Splunk Search

Splunk Search
Community Activity
sandeepmakkena
Mysesarch | stats avg(time) as "median", max(time) as MaxMedian max(time99) as "Max99th", max(time999) as Max999th by...
by sandeepmakkena Contributor in Splunk Search 10-01-2019
0 1
0
1
locose
I'm on Splunk 6.3.3 in my drop down for results per page, my available options are 10 per page, 20 per page and 50 pe...
by locose Path Finder in Splunk Search 10-01-2019
0 2
0
2
codedtech
I want to create a drill down that will go from a value on a stats table a time chart for the clicked pool name in a ...
by codedtech Path Finder in Splunk Search 10-01-2019
0 1
0
1
Nisarg
Is there a way we can pass epoch time from click of the table cell and set it to time filter of Splunk?
by Nisarg New Member in Splunk Search 10-01-2019
0 2
0
2
limalbert
A sample set of logs with fieldnames (time, name, and status) from one index=test 1. name=X1 status=FAIL time=7am 1....
by limalbert Path Finder in Splunk Search 09-30-2019
0 6
0
6
reverse
| timechart span=10m avg(Value) as AV by Host useother=false after running this query - I get desired values for a...
by reverse Contributor in Splunk Search 09-30-2019
0 3
0
3
jip31
hi I want to do a count the last event of a subsearch I am doing "stats count last" but it doesnt works what I have t...
by jip31 Motivator in Splunk Search 09-30-2019
0 2
0
2
learningnow
Want to run a report by comparing 2 indexes on " IP_Addresses" field. Ignore any matching " IP addresses" (If...
by learningnow New Member in Splunk Search 09-30-2019
0 1
0
1
swb03
I've seen a Python script and App for this, but not a lookup table. Since my admin is not willing to install either o...
by swb03 Explorer in Splunk Search 09-30-2019
3 6
3
6
learningnow
Trying to create a report using two indexes on same field "Pcname". Different datatype one of from Active Directo...
by learningnow New Member in Splunk Search 09-30-2019
0 2
0
2
wlcv
Hello! I want to compare my event flow rate from the benchmark (last 21 - last 7 days [14 days in total] to the last...
by wlcv Observer in Splunk Search 09-30-2019
0 1
0
1
vibhorkhanna
Hi, I am trying to find the abandonment rate for users who started the registration process but didnt complete it wit...
by vibhorkhanna New Member in Splunk Search 09-30-2019
0 3
0
3
jmcrabb
I've got a log file I'd like to have the Universal Forwarder watch and index, but there are 34 lines at the beginning...
by jmcrabb Explorer in Splunk Search 09-30-2019
3 9
3
9
onegame999
SEARCH | stats count(eval(Status="1")) as Assigned count(eval(Status="2")) as In_progress, count(eval(Status="3")) as...
by onegame999 Explorer in Splunk Search 09-30-2019
0 1
0
1
rlippincott
My search looks something like this: index=name | eval request=case(X, Y, X, Y, X, Y) | stats latest(request) as Req...
by rlippincott Explorer in Splunk Search 09-30-2019
0 4
0
4
dkoops
Here is the case: I've build a dashboard with 6 graphs/tables all using the same base search. It works like a charm ...
by dkoops Path Finder in Splunk Search 09-30-2019
0 7
0
7
jspvkey
Hi, I am really new to Splunk and Regular Expression stuff. I was planning to extract just the domain names of all e...
by jspvkey Explorer in Splunk Search 09-30-2019
0 7
0
7
smiththebest
My event log has comma separated field values of 100+ fields. Each field can have about 2-15 different values. Exampl...
by smiththebest New Member in Splunk Search 09-30-2019
0 3
0
3
haripriyasarve1
Status Count Failed 2 Passed 16 Skipped 22 Failed 66 Passed 7 Skipped 8 Please help me out on how to add the va...
by haripriyasarve1 Explorer in Splunk Search 09-30-2019
0 1
0
1
kmrkunal
When I am running the following search: index=main sourcetype="access_combined_wcookie"| stats list(useragent) as Br...
by kmrkunal New Member in Splunk Search 09-29-2019
0 2
0
2
tonakano
2つのデータを別のindex名でインポートしました。 2つのデータは、共通の端末IDにてリンクを取ることが可能です。 ・データA:各端末のバージョンを持ったデータ ・データB:各端末のエラー情報を持ったデータ やりたいこととしては、...
by tonakano Engager in Splunk Search 09-29-2019
0 2
0
2
luca1
I'm trying to extract IP (v4) addresses from different events. For instance, for an event such as: [...] sent ping ...
by luca1 New Member in Splunk Search 09-29-2019
0 3
0
3
Graham_Hanningt
Disclaimer: This is a "self-answering" question: I'm already doing what the question asks. I'm "asking" this question...
by Graham_Hanningt Builder in Splunk Search 09-29-2019
0 2
0
2
fmatera
I have an eventstats search that is working well. What I am having a difficult time with is that I am unable to retur...
by fmatera Explorer in Splunk Search 09-28-2019
0 2
0
2
manishyadav91
Problem: i have 200000 splunk events from which i only want 15000 events ( like vlookup in excel) Splunk events c...
by manishyadav91 New Member in Splunk Search 09-28-2019
0 10
0
10
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...