Splunk Search

Splunk Search
Community Activity
melvincorneliss
Hi I'm trying to do a count within my JSON logs. It's about the following data. I want to do a count for the extensio...
by melvincorneliss New Member in Splunk Search 02-20-2019
0 2
0
2
almar_cabato
Hi, I'm new to regex field extraction. I need a regex to capture only specific characters on my event source. I tr...
by almar_cabato New Member in Splunk Search 02-20-2019
0 6
0
6
henriq_c
I'm doing a chart where i want to predict the disk space for the month after and I have this : .... predict C as "Pr...
by henriq_c Explorer in Splunk Search 02-20-2019
0 1
0
1
sendilprakash
I need to present the output of a query in a stacked bar diagram. Here is my search output: Now, I want to presen...
by sendilprakash Explorer in Splunk Search 02-20-2019
1 2
1
2
cweiliou_splunk
I have some source files which the messages have only time information without date information as below. [ xxxxx2017...
by cweiliou_splunk Splunk Employee Splunk Employee in Splunk Search 02-20-2019
0 1
0
1
vb1612
I have a string as ABCD_20190219_XYZ I need to get 20190219 like 8 characters after first "_" and than convert that ...
by vb1612 New Member in Splunk Search 02-20-2019
0 1
0
1
manig007
Hello, I need to know how to send historical data from Splunk to QRadar (Version 731) I am aware that there are some...
by manig007 Engager in Splunk Search 02-20-2019
2 0
2
0
Rob2520
Seeing tons of these errors in splunkd logs of indexers. What could be the reason? We are also experiencing search pe...
by Rob2520 Communicator in Splunk Search 02-20-2019
0 3
0
3
juhisaxena28
We have logs being parsed in Splunk which have differences in _indextime and _time of an hour. Please advise how can ...
by juhisaxena28 Explorer in Splunk Search 02-20-2019
0 1
0
1
nls7010
I have a client that wants to set up a "near" real time search in Splunk. Can this be done (it needs to be continuou...
by nls7010 Path Finder in Splunk Search 02-20-2019
0 4
0
4
ashokpuvvada
I ran a query which gave results in the below manner I just want the last two columns, that is Today and Tomorrow...
by ashokpuvvada New Member in Splunk Search 02-20-2019
0 1
0
1
vinitchaudhari1
Hi I have a cloud instance version 7.0.2.1 https://prd-p-df4vmzb62ds7.cloud.splunk.com. I am trying to use REST API t...
by vinitchaudhari1 New Member in Splunk Search 02-20-2019
0 3
0
3
russell120
With my situation, all events have double the values in each field for some reason. I'm not an admin so I just have t...
by russell120 Communicator in Splunk Search 02-20-2019
0 3
0
3
althomas
Hi all, Previously I've used "search_now" to determine the start time of a late-running scheduled search. This appea...
by althomas Communicator in Splunk Search 02-20-2019
0 0
0
0
znaesh
Please advise! We noticed that in our 7.0.2 on-prem Splunk install on CentOS, CPU load metrics are partially missing....
by znaesh Path Finder in Splunk Search 02-20-2019
1 0
1
0
JuGuSm
Hi, I collect json data like this: {"timestamp":"2019.02.19-10:20:30","label":"xxx","size":"100"} {"timestamp":"201...
by JuGuSm Path Finder in Splunk Search 02-20-2019
0 6
0
6
splunked38
Hi, I've got a large list which is grouped in chronological order and I'd like to ingest it into Splunk. The list s...
by splunked38 Communicator in Splunk Search 02-20-2019
0 8
0
8
mikeydee77
I would like to combine the results of two searches to use as a dashboard base search and then filter in different wa...
by mikeydee77 Path Finder in Splunk Search 02-20-2019
0 4
0
4
mtanadsk
Hi, I am having some difficulty in locating information to help me to create a scatter plot (over time) of a data se...
by mtanadsk Explorer in Splunk Search 02-20-2019
4 9
4
9
ramesh12345
Hi, Please find the below query index="os" sourcetype="Service" CaseNumber=* status="Complete" assignment_group=*...
by ramesh12345 Explorer in Splunk Search 02-20-2019
0 12
0
12
swimena
Hi there, I hope for some help with a query. I'm using the following query to get a list of all failed login atte...
by swimena Explorer in Splunk Search 02-19-2019
0 3
0
3
woodcock
I just discovered that indexed fields with periods in them are not tstatsable in my 7.2.1 environment. Is this a kno...
by Esteemed Legend in Splunk Search 02-19-2019
0 3
0
3
mic1024
Is there a way to pass current date into outputlookup file name? For instance I created and append my lookup file wi...
by mic1024 Path Finder in Splunk Search 02-19-2019
2 4
2
4
abbass1
I am currently emailing a report to end-users. Is there a way to drop the cvs file into a given Unix folder on a diff...
by abbass1 New Member in Splunk Search 02-19-2019
0 0
0
0
weidertc
I have a map command whose input contains multiple rows. The input is responsible for collecting the names of macros...
by weidertc Contributor in Splunk Search 02-19-2019
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...