Splunk Search

Splunk Search
Community Activity
jip31
Hello In an hat apps I have many apps with many dashboards inside each apps From the hat apps nav menu, I want to op...
by jip31 Motivator in Splunk Search 12-23-2018
0 2
0
2
jambajuice
I would like to dedup a series of events and save the oldest event for each host. Is it possible to use dedup for th...
by jambajuice Communicator in Splunk Search 12-22-2018
0 7
0
7
seomisp
I have a few lookup tables that I need to query against. For example: LT_type1 LT_type2 Depending on my search, the...
by seomisp Explorer in Splunk Search 12-21-2018
0 3
0
3
rholm01
index=_internal host=* source=*splunkd.log ulimit is what I found that works. I would to make sure that certain group...
by rholm01 Explorer in Splunk Search 12-21-2018
0 4
0
4
ppokhrel
I am using the search below to get a week over week results using Timewrap, but the results shown are from today and ...
by ppokhrel New Member in Splunk Search 12-21-2018
0 3
0
3
Pranit_Hod
How to write a search for License usage to be checked every hour & send an alert email every 10 mins upon reaching 80...
by Pranit_Hod New Member in Splunk Search 12-21-2018
0 5
0
5
gnovak
I've been trying to chart some data and every way I try, it just doesn't work. I'm able to create a table of my data...
by gnovak Builder in Splunk Search 12-21-2018
1 20
1
20
akhil36109
Search 1 is : index=reportstore earliest=-28d@d latest=@d sourcetype=reportstore_logs host=denver | eval ReportCreat...
by akhil36109 New Member in Splunk Search 12-21-2018
0 2
0
2
kimberlytrayson
So, I have been using Splunk out of the box for a while, but now I would like to do some data massaging before I pu...
by kimberlytrayson Path Finder in Splunk Search 12-21-2018
0 3
0
3
diegofavoretto
I am trying to get Unique IDs (appears in both indexes) but I only want to count if there is event_name="AccountFinal...
by diegofavoretto New Member in Splunk Search 12-21-2018
0 2
0
2
seomisp
I'm enriching my search with a match against a lookup table. However, the lookup returns more than 1 result for each ...
by seomisp Explorer in Splunk Search 12-21-2018
0 2
0
2
JuhiSaxena
Hi, We are getting indexing lag in one of our splunk index. There is variation in _index-time and _time hence produc...
by JuhiSaxena Explorer in Splunk Search 12-21-2018
0 2
0
2
tdotcspot
Hi there, Hoping someone could help me out. I'm currently using the AWS Add-On For Splunk and I wanted to expand the...
by tdotcspot New Member in Splunk Search 12-21-2018
0 4
0
4
AnmolKohli
We have a lookup file that has a list of series stored in a field — TS_SERIES_ID. We want to find the count of series...
by AnmolKohli Explorer in Splunk Search 12-21-2018
0 30
0
30
mlorrette
same search: timespan showing X results while search is showing Y results for the same timeframe. This search that i...
by mlorrette Path Finder in Splunk Search 12-21-2018
0 3
0
3
ppanchal
Hi, Below is my sample payload. I want to convert/display it into a column value pair. Eg, ESBTransactionID 7...
by ppanchal Path Finder in Splunk Search 12-21-2018
0 3
0
3
shivam2411
00000887 ThreadMonitor W WSVR0606W: Thread "WebContainer : 24" (00000887) was previously reported to be hung but has ...
by shivam2411 New Member in Splunk Search 12-21-2018
0 6
0
6
krusovice
Hi there, I have this query formed and I can't the get expected result, but it's very close to what I want. The resu...
by krusovice Path Finder in Splunk Search 12-21-2018
0 6
0
6
the_wolverine
We have high cardinality data -- virtually every event is unique except for a small percentage of cases that we care ...
by the_wolverine Champion in Splunk Search 12-21-2018
0 2
0
2
VI371887
Does stats support function inside function like shown below ? Where first i want to take percentile90 of PERCENT90 ...
by VI371887 Path Finder in Splunk Search 12-21-2018
0 1
0
1
shivam2411
00000887 ThreadMonitor W WSVR0606W: Thread "WebContainer : 24" (00000887) was previously reported to be hung but has ...
by shivam2411 New Member in Splunk Search 12-21-2018
0 1
0
1
pavanae
Hi I have the following search which is presently displaying the list of eventcounts by the field "category_type", ...
by pavanae Builder in Splunk Search 12-21-2018
0 4
0
4
jip31
hello, I use the WMI below index="windows-wmi" sourcetype="WMI:Reliability" Logfile=Application SourceName="Applica...
by jip31 Motivator in Splunk Search 12-21-2018
0 7
0
7
aravindhan_padm
I need help in extracting fields from the dynamically nested array coordinates from JSON. Here is the example data....
by aravindhan_padm New Member in Splunk Search 12-21-2018
0 1
0
1
aovsiannikov
I.e. <search1>: ... | table id, f1, f2, f3 <search2>: ... | table id, f1, f2 I need to find all records in <searc...
by aovsiannikov Explorer in Splunk Search 12-21-2018
0 4
0
4
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...