenderj
Hi, I wanted to search result as count from two log statements. one log statement has value "...Out of stock ..." a...
by mahenderj New Member in Splunk Search 10-30-2019
0 3
0
3
nukarajusundeep
index=concourse sourcetype="deployments: csv" if project = * and team=$team$ | stats count by project, team elif team...
by nukarajusundeep New Member in Splunk Search 10-30-2019
0 4
0
4
pir8radio
In this string: Version=\x221.7.53a\x22 I want to capture everything in between \x22 and \x22 so the result...
by pir8radio Path Finder in Splunk Search 10-30-2019
0 6
0
6
jonthanze
I have a search between two data sets using join, let's say sourcetype A and B. My search looks like this: sourcetyp...
by jonthanze Explorer in Splunk Search 10-30-2019
0 2
0
2
mhouse
I need help figuring something out. Got this search during .conf19 to be used to do a Forwarder weight distribution s...
by mhouse New Member in Splunk Search 10-30-2019
0 3
0
3
danielbb
We would like to find out whether a certain string has three open parentheses characters in any order. Can we do it w...
by danielbb Motivator in Splunk Search 10-30-2019
0 5
0
5
chrisschum
I have a field where results are 'some letter & number combination of 3 or 4 characters' that includes txt on the end...
by chrisschum Path Finder in Splunk Search 10-30-2019
0 6
0
6
frbuser
I am trying to use a regex to extract a PowerShell script that is being executed in a way that also includes the dire...
by frbuser Path Finder in Splunk Search 10-30-2019
0 1
0
1
esalesapns2
Splunk Enterprise, v7.0.3 I ran the search in https://answers.splunk.com/answers/750097/search-performance-impact-ho...
by esalesapns2 Communicator in Splunk Search 10-30-2019
0 0
0
0
jip31
hi I use the search below in order to display a pie chart When I execute the first part of the search (before join),...
by jip31 Motivator in Splunk Search 10-30-2019
0 4
0
4
pgadhari
I am facing issues wherein the events with same timestamp are not showing in results, when I dedup based on time, but...
by pgadhari Builder in Splunk Search 10-30-2019
0 10
0
10
pavanbmishra
Hey guys, Is there any way how splunk get this lookup update itself or do we need to manually feed it? if yes what i...
by pavanbmishra Path Finder in Splunk Search 10-30-2019
0 2
0
2
ngperf
Hi, I have data in the following format from Microsoft Windows OS process executions: FileName,ProcessID,ParentProc...
by ngperf Explorer in Splunk Search 10-30-2019
0 5
0
5
astatrial
Hi all, For some reason, my search doesn't work properly. The search is as the one below: ....| search NOT (x=3 AN...
by astatrial Contributor in Splunk Search 10-30-2019
0 8
0
8
jbassi1
I have created a dashboard with two separate graphs one which counts the total number of calls made to the hosts and ...
by jbassi1 New Member in Splunk Search 10-30-2019
0 3
0
3
bretlowery1
Using Splunk Enterprise 7.3.2 on a MacBook. Two searches on the same static (loaded-once) search index, same date ra...
by bretlowery1 New Member in Splunk Search 10-29-2019
0 2
0
2
spammenot66
When creating a search using pivot/data model, I can add a filter that looks something like: FILTER Brand in (brand...
by spammenot66 Contributor in Splunk Search 10-29-2019
0 7
0
7
arseniof
So what I want to do is tag all IPs that belong to certain AWS regions and filter out those IPs. I want to try and ta...
by arseniof New Member in Splunk Search 10-29-2019
0 1
0
1
nick405060
I have a string date field and would like to sort it in a table by clicking the field. No, I do not want it displaye...
by nick405060 Motivator in Splunk Search 10-29-2019
0 1
0
1
dvohra
I have recently deployed Splunk UF on windows machined, installation and setup is successful. But while searching the...
by dvohra Explorer in Splunk Search 10-29-2019
0 4
0
4
avni26
Hi Team, I have multiple sources in sourcetype. Want to see difference of result from last two sources. Latest source...
by avni26 Explorer in Splunk Search 10-29-2019
0 7
0
7
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...