Splunk Search

Splunk Search
Community Activity
ugruner
Hi, i am not familiar with regex and am trying to extract only the filename from the following data without the numb...
by ugruner Explorer in Splunk Search 11-16-2018
0 1
0
1
morethanyell
I've looked hard, but I can't seem to find the .conf file of Lookup Definition. I know it can be done on the user int...
by morethanyell Builder in Splunk Search 11-16-2018
0 2
0
2
andrewtrobec
Hello, I am looking for optimization advice for a use case in which I need to create new event data and then calcula...
by andrewtrobec Motivator in Splunk Search 11-16-2018
0 3
0
3
rickyhsu7
I have added another algorithm SVR in Splunk Enterprise with the way on the website below, and it works. But I'm conf...
by rickyhsu7 Explorer in Splunk Search 11-16-2018
0 1
0
1
BlueSocket
Dear All, I have a geostats search that is providing a mapped view of events over a single area. It is like this: i...
by BlueSocket Contributor in Splunk Search 11-16-2018
1 9
1
9
ndaniel88
Hello, I'm trying to do an outer join, but without actually using a join, I have a lookup with names and based on t...
by ndaniel88 Explorer in Splunk Search 11-15-2018
0 3
0
3
ngantla
We are connecting to Splunk from Tableau via ODBC. It worked fine for most of the time. Recently we are facing [Spl...
by ngantla New Member in Splunk Search 11-15-2018
0 0
0
0
danje57
Hello Splunkers, I've a issue with my distributed searches. I've one search head and 2 indexers. Both indexers are ...
by danje57 Path Finder in Splunk Search 11-15-2018
0 2
0
2
ramprakash
Hello Everyone...I have the below query and I want to evict transactions that starts with Message arrived but not end...
by ramprakash Explorer in Splunk Search 11-15-2018
0 1
0
1
msteffes
I keep receiving the error "External search command 'ldapfetch' returned error code 1. Script output = "error_message...
by msteffes New Member in Splunk Search 11-15-2018
0 2
0
2
jtotzek
Hi, I tried many things but I still cannot get to the correct result. my field value looks like this http://34.223...
by jtotzek Explorer in Splunk Search 11-15-2018
0 5
0
5
nikosattlermhp
How can I get the nested JSON in this field called "Message" (see below) with the nested fields (here currentMessage)...
by nikosattlermhp Engager in Splunk Search 11-15-2018
0 0
0
0
johann2017
Hello, I want to make a very specific exclusion from my search. In my case, there are two different field names I am...
by johann2017 Explorer in Splunk Search 11-15-2018
0 2
0
2
sahil237888
How can I use streamstats for checking multiple column values.(With or without foreach command for multiple columns)
by sahil237888 Path Finder in Splunk Search 11-15-2018
0 9
0
9
rpradeep
One of my dashboards reflects some data which actually isn't present in the data input. It might have been present be...
by rpradeep Path Finder in Splunk Search 11-15-2018
0 15
0
15
praspai
I want to extract XML field value ItemType and ItemNo from following XML. How can I build the Regular expression? <...
by praspai Path Finder in Splunk Search 11-15-2018
1 5
1
5
Cyber_X
Hi Splunk Team. I have a problem with the agent as follows: I added a monitor to the directory, then 2 hours I chec...
by Cyber_X New Member in Splunk Search 11-14-2018
0 2
0
2
dsha
we have two queries . both the queries have same keyword with value.so we would like to list the values of the keywor...
by dsha Engager in Splunk Search 11-14-2018
0 2
0
2
l1bertyx
I am trying to average fields together across multiple columns based on a specific string (A_Field and B_Field) For ...
by l1bertyx Engager in Splunk Search 11-14-2018
0 2
0
2
yannK
Hi Splunk people. I am trying to map the number of concurrent transactions. This is not exactly the same than the co...
by yannK Splunk Employee Splunk Employee in Splunk Search 11-14-2018
5 16
5
16
splunkreal
Hello guys, I have data like this using Splunk 7.1 and I would like to calculate minutes between start and end of ea...
by splunkreal Motivator in Splunk Search 11-14-2018
0 1
0
1
splunker1981
Hello fellow Splunkers I'm trying to figure out how to join values from 2 indexes and return one field (from one of...
by splunker1981 Path Finder in Splunk Search 11-14-2018
0 6
0
6
kshanker
I am using souretype cisco:wsa:squid, however I tried all the cisco:wsa:w3c as well, no luck so far? No sure where am...
by kshanker New Member in Splunk Search 11-14-2018
0 1
0
1
neeraja432
i am new to Splunk. Please let me know when to use format and return in a Splunk subsearch.
by neeraja432 New Member in Splunk Search 11-14-2018
0 1
0
1
twh1
I have a requirement to print the source count from how many hosts we are collecting. Expected output: source_count/...
by twh1 Communicator in Splunk Search 11-14-2018
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...