Splunk Search

Splunk Search
Community Activity
crisjnelson
Given the following log events, how can transaction be used to calculate the average duration of nested overlapping t...
by crisjnelson Explorer in Splunk Search 12-24-2018
0 3
0
3
zacksoft
Here is how events are, 2018-12-20T13:38:07.938-0500: 28658.929: [**Dull BC** (Allocation Failure) 2018-12-20T13:38...
by zacksoft Contributor in Splunk Search 12-24-2018
0 2
0
2
a508184
Hi - Need to create a Splunk dashboard for an application. Am very new to Splunk and doesn't have any Splunk exper...
by a508184 Explorer in Splunk Search 12-24-2018
0 11
0
11
brent_weaver
So I need to add a bunch of local users to Splunk. We are an ansible shop, and we can leverage the uri modue: --- -...
by brent_weaver Builder in Splunk Search 12-23-2018
0 4
0
4
jip31
Hello In an hat apps I have many apps with many dashboards inside each apps From the hat apps nav menu, I want to op...
by jip31 Motivator in Splunk Search 12-23-2018
0 2
0
2
jambajuice
I would like to dedup a series of events and save the oldest event for each host. Is it possible to use dedup for th...
by jambajuice Communicator in Splunk Search 12-22-2018
0 7
0
7
seomisp
I have a few lookup tables that I need to query against. For example: LT_type1 LT_type2 Depending on my search, the...
by seomisp Explorer in Splunk Search 12-21-2018
0 3
0
3
rholm01
index=_internal host=* source=*splunkd.log ulimit is what I found that works. I would to make sure that certain group...
by rholm01 Explorer in Splunk Search 12-21-2018
0 4
0
4
ppokhrel
I am using the search below to get a week over week results using Timewrap, but the results shown are from today and ...
by ppokhrel New Member in Splunk Search 12-21-2018
0 3
0
3
Pranit_Hod
How to write a search for License usage to be checked every hour & send an alert email every 10 mins upon reaching 80...
by Pranit_Hod New Member in Splunk Search 12-21-2018
0 5
0
5
gnovak
I've been trying to chart some data and every way I try, it just doesn't work. I'm able to create a table of my data...
by gnovak Builder in Splunk Search 12-21-2018
1 20
1
20
akhil36109
Search 1 is : index=reportstore earliest=-28d@d latest=@d sourcetype=reportstore_logs host=denver | eval ReportCreat...
by akhil36109 New Member in Splunk Search 12-21-2018
0 2
0
2
kimberlytrayson
So, I have been using Splunk out of the box for a while, but now I would like to do some data massaging before I pu...
by kimberlytrayson Path Finder in Splunk Search 12-21-2018
0 3
0
3
diegofavoretto
I am trying to get Unique IDs (appears in both indexes) but I only want to count if there is event_name="AccountFinal...
by diegofavoretto New Member in Splunk Search 12-21-2018
0 2
0
2
seomisp
I'm enriching my search with a match against a lookup table. However, the lookup returns more than 1 result for each ...
by seomisp Explorer in Splunk Search 12-21-2018
0 2
0
2
JuhiSaxena
Hi, We are getting indexing lag in one of our splunk index. There is variation in _index-time and _time hence produc...
by JuhiSaxena Explorer in Splunk Search 12-21-2018
0 2
0
2
tdotcspot
Hi there, Hoping someone could help me out. I'm currently using the AWS Add-On For Splunk and I wanted to expand the...
by tdotcspot New Member in Splunk Search 12-21-2018
0 4
0
4
AnmolKohli
We have a lookup file that has a list of series stored in a field — TS_SERIES_ID. We want to find the count of series...
by AnmolKohli Explorer in Splunk Search 12-21-2018
0 30
0
30
mlorrette
same search: timespan showing X results while search is showing Y results for the same timeframe. This search that i...
by mlorrette Path Finder in Splunk Search 12-21-2018
0 3
0
3
ppanchal
Hi, Below is my sample payload. I want to convert/display it into a column value pair. Eg, ESBTransactionID 7...
by ppanchal Path Finder in Splunk Search 12-21-2018
0 3
0
3
shivam2411
00000887 ThreadMonitor W WSVR0606W: Thread "WebContainer : 24" (00000887) was previously reported to be hung but has ...
by shivam2411 New Member in Splunk Search 12-21-2018
0 6
0
6
krusovice
Hi there, I have this query formed and I can't the get expected result, but it's very close to what I want. The resu...
by krusovice Path Finder in Splunk Search 12-21-2018
0 6
0
6
the_wolverine
We have high cardinality data -- virtually every event is unique except for a small percentage of cases that we care ...
by the_wolverine Champion in Splunk Search 12-21-2018
0 2
0
2
VI371887
Does stats support function inside function like shown below ? Where first i want to take percentile90 of PERCENT90 ...
by VI371887 Path Finder in Splunk Search 12-21-2018
0 1
0
1
shivam2411
00000887 ThreadMonitor W WSVR0606W: Thread "WebContainer : 24" (00000887) was previously reported to be hung but has ...
by shivam2411 New Member in Splunk Search 12-21-2018
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors