Splunk Search

Splunk Search
Community Activity
spamphile
I'm trying to display a pie chart like so: chart count by transaction.inputSource | lookup transaction_input_sources...
by spamphile Engager in Splunk Search 06-05-2019
0 2
0
2
kkovanis
0400 ERROR DispatchProcess - String not found in literals.conf: DISPATCHCOMM:FAILED_TO_START_PROCESS I need help fi...
by kkovanis New Member in Splunk Search 06-05-2019
0 2
0
2
perlish
Hi all, I want to print results excluding the last line. In Linux, I can use head -n -1 but in Splunk, the head comm...
by perlish Communicator in Splunk Search 06-05-2019
1 7
1
7
jip31
hello I need to do a line breaking after "%" and after " on a total of " | eval Perc=round((NbTOUCHNGOCrashByHost/...
by jip31 Motivator in Splunk Search 06-05-2019
0 15
0
15
benjaminlin1019
I use one of the S.O.S. queries to get top 20 memory usage queries every 5 minutes, however, it might be easier for u...
by benjaminlin1019 Explorer in Splunk Search 06-05-2019
2 4
2
4
Shashank_87
Hi, I am trying to plot the Crash rate over _time on a graph and that has to be distributed by app_name. On a high l...
by Shashank_87 Explorer in Splunk Search 06-05-2019
0 2
0
2
kvanwagoner
I've got 2 search queries that are working for me (Thanks to @harshpatel) Query #1 returns the average # of successe...
by kvanwagoner New Member in Splunk Search 06-05-2019
0 5
0
5
vatsalyay
I am writing a code to simply match a regex in my search to match index field which matches app1_, app2_, etc Howeve...
by vatsalyay New Member in Splunk Search 06-05-2019
0 2
0
2
pfabrizi
We have a identities_expanded.csv file in our SA_IdentityManagement app under lookups. It contains our AD data but I ...
by pfabrizi Path Finder in Splunk Search 06-05-2019
0 1
0
1
jip31
hello I use the search below in order to calculate a last logon date and a last reboot date by host now I need to add...
by jip31 Motivator in Splunk Search 06-05-2019
0 7
0
7
progress101
I'm in the process of creating a troubleshooting guide for our networking team. I would like to be able to look up ev...
by progress101 New Member in Splunk Search 06-04-2019
0 2
0
2
TCK101
I have my derived tables | stats count by breached region | xyseries region breached count REGION NO YES U...
by TCK101 New Member in Splunk Search 06-04-2019
0 3
0
3
rashi83
So I created a dropdown input panel for weekwise but my search is not changing as per dropdown selection - ... we...
by rashi83 Path Finder in Splunk Search 06-04-2019
1 5
1
5
Jason
I'm working with some HTTP access logs that have a status code in them. Most are successful messages, naturally. I wo...
by Jason Motivator in Splunk Search 06-04-2019
5 5
5
5
reverse
q1- how can i get c4 where c4 will always be difference of values in c3 against first of c2 - next of c2 for example ...
by reverse Contributor in Splunk Search 06-04-2019
0 2
0
2
reverse
Q1: How can I get c4 where c4 will always be the difference of values in c3 against max of c2 - min of c2 For exampl...
by reverse Contributor in Splunk Search 06-04-2019
0 15
0
15
hduncan7
I'm trying to get percentages based on the number of logs per table. I want the results to look like this: Table ...
by hduncan7 Engager in Splunk Search 06-04-2019
0 3
0
3
acdevlin
Hi all, I know that the "dedup" command returns the most recent values in time. However, I'm currently in a situatio...
by acdevlin Communicator in Splunk Search 06-04-2019
0 7
0
7
mikefoti
My ultimate goal is to grab the srcIP and time from an event in one index, then search another index for the same src...
by mikefoti Communicator in Splunk Search 06-04-2019
0 2
0
2
willemjongeneel
Hello, I have a question on using lookups in a search. I want to achieve that I have a scheduled search to compare t...
by willemjongeneel Communicator in Splunk Search 06-04-2019
0 5
0
5
kvanwagoner
I'm using the following search which I have working in a dashboard. "A PUT was made to OpenAAA API - Status: OK" | ...
by kvanwagoner New Member in Splunk Search 06-04-2019
0 19
0
19
damucka
Hello, I have the following search: index=_internal sourcetype=scheduler savedsearch_name="Anomaly Detection - new-...
by damucka Builder in Splunk Search 06-04-2019
0 8
0
8
atulitm
Hi , I need help with following Log : 5th May device="devicename" policy="XYZ" BW_Limit="any number" Total_BW="any ...
by atulitm Path Finder in Splunk Search 06-04-2019
0 5
0
5
mveca
I want to exclude both primary and secondary IP addresses from a search. For example: src_ip!=192.50.244.10 AND src...
by mveca New Member in Splunk Search 06-04-2019
0 4
0
4
denzelchung
I have the following query to be performed, where "STRING" is replaced across different queries. Is there a way to re...
by denzelchung Path Finder in Splunk Search 06-04-2019
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...