Splunk Search

Splunk Search
Community Activity
akelbr
All, my query below just returns the values from the first sourcetype (first 3 lines in |stats). The fields from the ...
by akelbr Explorer in Splunk Search 02-04-2019
0 8
0
8
hredd
How would you create a new field for example, color, by extracting the text from the value to an existing field, for ...
by hredd New Member in Splunk Search 02-04-2019
0 6
0
6
dbashyam
Hi, is it possible to kill or disable long running searches automatically. For example whenever we hit performance is...
by dbashyam Explorer in Splunk Search 02-03-2019
0 6
0
6
samble
I have a list of IP's in a CSV that I need to exclude from the results of a query. Below is a my query. How can I app...
by samble Path Finder in Splunk Search 02-03-2019
0 2
0
2
sabaKhadivi
due to the splunk couldn't aggregate logs I want to use arcsight smart connector, I think I should use splunk app fo...
by sabaKhadivi Path Finder in Splunk Search 02-02-2019
0 1
0
1
bhupalbobbadi
I'm using a search-macro in alet(s), the search-macro is writing search (alert) results to file, I would like to crea...
by bhupalbobbadi Path Finder in Splunk Search 02-02-2019
1 1
1
1
sboogaar
Im trying to set a boolean based on a match in a string. I want to set a value to 1 if it does not match ingestion* a...
by sboogaar Path Finder in Splunk Search 02-02-2019
1 4
1
4
abdullawells89
How to use jquery confirms and alerts in Splunk
by abdullawells89 New Member in Splunk Search 02-02-2019
0 2
0
2
zhatsispgx
Hi there, I have a dataset that writes a logfile that has a field named host in it by default. Is there a way to ma...
by zhatsispgx Path Finder in Splunk Search 02-01-2019
0 2
0
2
skhprabu
I have my log like params=All Items | ABC | 2019-01-29 | | | | | | | = | | = | | | | | | ,uri=/api/items...
by skhprabu New Member in Splunk Search 02-01-2019
0 2
0
2
rotundwizard
I'm attempting to build a regex that will extract a field enclosed in double-quotes, after a string match. Basically ...
by rotundwizard Explorer in Splunk Search 02-01-2019
0 8
0
8
amirarsalan
Hi! I need help with a search to find scheduled reports that are running. I want to know what are exactly running ri...
by amirarsalan Explorer in Splunk Search 02-01-2019
0 4
0
4
vonsolo29
Im looking to find the total amount of data that was ingested for a particular index. We usually use out deployment s...
by vonsolo29 Explorer in Splunk Search 02-01-2019
0 4
0
4
marjonhtuazon
The scenario is this. I have a two field name name joe and bob. if bob help a job it indicate yes as its field value...
by marjonhtuazon Explorer in Splunk Search 02-01-2019
1 4
1
4
luckyman80
Hi Splunk Experts, I'm doing a calculation and adding to timechart like so eval ...
by luckyman80 Path Finder in Splunk Search 02-01-2019
0 3
0
3
ckeller2791
I have a powershell script which feeds data into Splunk via a UDP port. The output of the script is as follows: Abat...
by ckeller2791 Explorer in Splunk Search 02-01-2019
0 3
0
3
mandarpim
I have 2 tables contains random msisdn which can be repeated in one another as follows: Table1 | Table2 msisdn1 ...
by mandarpim New Member in Splunk Search 02-01-2019
0 5
0
5
sboogaar
I do not understand what is meant by concurrent historical searches. Can someone else explain what it means to me? ...
by sboogaar Path Finder in Splunk Search 02-01-2019
0 7
0
7
dtakacssplunk
How do I convert the output of a table from stats command that looks like this: TIME VALUE METRIC time1 ...
by dtakacssplunk Explorer in Splunk Search 02-01-2019
0 3
0
3
sajithpm101
I have created a few bar charts. In that few of the charts have 10 bars,5 bars, and 1 bar. All of these charts bars s...
by sajithpm101 New Member in Splunk Search 02-01-2019
0 1
0
1
rohanmiskin
I have logs having string like: 127.0.0.1|> GET /alldata 127.0.0.1|> GET /somedata 127.0.0.1|> GET /nodata 127.0.0.1...
by rohanmiskin Explorer in Splunk Search 02-01-2019
0 2
0
2
robertlynch2020
HI Every Saturday we do a full stop of Splunk and we do a full back up + restart. The issues is come Monday morning ...
by robertlynch2020 Influencer in Splunk Search 02-01-2019
0 6
0
6
ajayrejin
Hi, I need to check if the source address from the firewall logs is in private ip address range. How would i check u...
by ajayrejin Explorer in Splunk Search 02-01-2019
0 4
0
4
darioapis
(( host="vwp054" AND source="E:\\Apache\\apisit\\*")) | eval site = if(match(source,"E:\A.*"),1,0) | eval aba = if(...
by darioapis Explorer in Splunk Search 01-31-2019
0 1
0
1
danfinan
Hi all, My apologies if the title was a bit vague, wasn't sure how to word it! I have a search which identifes keyw...
by danfinan Explorer in Splunk Search 01-31-2019
0 1
0
1
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors