Splunk Search

Splunk Search
Community Activity
sjlaplac
The following SPL returns data for all returns for a day. How can I just return the maximum return for the day? Exam...
by sjlaplac Loves-to-Learn Lots in Splunk Search 09-16-2019
0 3
0
3
siddh01r
Hi There, I am trying to find where total account lockouts that are greater than 2 within the time frame of 30 mins....
by siddh01r New Member in Splunk Search 09-16-2019
0 4
0
4
ankitarath2011
I want to match a reg ex pattern (e.g. "aaa\s+:\d\d") from a lookup file. pattern,output_value "aaa\s+:\d\d:", 2 "aa...
by ankitarath2011 Path Finder in Splunk Search 09-16-2019
0 2
0
2
harkirat9712
Hi Team, I am using the below command to get the last 4 weeks of data solutionType=EML. index=sample1 "com.URL.con...
by harkirat9712 Explorer in Splunk Search 09-15-2019
0 0
0
0
sdewar83
Hi, I'm very much a Splunk novice, but I've been playing around with trying to do some health checks for Splunk so w...
by sdewar83 Path Finder in Splunk Search 09-15-2019
0 2
0
2
rey123
I got a different result count when I executed this query a week before, and when I executed it today. The first time...
by rey123 Path Finder in Splunk Search 09-15-2019
0 5
0
5
sandeepmakkena
gauge="ProcessorResponse.Country[US]Processor[ApgProcessor]PaymentType[VISA] DECLINE" is one of the field. I am tryin...
by sandeepmakkena Contributor in Splunk Search 09-15-2019
0 3
0
3
vasanthi77
I am using pattern base indexing like below that is if i have splunk_send and app host in event i m trying to discard...
by vasanthi77 Explorer in Splunk Search 09-15-2019
0 2
0
2
lsy9891
Hi, I know that we can create radial gauges using aggregate values but I've selected the radial gauge visualization ...
by lsy9891 Engager in Splunk Search 09-15-2019
0 1
0
1
gelica
I have a search that generates different number of results and I can't figure out why.. Here's my search: sourcety...
by gelica Communicator in Splunk Search 09-14-2019
2 12
2
12
PC00128849
I have a file, which will be updated multiple times in a single day and the it will be indexed into splunk multiples ...
by PC00128849 New Member in Splunk Search 09-14-2019
0 1
0
1
pop1989
I use Splunk to calculate user's Internet hits. There are about 710 thousands entries. I searched several times, but ...
by pop1989 Explorer in Splunk Search 09-14-2019
0 4
0
4
nishit_92
I have subnet lookup in cidr notation. so i am trying to print subnet detail with dest ip but not getting result. qu...
by nishit_92 Explorer in Splunk Search 09-14-2019
0 2
0
2
ankitarath2011
Hi, I have a lookup file with following structure. pattern,output_value "aaa\s+:\d\d:", 2 "aaa\s+:\d:", 1 For m...
by ankitarath2011 Path Finder in Splunk Search 09-14-2019
0 7
0
7
reaver3020
I have an alert configured to automatically send an email upon a user account locking. I'm looking for the email to o...
by reaver3020 New Member in Splunk Search 09-14-2019
0 1
0
1
ashishmgupta
If I have a search result which has a field named "Field1" and It has values like : This is Word1 now. This is Word2 ...
by ashishmgupta Explorer in Splunk Search 09-14-2019
0 1
0
1
smiththebest
My event log has comma separated field values of 100+ fields. Each field can have about 2-15 different values. Exampl...
by smiththebest New Member in Splunk Search 09-14-2019
0 0
0
0
anandhalagarasa
My search is that I have to log in the client machine, which needs to be ingested into Splunk Cloud- so I have deploy...
by anandhalagarasa Path Finder in Splunk Search 09-13-2019
0 7
0
7
koshyk
We need to override a tags & eventtypes from one of the official TA (eg eventtype=ssh_authentication). eventtypes....
by koshyk Super Champion in Splunk Search 09-13-2019
0 2
0
2
alex387
Hello, Is there a way to split out the unique values of a field into separate fields that are returned after a searc...
by alex387 New Member in Splunk Search 09-13-2019
0 4
0
4
toryan
I have a somewhat complicated search whose results I present in a dashboard, and looks a bit like this: [ search...
by toryan Engager in Splunk Search 09-13-2019
0 0
0
0
pkbhavani
I have created a field called PROCESS via Fields » Field transformations I could not see in the field appear in th...
by pkbhavani New Member in Splunk Search 09-13-2019
0 1
0
1
sai33
Hi All, I'm looking to include a If Else Check along with Len() Function along with Eval in my Search. My Raw synta...
by sai33 Explorer in Splunk Search 09-13-2019
0 2
0
2
twinspop
Since 7.3 the missing indexes message below goes to all my users causing many panicked questions about Splunk being d...
by twinspop Influencer in Splunk Search 09-13-2019
0 4
0
4
Glasses
Hi I need a little clarification as the related posts I have found are confusing. I inherited a lot of reports from...
by Glasses Builder in Splunk Search 09-13-2019
0 4
0
4
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...