Splunk Search

Splunk Search
Community Activity
karn
I would like to improve search performance by preload data into csv or kv-store with sparkline. How do I display spar...
by karn Path Finder in Splunk Search 03-16-2019
0 1
0
1
splunkuseradmin
Hello everyone, I have different device models in A1 and B1 where "A1" is calling device model and B1 is receiving d...
by splunkuseradmin Path Finder in Splunk Search 03-16-2019
0 2
0
2
evelandi
Hi experts, im trying to definde a variable in my search to use is in other search. it should work as a filter in the...
by evelandi New Member in Splunk Search 03-16-2019
0 1
0
1
vpurushottam
Hi guys, I have query regarding how i can break my search for one month into weekly searches. I have been given an ...
by vpurushottam Explorer in Splunk Search 03-16-2019
0 5
0
5
Prasenjit1508
I have a query which returns 100 ids(ids are dynamic). I have to search for these 100 ids in another log and see if t...
by Prasenjit1508 New Member in Splunk Search 03-15-2019
0 1
0
1
jspears
I have a user whose monthly report search is being auto-finalized due to disk usage. I've ensured there are no other ...
by jspears Communicator in Splunk Search 03-15-2019
0 2
0
2
veerendra_modi
I want to pick up values from different lookup files according to the sourcetype. | lookup error_rules.csv EventSubTy...
by veerendra_modi Loves-to-Learn in Splunk Search 03-15-2019
0 3
0
3
bstreber
I have come across an issue with my timecharts. When I do a search for all day on Feb 26th and check 9AM, I see 127...
by bstreber Path Finder in Splunk Search 03-15-2019
0 15
0
15
rajhemant26
Hello everyone. Want to display the output only for the time which crosses 18 months (earliest time)
by rajhemant26 New Member in Splunk Search 03-15-2019
0 2
0
2
Log_wrangler
Hi, I have a query that searches a field i.e. filenames with a value in this format >> filename = folder_name/sub_f...
by Log_wrangler Builder in Splunk Search 03-15-2019
0 1
0
1
mtupper
Below is the search string I am using. Everything works like perfect except for the description field. The field rema...
by mtupper New Member in Splunk Search 03-15-2019
0 1
0
1
MaryvonneMB
Hi all, I have a performance question about "join" and "subsearch". Even join is a ressource-guzzler command I saw t...
by MaryvonneMB Path Finder in Splunk Search 03-15-2019
0 1
0
1
hypePG
Hey, I got a dashboard with different panels. They are all controlled by a single timepicker. Usually the timeranges...
by hypePG Path Finder in Splunk Search 03-15-2019
0 5
0
5
brpsingara
Hi, Splunk Enterprise. I am trying to get the list of all user accounts using below code, but the result showing o...
by brpsingara Explorer in Splunk Search 03-15-2019
0 21
0
21
mumblingsages
Title pretty much says it all. Every time I go to run a time chart with a span of 1 week it runs from Thursday to Thu...
by mumblingsages Path Finder in Splunk Search 03-15-2019
0 5
0
5
Shashank_87
Hi, I have a scenario where I need to check if a customer has placed an order when he has been offered an offer. So...
by Shashank_87 Explorer in Splunk Search 03-15-2019
0 1
0
1
dahlberg
I'm trying to do a field extraction for an Avaya call log. With this particular log event, every character, includin...
by dahlberg New Member in Splunk Search 03-15-2019
0 5
0
5
schose
Hi forum, I'm trying to implement a custom reporting command. Here is the smallest implementation which does nothing...
by schose Builder in Splunk Search 03-15-2019
0 2
0
2
pench2k19
Hi team, I have the following as a single event in splunk. )V 2019-03-11 msp raw utility_extract13L hdfs:/datalake...
by pench2k19 Explorer in Splunk Search 03-15-2019
0 5
0
5
hoytn
Can I define a custom key field in a kvstore? I've created the kvstore with following configuration: _key, targetUse...
by hoytn Explorer in Splunk Search 03-15-2019
1 1
1
1
alc2019
Hi, I'm doing a device count based on device latest time event registration. I'm getting the correct device registr...
by alc2019 New Member in Splunk Search 03-14-2019
0 4
0
4
paullt12345
Hi all I want to extract Hostname, date and time from the log, Kindly help sample log: Mar 12 09:13:46 hostname1 <...
by paullt12345 Explorer in Splunk Search 03-14-2019
0 2
0
2
mmdacutanan
I have got 3 queries that I need to join together. First query has a subsearch. I used a subsearch because I need to...
by mmdacutanan Explorer in Splunk Search 03-14-2019
0 3
0
3
ejmin
I know this is a silly question but for some cases I need to know where the unmatched events go because my regex is t...
by ejmin Path Finder in Splunk Search 03-14-2019
0 20
0
20
anthonycopus
Hi, I need help deduplicating in a search where only half the data contains an id. Basically, the old data has a fie...
by anthonycopus Path Finder in Splunk Search 03-14-2019
2 4
2
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...