Splunk Search

Splunk Search
Community Activity
bandit
# have a summary index which stores load averages index=summary10min | table 10_min_load_avg 1 0.140000 2 0.7200...
by bandit Motivator in Splunk Search 07-09-2019
2 4
2
4
mklhs
Hello, i wanted to write a search which will return all hosts which have not sent any events for 10 minutes in the l...
by mklhs Path Finder in Splunk Search 07-09-2019
0 4
0
4
rmuraly
I am running a query to alert me if the sum of a particular property < 400000. I get alert most times saying the cou...
by rmuraly Explorer in Splunk Search 07-09-2019
0 1
0
1
swimena
Hello everyone, I'm trying to calculate the % of overdue items and print the result for every month. It looks like ...
by swimena Explorer in Splunk Search 07-09-2019
0 8
0
8
twh1
I am trying to create a time series chart but not getting any data in visualization tab. index="test_data" sourcetyp...
by twh1 Communicator in Splunk Search 07-08-2019
0 10
0
10
brdr
Hello, I've been using this command on other metric indexes and i can't get this one to work. index=iiot_index Ta...
by brdr Contributor in Splunk Search 07-08-2019
0 1
0
1
jspigler2010
I'm looking to dynamically extract both the field name and the associated value from a data source. Essentially, the...
by jspigler2010 Explorer in Splunk Search 07-08-2019
0 2
0
2
keronedave
I have three columns from a search query. I would like to count the items in one column and display it next to the ot...
by keronedave Explorer in Splunk Search 07-08-2019
0 7
0
7
alucarddjin
I have a lookup list of users and I want to get that date off their last event (or empty if no event) but I keep gett...
by alucarddjin Path Finder in Splunk Search 07-08-2019
0 3
0
3
jip31
hello The max function in this search doesnt works. Idem with latest! Its not the latest or max event taked into acc...
by jip31 Motivator in Splunk Search 07-08-2019
0 9
0
9
almanacht
Hi, I have a menu with some option how I can chose with the box menu option, my question is quite simple because I ha...
by almanacht Explorer in Splunk Search 07-08-2019
0 0
0
0
genesiusj
Hello, I’m having issues with a report not displaying correctly. If I save a bar chart as a normal report, the Y-axi...
by genesiusj Builder in Splunk Search 07-08-2019
0 3
0
3
afx
I have a totally weird case... I have field extractions defined in props.conf either individually or all in one extra...
by afx Contributor in Splunk Search 07-08-2019
0 43
0
43
jip31
hi I use the search below "LAST_SEEN" is a field with a date format like "2019-06-07 09:12:40.0" I need to add an ev...
by jip31 Motivator in Splunk Search 07-08-2019
0 9
0
9
vishaltaneja070
Hello, I need to check the regex condition only on first 300 characters, if the regex condition available after tha...
by vishaltaneja070 Motivator in Splunk Search 07-08-2019
0 15
0
15
SathyaNarayanan
Hi Splunkers, i installed Splunk Maps+ apps 3.0.2 version, after installing i uploaded the KMZ file in it. After u...
by SathyaNarayanan Path Finder in Splunk Search 07-08-2019
0 0
0
0
ketaka
I want to use dashboard text input in custom search command. Please tell me some tips such as how to use and sentence...
by ketaka Explorer in Splunk Search 07-07-2019
0 2
0
2
qazwsxe
I want to get hundreds of millions of data from billions of data, but it takes more than an hour each time.I just use...
by qazwsxe New Member in Splunk Search 07-07-2019
0 56
0
56
mkhedr
how to remove other values from this search syntax index=main sourcetype=access_combined_wcookie productId | chart c...
by mkhedr Explorer in Splunk Search 07-07-2019
0 1
0
1
denymw
Hi, I am trying to get a visualization to show the average sentiment of a search term by the index. index=* foo | ta...
by denymw Explorer in Splunk Search 07-07-2019
0 2
0
2
sanjeev543
Hi There, I have scheduled a report to run and generate the CSV file and sent it over email, it had been working till...
by sanjeev543 Communicator in Splunk Search 07-07-2019
0 2
0
2
massumtaqi
if an action 1 triggers one event of common field=A and action 2 triggers ten events of common field= A, B or C. How...
by massumtaqi New Member in Splunk Search 07-06-2019
0 5
0
5
aakines
Suppose I performed the following subsearch index=whatever "name=" [|inputlookup lookup_file.csv | return 100 $look...
by aakines Engager in Splunk Search 07-05-2019
0 3
0
3
TylerJVitale
I want to set up an alert to trigger if three conditions are met: Volume of a particular app is above 100 over the l...
by TylerJVitale Explorer in Splunk Search 07-05-2019
0 3
0
3
NirajAlly
ok, let me try my best to explain my question here. I have Json format logs and now I need them to compare based on...
by NirajAlly New Member in Splunk Search 07-05-2019
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...