Splunk Search

Splunk Search
Community Activity
deepak007
I have 2 types of account for the same user's like 1. username 2. adm-username As a requirement, I need to find the ...
by deepak007 Explorer in Splunk Search 01-01-2019
0 6
0
6
keiran_harris
Hi guys, i need help with a search. I believe it's a subsearch that i need (I need a variable output of one search ...
by keiran_harris Path Finder in Splunk Search 01-01-2019
0 5
0
5
gokikrishnan
BaseSearch>|convert auto(A)|appendcols[|convert auto(B)]|eval C=A-B|table A B C This gives the result as A B ...
by gokikrishnan New Member in Splunk Search 01-01-2019
0 7
0
7
tzitello_splunk
When I run the following search, the field does not convert to a number: search| convert num(Samples.Sample.Depth) as...
by tzitello_splunk Splunk Employee Splunk Employee in Splunk Search 01-01-2019
0 2
0
2
ramanir
This is the search: index=vha_pronto sourcetype=pronto_neopil_prd NOT [ search index=vha_pronto sourcetype=pronto_ne...
by ramanir New Member in Splunk Search 01-01-2019
0 6
0
6
venanciop
Convert does not work search | convert num(quantity) as Quantity The quantity field samples are: 1.0000 ...
by venanciop New Member in Splunk Search 12-31-2018
0 3
0
3
dojiepreji
Is there any way to get the upper and lower bound dates for a timechart that has a span of weeks? | timechart span=...
by dojiepreji Path Finder in Splunk Search 12-31-2018
0 5
0
5
jip31
hello, In the log below, I want to extract the field TIMECREATED SYSTEMTIME https://cjoint.com/c/HLDpeThG7Qd Could...
by jip31 Motivator in Splunk Search 12-31-2018
0 1
0
1
aamer86
I have a WAF log source where logs are written to CEF files. I need a search that calculates the minimum time per lo...
by aamer86 Path Finder in Splunk Search 12-31-2018
0 4
0
4
gmasca
Hi, I am making a query where it get some raw syslog data and format into columns with some filters. When I search ...
by gmasca Explorer in Splunk Search 12-31-2018
0 4
0
4
lmjoin
How to send data 514 port to splunk. I have configured TCP udp 514 port and also install cisco app on splunk. I need ...
by lmjoin Explorer in Splunk Search 12-30-2018
1 0
1
0
skribble5
Hi all, I would like to show my data via 2 different histograms, but I am having trouble figuring it out. Can someon...
by skribble5 Explorer in Splunk Search 12-28-2018
0 5
0
5
rharrisssi
I've seen quite a few posts about IronPort/Cisco ESA mail logs and how folks have put them together with transaction....
by rharrisssi Path Finder in Splunk Search 12-28-2018
0 2
0
2
crazyeva
Hi Guys I am trying to delete some Fields configured by someone else, but I can't find where they are. First of all,...
by crazyeva Contributor in Splunk Search 12-28-2018
0 4
0
4
appleman
Hello, I want to calculate the time difference between two fields, so I tried the below query, but it didn't work. P...
by appleman Contributor in Splunk Search 12-28-2018
0 6
0
6
muzicman61
I have a search that works perfectly. It lists the number of calls by area code by state. However, I'm trying to lim...
by muzicman61 New Member in Splunk Search 12-28-2018
0 2
0
2
ppiton
Hello, I can't find out how to do a search to compare the same value in 2 fields, and if this is same value, add a t...
by ppiton New Member in Splunk Search 12-28-2018
0 3
0
3
khusain_splunk
I am not able to view my license usage report for Today and Previous 30 days. I am getting below WARNINGS under Messa...
by khusain_splunk Splunk Employee Splunk Employee in Splunk Search 12-28-2018
0 1
0
1
Arpit_S
Hi, I am trying to create a lookup that has the names of all the indexes and the timestamp of the oldest event in th...
by Arpit_S Path Finder in Splunk Search 12-28-2018
0 5
0
5
brajaram
I have a lookup table filled with thousands of user IDs. I have a log filled with tens of thousands of user IDs. I am...
by brajaram Communicator in Splunk Search 12-28-2018
0 5
0
5
efaundez
good afternoon     I have a lookups that has 11737540 lines, but when I see it in splunk, it only shows me half | i...
by efaundez Path Finder in Splunk Search 12-28-2018
0 1
0
1
scottrunyon
I have a data model where the object is generated by a search which doesn't permit the DM to be accelerated which mea...
by scottrunyon Contributor in Splunk Search 12-27-2018
1 3
1
3
sdeveen
I use some embedded reports and they work fine. Now i made an upgrade to Version 6.3 and a Searchhead-Cluster. Now em...
by sdeveen Explorer in Splunk Search 12-27-2018
7 9
7
9
weidertc
We need to get the previous week's results as a second set of results based on the time picker used for current time ...
by weidertc Contributor in Splunk Search 12-27-2018
0 3
0
3
HealyManTech
I am trying to get where I have if the _time and host are the same I exclude those results. I was thinking an eval o...
by HealyManTech Explorer in Splunk Search 12-27-2018
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...