| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hi, i want to find out the total run time of both ad-hoc and saved searches. I checked in _audit index to find out th...
        
         
           by 
           
                
                    
                        manjuase
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-26-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am having data as shown in the below image, 
  
    
  Is there a way i can get the avg of output considering the d...
        
         
           by 
           
                
                    
                        aseadmin
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-14-2019
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi ,  i have produced output below using predict command .  
  _time Prediction(hostA) Prediction(HostB) Prediction(H...
        
         
           by 
           
                
                    
                        jienlim2
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-26-2019
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi I'm trying to match a table list of tasks for a client with a task run result. The table task shows if the task is...
        
         
           by 
           
                
                    
                        falkienltd
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-26-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I want to |search sourcetype=syslog | eval DATA=[search tratata | eval ip=somedata | return $ip] | search DATA Exampl...
        
         
           by 
           
                
                    
                        borisk95
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-25-2019
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi, I have this string in the log. 
  439 XObk5g6CUI62-gr3UIKfXAAAAAs 1@43465473@A 
  and I want to create a field ou...
        
         
           by 
           
                
                    
                        iamtrying
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi, I have a list of Tenants and the data is being pulled from Jira labels. 
  Some of the labels have not been spell...
        
         
           by 
           
                
                    
                        sumaitasiddiky1
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-25-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have windows logs in below format, and not able to extract single field for merged text value. I want to create a f...
        
         
           by 
           
                
                    
                        utk123
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-31-2018
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        This is the string in the log 
  I 2019-05-23 18:22:38.984Z 7881 216 XObk7A6CU-I62gr3UIKfXQAAAAs 1@43465473@A WPB-Log...
        
         
           by 
           
                
                    
                        iamtrying
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-24-2019
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        So I'm trying to build a transaction based on events I am getting from a log. I'm struggling how to set the transacti...
        
         
           by 
           
                
                    
                        joesrepsolc
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-24-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        i need that all lines will be one line, without newline
        
         
           by 
           
                
                    
                        alina_mandarina
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-24-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello Splunkers,  
  I am relatively new with Splunk and was wondering if someone out there can please tell me which ...
        
         
           by 
           
                
                    
                        cosmo360
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-24-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello, 
  I want to write a detection for watching abuse of a service being used. How to do i start writing the logic...
        
         
           by 
           
                
                    
                        lakshmikolli201
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-17-2019
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi, 
  I try to make a column chart using this search: 
  index=webtrafic 
| rename ProcessName AS RootObject.Process...
        
         
           by 
           
                
                    
                        bogdan_nicolesc
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        By using Splunk SDK, able to use the below search string and get the results from SPlunk String searchQuery_string = ...
        
         
           by 
           
                
                    
                        duddukuri
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-24-2019
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        hello splunker.  
  i changed search to datamodel search(tstats) for speed up. 
  but, stats and tstats result are sl...
        
         
           by 
           
                
                    
                        YUNHYEONG
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hello all, Please help me with some regular expression. This is the text: {"Value": "arn:aws:cloudformation:us-west-2...
        
         
           by 
           
                
                    
                        braicu
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-22-2019
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello, 
  I`m trying to find a solution for this problem. The result of the following SPL query should show every day...
        
         
           by 
           
                
                    
                        Silmarillion197
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-17-2019
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Based on the statistical data we have to generate, we normally have to type out many functions like so: 
  search str...
        
         
           by 
           
                
                    
                        kamryn
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        WinNetMon maps protocol #58 to "SIP", but according to IANA, #58 is "IPv6-ICMP"? 
  Seems fine for others: 17=UDP,6=T...
        
         
           by 
           
                
                    
                        templets
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi, 
  Is there a way to display all fields being used by a sourcetype, without the values?
        
         
           by 
           
                
                    
                        a212830
                    
                
           
             
             
               Champion
             
           
           in
           Splunk Search
           
           
              
               04-03-2013
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        For example, given the fields and values: 
  field1=A123
field2=baba
field3=A123B
field4=bA123
 
  I want a list with...
        
         
           by 
           
                
                    
                        msolgonza
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I'm new to Splunk, and I am trying to figure out how the eval command works in searches.  Sometimes I don't get any r...
        
         
           by 
           
                
                    
                        fabriziorti
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-21-2019
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi all,  I'm stuck with this i hope somebody can helps me. 
  I have a csv lookup with following data for search matc...
        
         
           by 
           
                
                    
                        cpm003
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2019
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have data that looks like this: 
  event,myField,myHost,myCategory
yes,a,host1,category1
yes,b,host1,category1
yes,...
        
         
           by 
           
                
                    
                        dsong555
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-22-2019
             
           
         
        | 
		
		0
   | 
	  
	  4
	 |