Splunk Search

Splunk Search
Community Activity
a_naoum
Hello, I'm trying to use calculated field on data with url field. Simple doesn't work. Even a very simple 'upper(url...
by a_naoum Path Finder in Splunk Search 06-12-2019
0 10
0
10
jkumarr2
I am trying to filter out all URLs which are for file downloads and those URLs will end with the file extension. Eg -...
by jkumarr2 New Member in Splunk Search 06-12-2019
0 1
0
1
davidch12
I always understood the search command's expressions be connected by a logical AND by default: search customer=123 it...
by davidch12 Explorer in Splunk Search 06-12-2019
0 1
0
1
sarit_s
Hello in my organisation we have few kinds of log format one of them does not have the year in the time stamp so the ...
by sarit_s Communicator in Splunk Search 06-12-2019
0 6
0
6
anasamer
Can anyone here help with breaking this sample into multiple events each should start with { "resourceId": ? I have t...
by anasamer New Member in Splunk Search 06-12-2019
0 9
0
9
jip31
hi I use the search below and I filter the data with 2 token | inputlookup tablet_host.csv | lookup PanaBatterySta...
by jip31 Motivator in Splunk Search 06-12-2019
0 19
0
19
jip31
Hello I use the stats command below but some process_name have no process_cpu_used_percent value So how to do for di...
by jip31 Motivator in Splunk Search 06-12-2019
0 11
0
11
rchittip
Dears, My Splunk Indexer is in CDT time zone and my forwarder logs are in UTC time zone and there is time differenc...
by rchittip Path Finder in Splunk Search 06-12-2019
0 9
0
9
tomgc
Hello everyone, I am trying to combine the following: - The query 1 looks for recent events (earliest=-10m@m latest...
by tomgc Engager in Splunk Search 06-12-2019
0 0
0
0
AshimaE
I have to extract the same features from two sets of logs with very different formats and need to take the additional...
by AshimaE Explorer in Splunk Search 06-12-2019
0 5
0
5
kavyadekkata
Hi I currently have a search which returns a list of users with employee id from a user lookup eg: user lookup has ...
by kavyadekkata Explorer in Splunk Search 06-11-2019
0 1
0
1
dowdag
I have a log file that has the timestamp for each line as: Jun 10, 11:07:59.305475 Note that the year is missing -...
by dowdag Engager in Splunk Search 06-11-2019
0 6
0
6
lsanthoshbe
In my Application there are logs statements which are repetitive and how to avoid them sending to Indexer so that i w...
by lsanthoshbe New Member in Splunk Search 06-11-2019
0 1
0
1
ankurtaunk
I want to write a search where the events are in one column and the related counts are in each column corresponding t...
by ankurtaunk Explorer in Splunk Search 06-11-2019
0 9
0
9
viking1978
I am doing weekly statistics and in splunk 7, i can easily specify the first day of a week by @w1 so 1 means Monday. ...
by viking1978 New Member in Splunk Search 06-11-2019
0 1
0
1
dirtyspawn
I am kind of new so I apologize to my ignorance. What I am trying to do is use the Windows Event Logs EventCode 5156 ...
by dirtyspawn Engager in Splunk Search 06-11-2019
0 6
0
6
jenkinsta
I have a search that gets the count of events by users which works well. However, I want to have the chart list all u...
by jenkinsta Path Finder in Splunk Search 06-11-2019
0 5
0
5
eholz1
Hello all, I have a working universal forwarder that happily sends data to my Enterprise indexer. The data shows up u...
by eholz1 Builder in Splunk Search 06-11-2019
0 5
0
5
user93
Hello, I need a search to match when a field that has free form text contains exactly 8 characters that are letters ...
by user93 Communicator in Splunk Search 06-11-2019
0 3
0
3
barriersbill
hi, what are your thoughts on data virtualization and how does it apply to Splunk? I ave been researching data virtua...
by barriersbill Explorer in Splunk Search 06-11-2019
1 2
1
2
jsalsbur
Good afternoon I have a stats count query leading to a single number dashboard. I was wondering if it is possible to ...
by jsalsbur Explorer in Splunk Search 06-11-2019
0 3
0
3
veerappan
I am beginner to Splunk and could you please help me with the following scenario. I have a search that will display a...
by veerappan New Member in Splunk Search 06-11-2019
0 2
0
2
sarit_s
Hello i have several reports that contains the search index=something__something in my case, '' is the name of the re...
by sarit_s Communicator in Splunk Search 06-11-2019
0 9
0
9
aleksandar_mati
Hi, I need help with transaction command results. I have the following input to transaction command: eventID,"_time...
by aleksandar_mati New Member in Splunk Search 06-11-2019
0 4
0
4
jip31
Hello I use 2 tokens in the XML below, I need to use comparison sign like > and < in this token. I would like also t...
by jip31 Motivator in Splunk Search 06-11-2019
0 10
0
10
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...