Splunk Search

Splunk Search
Community Activity
jip31
Hi I use the search below [| inputlookup host.csv | table host] index="x" sourcetype="x" | bucket _time span=3...
by jip31 Motivator in Splunk Search 07-22-2019
0 9
0
9
xuehui
i want save search results data into my index. how can i do it... (|crawl ... |input add index=myindex) is not work...
by xuehui New Member in Splunk Search 07-22-2019
0 2
0
2
bennythedroid
Given: index=log category=Price | eval PriceStatus=case(activity=="approve" AND event=="complete", "Price Approved"...
by bennythedroid Engager in Splunk Search 07-22-2019
0 3
0
3
tobi2k
For my Dashboard I ping a Source and want to see to Text-States: UP or DOWN. My search statement looks similar like ...
by tobi2k Explorer in Splunk Search 07-21-2019
0 4
0
4
michaelrosello
I am trying to extract xml fields using regex but I am encourtering this issue for this specific tags, It is working ...
by michaelrosello Path Finder in Splunk Search 07-21-2019
0 1
0
1
tobi2k
The rounding of search results has already been discussed numerously. But unfortunately, it doesn't work for me. I wa...
by tobi2k Explorer in Splunk Search 07-21-2019
0 4
0
4
chandanimishra
I am new in splunk i want to calculate the quarter data based on all people and what are the highest planned and lowe...
by chandanimishra New Member in Splunk Search 07-21-2019
0 1
0
1
michaelhoang
Hi, I am having the following issue that need your help. The scenario is: I am working on the report of firewall data...
by michaelhoang New Member in Splunk Search 07-21-2019
0 1
0
1
d00m4ig
Need creating a search query for Splunk that results in a list of unique requests that have been completed.
by d00m4ig Engager in Splunk Search 07-21-2019
0 3
0
3
habisht
I'm trying to create a dashboard which will display pie-charts from different results. For this, I've multiple string...
by habisht Explorer in Splunk Search 07-21-2019
0 2
0
2
ewan000
I am attempting to make a trellis visualization off the sample data : * clientip=* | iplocation clientip | lookup ...
by ewan000 Path Finder in Splunk Search 07-20-2019
0 3
0
3
aking76
I have the following search, I'm trying to get it to show the src, dst, current amount of connections, and then an av...
by aking76 Path Finder in Splunk Search 07-20-2019
0 2
0
2
vikrantkumar199
I am trying to monitor a folder containing JSON files in it. But, I observed that files are not getting indexed. Whe...
by vikrantkumar199 New Member in Splunk Search 07-19-2019
0 1
0
1
jadengoho
Hi im having this issue : The times on the system clocks for the machines running this search head and the intended ...
by jadengoho Builder in Splunk Search 07-19-2019
0 3
0
3
fclsplunk
I have a fairly straightforward query using timechart to count the top 10 users triggering an event. ( Sanitized ) ...
by fclsplunk New Member in Splunk Search 07-19-2019
0 8
0
8
mpasha
Good day everyone, I am dealing with a challenge and really hope i can get an answer here. I am running a Join search...
by mpasha Path Finder in Splunk Search 07-19-2019
0 7
0
7
amaurya1
index=abc sourcetype=xyz | eval is_passed=if(label=="PASS", 1, 0) | eval is_failed=if(label=="FAIL", 1, 0) | stats...
by amaurya1 Explorer in Splunk Search 07-19-2019
0 3
0
3
yutaka1005
I recently saw the manual of eval, and I found the following description. To specify a field name with multiple word...
by yutaka1005 Builder in Splunk Search 07-19-2019
2 4
2
4
Sparky1
So i'm trying to extract and ip address from a multi-value field and my transforms stanza is something along these li...
by Sparky1 Explorer in Splunk Search 07-19-2019
0 5
0
5
Tamilraj28
Please help me in Finding the 3rd or nth largest value from a field... SALARY 10000 30000 20000 80000 60000 93000 5...
by Tamilraj28 Engager in Splunk Search 07-19-2019
0 3
0
3
jfraley
I have two searches, one that gives me a table: index="netapp_snapmirror_reports" source="/var/tmp/netapp_snapmirror...
by jfraley Path Finder in Splunk Search 07-19-2019
0 4
0
4
msaranya
I have a field as field1, and field2 which is an indexed event: Field1 1.A 2.B and another table I have as match1 ...
by msaranya Observer in Splunk Search 07-19-2019
0 5
0
5
dvanderlaan
Hi. Suppose my search generates the first 4 columns from the following table: field1 field2 field3 lookup resul...
by dvanderlaan New Member in Splunk Search 07-19-2019
0 6
0
6
adalbor
Does anyone know of a good way to pull one event of a specific eventcode/type when searching for multiple eventcodes?...
by adalbor Builder in Splunk Search 07-19-2019
0 3
0
3
splunkuseradmin
hi all I have events in json format need to extract number from this sip:+1234566@12.23.34.45 example: i need +1234...
by splunkuseradmin Path Finder in Splunk Search 07-19-2019
0 4
0
4
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...