Splunk Search

Splunk Search
Community Activity
w564432
I have a dropdown that reads from a lookup but would like to allow the user to enter in a value that doesn't exist in...
by w564432 Explorer in Splunk Search 08-06-2019
0 3
0
3
3666142
I have a line graph that displays the number of transactions per hour. I want a trendline to go with it, but I want i...
by 3666142 Path Finder in Splunk Search 08-06-2019
0 8
0
8
VijaySrrie
I use the below query to find the index size, how can I modify the query to get the comparision between todays's inde...
by VijaySrrie Builder in Splunk Search 08-06-2019
0 10
0
10
sahil237888
Hi Team, Need help in creating a query. I want to display 0 when no data/events found. But I am getting "No results ...
by sahil237888 Path Finder in Splunk Search 08-06-2019
0 3
0
3
sivapuvvada
I am not always getting one interesting field, even though I have selected all fields from the fields bar on the left...
by sivapuvvada Path Finder in Splunk Search 08-06-2019
0 4
0
4
pkumar9610
HI Friends, In Search&Reporting app (default app) when I search anything, I see only 3 INTERESTING FIELDS coming up...
by pkumar9610 Explorer in Splunk Search 08-06-2019
0 1
0
1
philipfritsch
Right now we receive and store several data points per second in an index and do reporting on it. In the future we wo...
by philipfritsch New Member in Splunk Search 08-06-2019
0 1
0
1
joerglang
I have create a metric Index called "my_metric_index". I see, that the index is populated with events. I have added ...
by joerglang Engager in Splunk Search 08-06-2019
0 0
0
0
philrego
Let's say I perform this search: index=mysecretindex host=mysecrethost* source="/my.log" error-3005 Then say I s...
by philrego Path Finder in Splunk Search 08-06-2019
0 5
0
5
Dsrao12345
my search query : index=index1"PrepareResponseTime= " | rex "PreResponseTime= (?[0-9]*) ms" | where PrepareRespon...
by Dsrao12345 New Member in Splunk Search 08-06-2019
0 1
0
1
Mayanakhan
Hi, We are unable to start the our one of the indexer in cluster getting the below error. Can we copy the directory...
by Mayanakhan Explorer in Splunk Search 08-06-2019
0 1
0
1
bagarwal
Hi, I have created a lookup file name file1.csv . There are two columns in the file "Application" and "Allow" and ...
by bagarwal Path Finder in Splunk Search 08-05-2019
0 4
0
4
daniel333
All, Can I map multiple AD groups to one role in authentication.conf? Example?
by daniel333 Builder in Splunk Search 08-05-2019
0 1
0
1
Shashank_87
Hi, I am struggling to form my search query along with lookup. So the scenarios is like this - I have a search query ...
by Shashank_87 Explorer in Splunk Search 08-05-2019
0 3
0
3
intelli2019
Hi, I thought this would be easy but no! I'm doing the query below on the Sample data below but the FileTime_END valu...
by intelli2019 New Member in Splunk Search 08-05-2019
0 7
0
7
dccrain
Recently I migrated one of our indexers to a new machine. Sometimes searches result in the below message despite t...
by dccrain New Member in Splunk Search 08-05-2019
0 3
0
3
amahesh3
Hi, In my Splunk logs, I have a field called location which stores values like" SINGAPORE (ABC) WASHINGTON DC (ABC)...
by amahesh3 New Member in Splunk Search 08-05-2019
0 10
0
10
hartfoml
I have a search looking for the events I want to look at. Then i want to have the average of the events per day. I ...
by hartfoml Motivator in Splunk Search 08-05-2019
4 16
4
16
simpkins1958
Seeing lots of "SearchEvaluator - using old evaluator" in search.log for TSTAT with DMA. Could someone please explai...
by simpkins1958 Contributor in Splunk Search 08-05-2019
0 1
0
1
tewarbit
I am using a transaction to combine events and I want to calculate the difference in time between the two events. I a...
by tewarbit New Member in Splunk Search 08-05-2019
0 3
0
3
Dsrao12345
how to solve the above issue using eval function. (1 * 100) / (1 + 2) = % .
by Dsrao12345 New Member in Splunk Search 08-05-2019
0 2
0
2
jig004
Stuck on regex question for Ad FS logs. I am trying to extract all ips following a field ("Client IP: ") in a AD FS ...
by jig004 Engager in Splunk Search 08-05-2019
1 2
1
2
bah5663_98
I made the following search to group exceptions together that happened within 1 second but I want to be able to view ...
by bah5663_98 Explorer in Splunk Search 08-05-2019
0 2
0
2
nsantiago17
(first four rows) JOB_NAME,Description ATUALIZACAOATIVOS,BATCH-PRO-AGRO BLOQUEIO-EMISSORES,BATCH-PRO-AGRO CONCATENAPD...
by nsantiago17 Explorer in Splunk Search 08-05-2019
0 2
0
2
ecedwards
So, I'm trying to come up with a way to compare data from this year and last year into a Single Value Graph but I am ...
by ecedwards Engager in Splunk Search 08-05-2019
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...