Splunk Search

Splunk Search
Community Activity
venkat0896
Hi, I am working on a dashboard. i am creating a table to monitor the count, average response time and maximum respo...
by venkat0896 Path Finder in Splunk Search 08-21-2019
0 8
0
8
danielbb
A developer here wrote the following - |eval admin_activity=if((like(cmd_data, "%audit%") AND like(cmd_data, "%star...
by danielbb Motivator in Splunk Search 08-21-2019
0 2
0
2
AKG1_old1
Hi, How can we Ignore timechart column if all rows having 0 values. basically I am using trellis to display and w...
by AKG1_old1 Builder in Splunk Search 08-21-2019
0 4
0
4
dsmith1988
I am trying to run a search from amazon. index=amazon-aws sourcetype="aws:description" source="*:ec2_instances" W...
by dsmith1988 Engager in Splunk Search 08-21-2019
0 2
0
2
deeptha1992
How I can Change this sql query to splunk query, I tried in different way but It is not giving proper result please h...
by deeptha1992 New Member in Splunk Search 08-21-2019
0 4
0
4
Ricapar
I have some logs where there are events that are like this: Apr 5 21:16:33 myhost001.company.com key=value key2=va...
by Ricapar Communicator in Splunk Search 08-21-2019
0 6
0
6
Sujithkumarkb
The data in event 1 is incomplete and the rest of it is getting populated into event2 and so on . If i am not wrong ,...
by Sujithkumarkb Observer in Splunk Search 08-21-2019
0 0
0
0
IRHM73
Hi. I wonder whether someone may be able to help me please. I'm using the query below: | multisearch [ search `gat...
by IRHM73 Motivator in Splunk Search 08-21-2019
0 3
0
3
balcv
I have created a lookup table, service.csv host,service,resource "host1","fdl","all" "host2","finance","db" "host3...
by balcv Contributor in Splunk Search 08-20-2019
0 2
0
2
shayvdee
Hi, I am trying to create a search that finds two sequential events. So far I have: index=wineventlog EventCode=462...
by shayvdee Explorer in Splunk Search 08-20-2019
0 4
0
4
cquinney
Greetings, I'm trying to get multiple totals for multiple fields. My current query incorporates | stats count as ...
by cquinney Communicator in Splunk Search 08-20-2019
0 3
0
3
divyamudundi
Hi, I am trying to extract a license file from our current license pool. All I could see is the delete option for th...
by divyamudundi Path Finder in Splunk Search 08-20-2019
2 4
2
4
uvmk61
Any help is appreciated in parsing the following xml data retrieved from DB connect input. We just need the Name an...
by uvmk61 New Member in Splunk Search 08-20-2019
0 5
0
5
a212830
Hi, I'm trying to count the number of events for a specific index/sourcetype combo, and then total them into a new f...
by a212830 Champion in Splunk Search 08-20-2019
0 1
0
1
juanherrera
Hello there, In our company we've been using Splunk for a while now but I think we use it not to it's full potential...
by juanherrera Explorer in Splunk Search 08-20-2019
0 7
0
7
shulmaniel
I'd like to build an alert that essentially says "if the count from this hour is more than twice, or less than half, ...
by shulmaniel New Member in Splunk Search 08-20-2019
0 3
0
3
aohls
We have logging with user data for the requests each use does. We have created some averages and dashboards with this...
by aohls Contributor in Splunk Search 08-20-2019
0 4
0
4
jpsquires
This is probably quite simple and I am missing something.. i am using this search. index=sxxx sourcetype=sxxx host=...
by jpsquires New Member in Splunk Search 08-20-2019
0 3
0
3
vikashperiwal
I am trying to iterate through 16million data and trying to use tstats instead of stats... please help me out in conv...
by vikashperiwal Path Finder in Splunk Search 08-20-2019
0 6
0
6
rmcmillin
this is one of the events i am seeing and we are trying to figure our why only 20-30 servers are doing this 08/20/20...
by rmcmillin New Member in Splunk Search 08-20-2019
0 0
0
0
venkat0896
Hi i am trying to create a Dashboard. i need some assistance on creating a table format. i have some executions like...
by venkat0896 Path Finder in Splunk Search 08-20-2019
0 10
0
10
nlisle
Hello, I currently have a search running on two different indexes pulling different fields. There is one field cal...
by nlisle New Member in Splunk Search 08-20-2019
0 2
0
2
jasongb
I need to document a transaction that begins with a multithreaded process. The process creates multiple entries in a...
by jasongb Path Finder in Splunk Search 08-20-2019
0 12
0
12
Reddi694325
Have to find a source type how many times it is not sending data to index within a month or some period of time Than...
by Reddi694325 Path Finder in Splunk Search 08-20-2019
0 1
0
1
hazemfarajallah
Hello everyone I'm using this query `|eval Status = case (eventId="endProcess" ,"Completed" ,eventId="error","Term...
by hazemfarajallah Explorer in Splunk Search 08-19-2019
0 6
0
6
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...