Splunk Search

Splunk Search
Community Activity
hartfoml
I have a search looking for the events I want to look at. Then i want to have the average of the events per day. I ...
by hartfoml Motivator in Splunk Search 08-05-2019
4 16
4
16
simpkins1958
Seeing lots of "SearchEvaluator - using old evaluator" in search.log for TSTAT with DMA. Could someone please explai...
by simpkins1958 Contributor in Splunk Search 08-05-2019
0 1
0
1
tewarbit
I am using a transaction to combine events and I want to calculate the difference in time between the two events. I a...
by tewarbit New Member in Splunk Search 08-05-2019
0 3
0
3
Dsrao12345
how to solve the above issue using eval function. (1 * 100) / (1 + 2) = % .
by Dsrao12345 New Member in Splunk Search 08-05-2019
0 2
0
2
jig004
Stuck on regex question for Ad FS logs. I am trying to extract all ips following a field ("Client IP: ") in a AD FS ...
by jig004 Engager in Splunk Search 08-05-2019
1 2
1
2
bah5663_98
I made the following search to group exceptions together that happened within 1 second but I want to be able to view ...
by bah5663_98 Explorer in Splunk Search 08-05-2019
0 2
0
2
nsantiago17
(first four rows) JOB_NAME,Description ATUALIZACAOATIVOS,BATCH-PRO-AGRO BLOQUEIO-EMISSORES,BATCH-PRO-AGRO CONCATENAPD...
by nsantiago17 Explorer in Splunk Search 08-05-2019
0 2
0
2
ecedwards
So, I'm trying to come up with a way to compare data from this year and last year into a Single Value Graph but I am ...
by ecedwards Engager in Splunk Search 08-05-2019
0 1
0
1
pateriaak
I am getting info=denied events for specific users while searching for _audit index. What is the significance of this...
by pateriaak Explorer in Splunk Search 08-05-2019
0 3
0
3
dpraveen88
I need queries like: which Splunk user generating the query? Output need [ Username, Time, Search Query] Which Sp...
by dpraveen88 Explorer in Splunk Search 08-05-2019
0 3
0
3
katharsys
(Using Splunk 6.1.2 for...reasons) Background: We send out a push notification to a third party. The third party som...
by katharsys Path Finder in Splunk Search 08-05-2019
0 6
0
6
Shashank_87
Hi, I need some help related to a search query. My search query has a field called "holdings" which contain data like...
by Shashank_87 Explorer in Splunk Search 08-05-2019
0 3
0
3
trem0re09
I have a field name called Column1 with the following data below... Data1: |Transitioned to:Team1|Transition Reason:...
by trem0re09 Explorer in Splunk Search 08-05-2019
0 6
0
6
strive
Hi, We have splunk UF installed on our streamers. The splunk UF sends logs to splunk forwarder of our analytics set...
by strive Influencer in Splunk Search 08-05-2019
1 8
1
8
sbhatnagar88
How can we apply below logic in splunk. We have the data in Splunk which is coming out as below. Host Patching L...
by sbhatnagar88 Path Finder in Splunk Search 08-05-2019
0 2
0
2
marisstella
Hii Everyone, I want to move all the knowledge objects and everything from one splunk instance to another instance......
by marisstella Explorer in Splunk Search 08-05-2019
0 5
0
5
miguelebf
Hi i have raw data like this: 192.0.100.3 - - [30/Jul/2019:00:06:05 -0500] "GET /test/ HTTP/1.1" 403 207 "-" "Mozill...
by miguelebf New Member in Splunk Search 08-04-2019
0 2
0
2
surekhasplunk
Hi, index="spectrum" * | eval foo=_cd | rename "ns1.alarm.ns1.attribute{}.$" as value "ns1.alarm.ns1.attribute{}.@i...
by surekhasplunk Communicator in Splunk Search 08-04-2019
0 4
0
4
chinkeeparco
Hello guys, I have the following syntax and data: However, there is a discrepancy with the total count per catego...
by chinkeeparco Explorer in Splunk Search 08-04-2019
0 10
0
10
jhuysing
We have a log of some metrics that look like this: 20:45:00 10.10.71.01 values : [12035313, 233658, 0, 0, 24249, 13...
by jhuysing Explorer in Splunk Search 08-04-2019
0 6
0
6
saikumarsplunkt
Can someone please help with extracting the bold highlighted field from below /07981368-d226-4cf6-8d88-9853c843bcb9...
by saikumarsplunkt New Member in Splunk Search 08-04-2019
0 1
0
1
harshal_chakran
I have a search in below format: index=xyz sourcetype=abc...|table code... |join code[search index=def ....] |where...
by harshal_chakran Builder in Splunk Search 08-04-2019
0 7
0
7
praphulla1
one of our dashboards were using below query | timechart count span=1d cont=false in 6.6.4 Splunk enterprise, we cou...
by praphulla1 Path Finder in Splunk Search 08-04-2019
0 8
0
8
balash1979
I have 3 panels. Each panel runs a query and displays the result in timechart. This works fine. Now , I would like t...
by balash1979 Path Finder in Splunk Search 08-04-2019
0 8
0
8
monipinni
Hi, Can any one help me adding two fields in one search I am seeing both fields in splunk selected fields but not s...
by monipinni Explorer in Splunk Search 08-04-2019
0 2
0
2
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...