Splunk Search

Splunk Search
Community Activity
pkeller
Using: index=default sourcetype=my:sourcetype | extract pairdelim="][", kvdelim="=", auto=f Feb 19 09:44:02 fooba...
by pkeller Contributor in Splunk Search 02-19-2019
0 2
0
2
N92
For example, I have lookup xyz.csv with two fields, A and B. I want to search for the value of A field. If any matc...
by N92 Path Finder in Splunk Search 02-19-2019
0 7
0
7
atpsplunk11
Hello everyone! We have a log file contains the following information, status 0 means server is up, 1 means down: Da...
by atpsplunk11 Explorer in Splunk Search 02-19-2019
0 0
0
0
N92
How can we identify a particular search using lookup or lookup definition? in the case where a lookup file is enable...
by N92 Path Finder in Splunk Search 02-19-2019
0 3
0
3
noy72
Splunk Enterprise 7.1.3, SCCM Current Branch with univesal forwarder configured to forward event logs and WMI. I hav...
by noy72 New Member in Splunk Search 02-19-2019
0 3
0
3
jip31
hI I use the request below sometimes I have only value for Free_Space and sometimes only value for TotalSpace instea...
by jip31 Motivator in Splunk Search 02-19-2019
0 7
0
7
meet_vadaria
Hi, I am collecting all log file to a syslog server where I have a Splunk forwarder installed. To override source of...
by meet_vadaria Engager in Splunk Search 02-19-2019
0 2
0
2
kawashita_t
I would like to tag you at search time. I'd like to tag the result of the calculation when searching. ex ) LogID ...
by kawashita_t Explorer in Splunk Search 02-19-2019
0 2
0
2
paddygriffin
Example: I want a second-by-second stat for the past 24 hours. The following message shows: "These results may be tru...
by paddygriffin Path Finder in Splunk Search 02-19-2019
1 3
1
3
zacksoft
I have two values a) The time when a breach occurs. b) The amount of memory consumed during the memory breach. I w...
by zacksoft Contributor in Splunk Search 02-19-2019
0 3
0
3
twh1
I am running timechart command for sum of free space and used space with span of 1 day. I am missing data for few day...
by twh1 Communicator in Splunk Search 02-19-2019
0 7
0
7
pbsuju
I have a log with below as a source field from which I need to extract the field Gateway name (My_Gateway_NONPROD). ...
by pbsuju Explorer in Splunk Search 02-19-2019
0 3
0
3
skribble5
Hi everyone, I need some help figuring out how can I exclude certain users' data from my calculation of average of a...
by skribble5 Explorer in Splunk Search 02-19-2019
0 3
0
3
ryanhindley92
Hi, I am new to using Splunk and have been tasked with trying to find all inactive distribution lists within our en...
by ryanhindley92 New Member in Splunk Search 02-19-2019
0 0
0
0
ADRIANODL
Hi folks, This is a complex question, so bear with me. We have 2 heavy searches that return calculated and lookup va...
by ADRIANODL Explorer in Splunk Search 02-18-2019
0 1
0
1
jamesmarlowww
I'm trying to set a token with eval. However, my logic doesn't seem to be working. I haven't been able to find a work...
by jamesmarlowww Path Finder in Splunk Search 02-18-2019
2 12
2
12
ADRIANODL
Hi folks, I have 2 searches that return equivalent values based on the result of a lookup, as such: Search 1 index...
by ADRIANODL Explorer in Splunk Search 02-18-2019
0 3
0
3
johann2017
How would I write a search to look for failed logons coming from the same account happening across different systems?...
by johann2017 Explorer in Splunk Search 02-18-2019
0 4
0
4
bud9
Lookup file sla_jobs.csv: Business AppName RunDays BatchStartJob AvgBatchStartTime BatchEndJob SLA_time Same...
by bud9 New Member in Splunk Search 02-18-2019
0 3
0
3
jainkul123
I would like to join the result from 2 different indexes on a field named OrderId (see details below) and show field ...
by jainkul123 Explorer in Splunk Search 02-18-2019
0 15
0
15
rajneeshdba
NOT "/healthCheck" , what the point of using this n search ? I want to know is it searching for string health chec...
by rajneeshdba Explorer in Splunk Search 02-18-2019
0 2
0
2
johann2017
Hello! I am wanting to build a search that can help detect lateral movement. I want to see when the same user is logg...
by johann2017 Explorer in Splunk Search 02-18-2019
0 1
0
1
tb5821
I have a search that returns a list of namespace values. I want to take each one of those namespace values and run ...
by tb5821 Communicator in Splunk Search 02-18-2019
0 25
0
25
vrmandadi
I am running the below search index=main sourcetype="aws:description" state=* image.attributes.name!=emr* id=i-069ff...
by vrmandadi Builder in Splunk Search 02-18-2019
0 18
0
18
vrmandadi
I have the below query index=main AND sourcetype="abc" AND id=* AND ((state="terminated" AND image.attributes.name!...
by vrmandadi Builder in Splunk Search 02-18-2019
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...