Splunk Search

Splunk Search
Community Activity
kavyamohan
index="event" | rex field=Macaddress mode=sed "s/(.{2})/\1-/g s/-$//" | rename Macaddress as "macAddress" | eval Se...
by kavyamohan Explorer in Splunk Search 10-03-2019
0 3
0
3
sahil237888
Hi Guys, Can anyone please help me in the below search. I want the name of all logfiles with details of keywords fro...
by sahil237888 Path Finder in Splunk Search 10-03-2019
0 2
0
2
sandeepmakkena
mess.url= /ae-business/shop/question/answer/product/HHRM2M/B?furl=bd2b75a1e85553a64aa4df2c47c93e049ccfe0d07f5dc518f95...
by sandeepmakkena Contributor in Splunk Search 10-03-2019
0 4
0
4
john_q
Hi, I have two strings like "opend" and "exited" in the events. So i need to count how many opened and exited today a...
by john_q Explorer in Splunk Search 10-03-2019
0 4
0
4
balash1979
Here is my query index="search_index" search processing_service | eval time_in_mins=('metric_value')/60 | stats a...
by balash1979 Path Finder in Splunk Search 10-03-2019
0 3
0
3
gkapitany
I have the search below: index=stats_summary dest_ip=172.* | dedup src_ip dest_ip| map maxsearches=100 search="| i...
by gkapitany Explorer in Splunk Search 10-03-2019
0 4
0
4
efaundez
Good afternoon could someone help me with this query: I have the following values | users | Age |   user1 | 99   u...
by efaundez Path Finder in Splunk Search 10-03-2019
0 2
0
2
efaundez
Good afternoon could someone help me with this query: I have the following values | users | Age |   user1 | 99   u...
by efaundez Path Finder in Splunk Search 10-03-2019
0 3
0
3
cspaid75
How do you combine info from multiple events but for one customer in one table or dashboard? For example: Event1: C...
by cspaid75 New Member in Splunk Search 10-03-2019
0 1
0
1
email2vimalraj
I've a search like this: (api=*/getUser) OR (api=/api/v1/addUser component=Comp1) OR (api=/api/v1/addUser component=...
by email2vimalraj New Member in Splunk Search 10-03-2019
0 1
0
1
gopiven
Hello Experts Actually I am trying to join the results of two searches. There are 3 indexes 1a,2b, and 3c with many...
by gopiven Explorer in Splunk Search 10-03-2019
0 2
0
2
Shashank_87
Hi, I am working on a query to get the peak hour count of of the top 100 visited pages on my website and i want this ...
by Shashank_87 Explorer in Splunk Search 10-03-2019
0 4
0
4
twinspop
I am trying to to default particular roles to particular apps by including default_namespace in a user-prefs file ins...
by twinspop Influencer in Splunk Search 10-03-2019
0 1
0
1
aalaa
Hello , i have a csv file that contains the list of all existing services, and i have a search already created that...
by aalaa Path Finder in Splunk Search 10-03-2019
0 2
0
2
jip31
hi From the code below, I need to do a pie chart with 2 labels I am doing a first count in order to count the events...
by jip31 Motivator in Splunk Search 10-03-2019
0 4
0
4
vikas_gopal
Hi Experts , I know this can be achieved in splunk , I have data like below name,status,date erp,200,2019-10-01 08...
by vikas_gopal Builder in Splunk Search 10-03-2019
0 2
0
2
Shashank_87
Hi, I am working on a query to get the peak hour count of of the top 100 requested pages on my website and i want thi...
by Shashank_87 Explorer in Splunk Search 10-03-2019
0 4
0
4
dinkarvidyarthy
group count SubTotal Desired_Field WEEK1 9 36 36 WEEK2 1 36 27 WEEK3 3 36 26 WEEK4 7 36 23 WEEK5 2...
by dinkarvidyarthy New Member in Splunk Search 10-03-2019
0 0
0
0
yuanliu
I have INDEXED_EXTRACTIONS = json and TIMESTAMP_FIELDS = my_timestamp_field in [my_json_type] stanza. This works whe...
by SplunkTrust SplunkTrust in Splunk Search 10-03-2019
0 0
0
0
conky2019
What I currently have, name=EVENT_1 | stats count(metrics.time), median(metrics.time, mean(metrics.time) by name ...
by conky2019 New Member in Splunk Search 10-03-2019
0 0
0
0
akke
I have a known value (eg. "rabbit") that I want to search for but it is in a unknown column in a large csv. Is it po...
by akke Explorer in Splunk Search 10-03-2019
0 1
0
1
longnh26
Now i very interested with command Spath of Splunk, can auto extract values JSON. But i can't extract it to field in ...
by longnh26 New Member in Splunk Search 10-03-2019
0 0
0
0
tonakano
ご教授ください。 複数のフィールドにそれぞれの集計数が設定されています。 これの一部を集計し、timechartで表現したいのですが、フィールドの中身の合算する方法が分かりません。 ・やりたいこと例 以下のフィールドを持つ A,B...
by tonakano Engager in Splunk Search 10-03-2019
0 2
0
2
sdewar83
Hi, I have a failed logon search which includes: | stats count by user, ComputerName |search count >3 earliest=now(...
by sdewar83 Path Finder in Splunk Search 10-02-2019
0 3
0
3
kevinfehrenbach
So I am having an issue where my Splunk logs from a particular source type pumps out trillions and trillions of logs ...
by kevinfehrenbach New Member in Splunk Search 10-02-2019
0 2
0
2
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors