Splunk Search

Splunk Search
Community Activity
jbezanson
I have a report that reports the count of events per another field. I can get a total of all of these events but it ...
by jbezanson Engager in Splunk Search 07-09-2019
1 5
1
5
runiyal
I need to create a report based on three different search criteria from three different sources. But since its a reco...
by runiyal Path Finder in Splunk Search 07-09-2019
0 2
0
2
runiyal
I need to create a report based on three different search criteria from three different sources. But since its a reco...
by runiyal Path Finder in Splunk Search 07-09-2019
0 1
0
1
cmille19
I'm trying to exclude known issues from a search by using a lookup of exclusions. Our Splunk admins lock down alert c...
by cmille19 Engager in Splunk Search 07-09-2019
0 3
0
3
amunag439
I'm calculating the time difference between two events by using Transaction and Duration. Below is the query that I u...
by amunag439 Explorer in Splunk Search 07-09-2019
0 5
0
5
johnansett
Hello, I am trying to extract the entire URL up to the point where it includes a question mark. Generally the data w...
by johnansett Communicator in Splunk Search 07-09-2019
0 2
0
2
jeburkes76
Trying to understand how this SEDCMD works so I can modify it for something else. It works in props.conf but I can't ...
by jeburkes76 Explorer in Splunk Search 07-09-2019
0 6
0
6
keldridg2
I downloaded the Splunk visualization app to create a custom visualization but when I click on starting on the base t...
by keldridg2 New Member in Splunk Search 07-09-2019
0 0
0
0
zawan
I am trying to optimize my splunk deployment by removing duplicate alerts. I have this search which shows me all of ...
by zawan Engager in Splunk Search 07-09-2019
0 1
0
1
keldridg2
I downloaded the Splunk visualization app to create a custom visualization but when I click on starting on the base t...
by keldridg2 New Member in Splunk Search 07-09-2019
0 0
0
0
smazzatenta
host="server" EventCode=4688 OR EventCode=469 | transaction New_Process_Name startswith=(EventCode=4688) endswith=(Ev...
by smazzatenta New Member in Splunk Search 07-09-2019
0 13
0
13
frbuser
How can I correlate Windows event 4688 logs to show a chain of processes that were that were started? Basically a pro...
by frbuser Path Finder in Splunk Search 07-09-2019
0 2
0
2
aschneider29
Hi - new user here. We have log files streaming to S3 for some of our data, but in other cases we have an ETL job doi...
by aschneider29 New Member in Splunk Search 07-09-2019
0 0
0
0
mmol
Another question on counting the number of events per values() value in stats command. Using sistats this is seems t...
by mmol Explorer in Splunk Search 07-09-2019
0 0
0
0
darioapis
I have a question about two searches. The first one is much more faster than the second one, but I think that they do...
by darioapis Explorer in Splunk Search 07-09-2019
0 6
0
6
telecomdesign
Hello I did a code using append it was working perfectly. I didn't use my code for a week and now it is not working...
by telecomdesign New Member in Splunk Search 07-09-2019
0 2
0
2
jmoral03
I've created a chart using the search: base search | chart values(y) over x It charts perfectly except for the fact ...
by jmoral03 New Member in Splunk Search 07-09-2019
0 3
0
3
aayushisplunk1
Hello, I am facing issues joining the two table A & B given below: Table A: A | email@xxx 1 | abcd@xxxx 2 | efgh...
by aayushisplunk1 Path Finder in Splunk Search 07-09-2019
0 12
0
12
bandit
# have a summary index which stores load averages index=summary10min | table 10_min_load_avg 1 0.140000 2 0.7200...
by bandit Motivator in Splunk Search 07-09-2019
2 4
2
4
mklhs
Hello, i wanted to write a search which will return all hosts which have not sent any events for 10 minutes in the l...
by mklhs Path Finder in Splunk Search 07-09-2019
0 4
0
4
rmuraly
I am running a query to alert me if the sum of a particular property < 400000. I get alert most times saying the cou...
by rmuraly Explorer in Splunk Search 07-09-2019
0 1
0
1
swimena
Hello everyone, I'm trying to calculate the % of overdue items and print the result for every month. It looks like ...
by swimena Explorer in Splunk Search 07-09-2019
0 8
0
8
twh1
I am trying to create a time series chart but not getting any data in visualization tab. index="test_data" sourcetyp...
by twh1 Communicator in Splunk Search 07-08-2019
0 10
0
10
brdr
Hello, I've been using this command on other metric indexes and i can't get this one to work. index=iiot_index Ta...
by brdr Contributor in Splunk Search 07-08-2019
0 1
0
1
jspigler2010
I'm looking to dynamically extract both the field name and the associated value from a data source. Essentially, the...
by jspigler2010 Explorer in Splunk Search 07-08-2019
0 2
0
2
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors