Splunk Search

Splunk Search
Community Activity
danielwan
my splunk server has high CPU usage and I saw a bunch of splunkd process like below search --id=admin_adminsearch_se...
by danielwan Explorer in Splunk Search 01-25-2019
1 3
1
3
navd
Hi , I am using the below query to get an average count . But how do I write a query to send an alert when the numbe...
by navd New Member in Splunk Search 01-25-2019
0 3
0
3
reed_kelly
It is becoming harder to submit cases, because our diag files have gotten very large. In the most recent case, the di...
by reed_kelly Contributor in Splunk Search 01-25-2019
2 4
2
4
sgoodman26
My company gets a log file that we are trying to compare a set of numbers to one another. These numbers have to be wi...
by sgoodman26 Explorer in Splunk Search 01-25-2019
0 4
0
4
joeldavideng
I recently upgraded a Windows heavy forwarder to 7.2.3 and I am now getting errors when it attempts to connect to an ...
by joeldavideng Path Finder in Splunk Search 01-25-2019
0 2
0
2
matansocher
Hi, I want to remove a number (up to 5 digits) from a string on its beginning. an example: 43.aaaa_vvvvv.cccccc:ddd...
by matansocher Contributor in Splunk Search 01-25-2019
0 3
0
3
arai0729
Splunk Enterprizeでログのサーチ結果をグラフ化しようとしています。 サーチした結果について、視覚エフェクトからグラフ化したところ、グラフの色が用意していた項目の色とずれてしまいました。 主導でグラフの色を変えられないか...
by arai0729 Explorer in Splunk Search 01-25-2019
0 1
0
1
MaryvonneMB
Hi everyone! I'm trying to use Timeline module but I have some trouble with the duration: Note: I'm working with a l...
by MaryvonneMB Path Finder in Splunk Search 01-25-2019
0 4
0
4
harishnpandey
Is there any way I can extract only PersistenceLo cache cleared! and PmFinUtilityL Cache Cleared (highlighted in BOLD...
by harishnpandey Explorer in Splunk Search 01-25-2019
0 5
0
5
wfjarrett538
I have a lookup table that is giving me strange search results that I can't figure out — I have a table which is a li...
by wfjarrett538 Explorer in Splunk Search 01-25-2019
0 6
0
6
john_dagostino
I have an issue on one of my two search head clusters where the column order is reversed when running timechart. For...
by john_dagostino Path Finder in Splunk Search 01-25-2019
0 9
0
9
bogdan_nicolesc
Hi all, What i try to ask is if that i can add to this: (index="bogdan") | rename Date AS RootObject.Date ...
by bogdan_nicolesc Communicator in Splunk Search 01-25-2019
0 11
0
11
vineethvnair0
Hi, I have a tomcat access log which contains urls like url=/find.do?from-id=549499&q-out=2019-02-20&q-room-0-adul...
by vineethvnair0 New Member in Splunk Search 01-25-2019
0 10
0
10
ernestpoon
Hi guys, I have an Apache log (with only few information) and I would like to find out the possible events related to...
by ernestpoon New Member in Splunk Search 01-25-2019
0 5
0
5
xzywind
Hi. i have a search which need to combine fields from two index. i know i can use "Join" but it is too costly thats ...
by xzywind New Member in Splunk Search 01-25-2019
0 0
0
0
khairilfirza
Hi team, I want to ask: I cannot do extract new field and its show this error. Error in 'rex' command: The regex 'Te...
by khairilfirza Explorer in Splunk Search 01-24-2019
1 14
1
14
iamlearner123
Hi, Can i please know about how to find out a old data available for a sourcetype. For example, if i have a sourcetyp...
by iamlearner123 Explorer in Splunk Search 01-24-2019
0 4
0
4
dbcase
Hi, I have this data {"method":"GET","url":"/rest/icontrol/logout","params":{},"requestStartTime":1548363789220,"re...
by dbcase Motivator in Splunk Search 01-24-2019
0 4
0
4
DavisLee
TIA. This has probably been asked and answered dozens of times but my brain is now mush. The following search gives ...
by DavisLee New Member in Splunk Search 01-24-2019
0 1
0
1
HattrickNZ
How do I round only certain columns/fields ? below this | foreach * [eval <<FIELD>>=round('<<FIELD>>',2)] will round ...
by HattrickNZ Motivator in Splunk Search 01-24-2019
0 1
0
1
kumagaur
I have one lookup in which there is a field which consist Team Member A1 A2 A3 A4 A5 A6 A7 Now,If TeamMember=(A1 ...
by kumagaur New Member in Splunk Search 01-24-2019
0 1
0
1
VexenCrabtree
I've got an average session duration (gotten via | Transaction) broken down by EndStatus. EndStatus is the cause of t...
by VexenCrabtree Path Finder in Splunk Search 01-24-2019
1 10
1
10
auaave
Hi guys! I have the below query for a Single Value Dashboard Panel. It is counting the daily total error duration of...
by auaave Communicator in Splunk Search 01-24-2019
0 5
0
5
vickyvishwa
I have the below log event. [INFO ] 2019-01-24T04:09:20,513 [thread=framework1234] className=DummyConsumer - {} - {...
by vickyvishwa Explorer in Splunk Search 01-24-2019
0 2
0
2
knutsod
Is there a way to set a Field Alias as search time, I am building a report looking at Windows Event IDs, In this case...
by knutsod Path Finder in Splunk Search 01-24-2019
2 3
2
3
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...