Splunk Search

Splunk Search
Community Activity
willsy
Hello, I am trying to complete a query that allows me to see both the latest failed and successful backups from eve...
by willsy Communicator in Splunk Search 12-10-2018
0 4
0
4
casmond
Hi everyone, I am new to Splunk and i have a quite a few projects in my organization. I know that an index can have ...
by casmond New Member in Splunk Search 12-10-2018
0 2
0
2
cindywee
Hi all, I have the following data and I need some help to progress further. I have fields: _time uniqueId action us...
by cindywee New Member in Splunk Search 12-09-2018
0 2
0
2
roayers
Here is the search and lookup, I need to capture the value, last_logon_lookup_20180928.csv We need the value in bold...
by roayers Explorer in Splunk Search 12-09-2018
0 3
0
3
doogan12
Woodcock - As a new question to the previous one that you help resolve - do you have any idea why the drilldown isn't...
by doogan12 Engager in Splunk Search 12-09-2018
0 16
0
16
lblackey
Splunk rookie here, so please be gentle. I am hoping someone can help me with a date-time range issue within a subse...
by lblackey Engager in Splunk Search 12-09-2018
1 8
1
8
ny34940
I want to add % symbol with both the y-axis legend and data labels Thanks in advance!
by ny34940 Path Finder in Splunk Search 12-09-2018
0 13
0
13
lukasz92
Hi, I have savedsearches like: dev_sudo dev_sudo mod dev_sudo mod2 How to dump the first with btool? If I use spl...
by lukasz92 Communicator in Splunk Search 12-08-2018
0 3
0
3
rkatsnel
Hello all , I've configured Splunk to monitor directory , i.e. /usr/home/test/* for new CSV files ( periodically ...
by rkatsnel New Member in Splunk Search 12-08-2018
0 6
0
6
grex2595
I'm doing a join where I want to only get subsearch events that happened before the parent search event. Thus, I'm u...
by grex2595 New Member in Splunk Search 12-08-2018
0 1
0
1
moizmmz
Hello, I've been asked to set up an alert for disk space exceeding 80%. I enabled the DMC Alert - Near Critical Di...
by moizmmz Path Finder in Splunk Search 12-07-2018
0 3
0
3
juanlazarosanch
Using Splunk 7.2.0. While looking at the Monitoring Console and performing this search (see below) , I see almost 70...
by juanlazarosanch New Member in Splunk Search 12-07-2018
0 1
0
1
samtheman
I notice that the below query results in 0 events, whereas the baseSearch alone results in 11 events and the sub-sear...
by samtheman Engager in Splunk Search 12-07-2018
0 3
0
3
moizmmz
Query I am running: index="dcg-video-eng-live-services-stage" | spath "message.req.originalUrl" | search "message.re...
by moizmmz Path Finder in Splunk Search 12-07-2018
0 8
0
8
0xlc
Hi, can anyone help me a bit? i am trying to split an event in more lines or more events, every events got multiple ...
by 0xlc Path Finder in Splunk Search 12-07-2018
0 2
0
2
lball
I am creating a dashboard for Tenable results and some entries have a Patch Publication Date value of -1. I'm having ...
by lball Explorer in Splunk Search 12-07-2018
0 3
0
3
vaibhavvijay9
Hi All, I am using this search string as below : (some data- index, host, etc)............. | xmlkv | search "ns0:Ap...
by vaibhavvijay9 New Member in Splunk Search 12-06-2018
0 3
0
3
infcl
Log1: id=5 errorA Log2: id=5 errorB I would like a query to return the logs with the same id value grouped together....
by infcl Explorer in Splunk Search 12-06-2018
0 1
0
1
mcbradfordwcb
I understand the behavior of Splunk when using _indextime, but I want to know what query would do what I really am lo...
by mcbradfordwcb Engager in Splunk Search 12-06-2018
0 7
0
7
HattrickNZ
I refer to the outlier command https://docs.splunk.com/Documentation/Splunk/7.0.4/SearchReference/Outlier *Is there ...
by HattrickNZ Motivator in Splunk Search 12-06-2018
0 0
0
0
abhishekgandhe
I want to extract the following values from below JSON. Values needs to be extracted from the highlighted text in Bol...
by abhishekgandhe Explorer in Splunk Search 12-06-2018
0 2
0
2
purnang
Join query return weird result. Sometime its pull correct result & if I execute the same query after 2 mins. Some of ...
by purnang New Member in Splunk Search 12-06-2018
0 4
0
4
haoban
virus_type {"Troj/DocDl-QUA": 4, "CXmail/OleDl-AU": 44, "CXmail/EncDoc-B": 6, "Troj/DocDl-QVV": 10, "Troj/DocDl-QVQ...
by haoban Path Finder in Splunk Search 12-06-2018
0 0
0
0
bollam
Hello, I have got events with two different types: Type=First and type=Second I would like to get the consolidated(...
by bollam Path Finder in Splunk Search 12-06-2018
0 3
0
3
vinoth12
In PIEchart dashboard, I can view the details of all the slices properly. But while trying to export as PDF.. only 12...
by vinoth12 New Member in Splunk Search 12-06-2018
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...