Splunk Search

Splunk Search
Community Activity
luckyman80
Hi Splunk Community! Quick one for all you experts! I'm trying to timechart the following 4 separate metrics (repres...
by luckyman80 Path Finder in Splunk Search 10-29-2018
0 1
0
1
barney00
I have a field which is a username, but the results of the username starts with "USR" and the actual username is "USR...
by barney00 New Member in Splunk Search 10-29-2018
0 2
0
2
dbcase
Hi, I have this eval for a token but it doesn't ever seem to get set, what am I missing? <eval token="showapppages"...
by dbcase Motivator in Splunk Search 10-29-2018
0 5
0
5
ejwade
I need to create a table of all unique firewall connections over the last 90 days. Our FortiGate firewall is config...
by ejwade Contributor in Splunk Search 10-29-2018
0 4
0
4
antoniofacchi
Goodmorning, I have a Simple-XML with following search index=_internal source=*metrics.log group="per_sourcetype_th...
by antoniofacchi New Member in Splunk Search 10-29-2018
0 4
0
4
JyotiP
I have a query : host=*perf* bf19f0c3-2f10-4db2-b33f-efb946b0ee24 {"StatusCode":204* | table Message Out put of the...
by JyotiP Path Finder in Splunk Search 10-29-2018
0 7
0
7
maheshsat
Hi Team, I have PATA field which needs to do sum of PATA field, am using below command where should add PATA to get...
by maheshsat Explorer in Splunk Search 10-29-2018
0 8
0
8
rettops
We have a search that is spending most of its time in command.search.kv. If we give it a search which doesn't need a...
by rettops Path Finder in Splunk Search 10-29-2018
0 3
0
3
mishen_ka
HI, I creating modular input add-on. Now I try to create custom UI for input parameters as explained in documentation...
by mishen_ka New Member in Splunk Search 10-29-2018
0 3
0
3
mansinchu
Hi, I am trying to see if this type of query is possible I am creating an alert base on 2 conditions. The first co...
by mansinchu New Member in Splunk Search 10-29-2018
0 3
0
3
cfstoica
How do you add another column that contains averages based on previous columns after "chart count over Level by Month...
by cfstoica New Member in Splunk Search 10-29-2018
0 2
0
2
nuaraujo
Hello all, Can someone help me build a regex that may allow me to extract 3 different fields from events where all t...
by nuaraujo Path Finder in Splunk Search 10-29-2018
0 2
0
2
bogdan_nicolesc
Hi there, I need a way to rename rows using a file list (csv file or other file type) from a search job / dashboard....
by bogdan_nicolesc Communicator in Splunk Search 10-29-2018
0 3
0
3
sahil237888
Foreach value of a field (say field1), check if there is continuous 5 minutes low or high value (than 100) of res_tim...
by sahil237888 Path Finder in Splunk Search 10-29-2018
0 0
0
0
kcchu01
Hi, Can anyone teach me how to write a regular expression to extract the field on the following raw event? sendmai...
by kcchu01 Explorer in Splunk Search 10-29-2018
0 3
0
3
simpkins1958
Started getting Search auto-finalized after disk usage limit (100mb) reached - What does this mean?
by simpkins1958 Contributor in Splunk Search 10-29-2018
0 4
0
4
jip31
Hello, I would like to know how to display results in a count table (count = 0) even if the search doesn't return ev...
by jip31 Motivator in Splunk Search 10-29-2018
0 6
0
6
zztc2004
Hello, I am currently have 2 tables: Table-1 date, common-granularity, groupId-1, value-1 Table-2: date, common-gr...
by zztc2004 Explorer in Splunk Search 10-28-2018
0 2
0
2
msmapper
Hi there, I am trying to decide which Splunk command I should use to give better long-term performance on the search...
by msmapper Path Finder in Splunk Search 10-28-2018
0 8
0
8
jrnortonjr
I am utilizing a correlation search to schedule the delivery of application performance metrics against running proce...
by jrnortonjr New Member in Splunk Search 10-28-2018
0 1
0
1
mschellhouse
We are discussing the subsearch_max configuration setting in limits.conf internally and trying to better understand t...
by mschellhouse Path Finder in Splunk Search 10-28-2018
3 1
3
1
rossboss1989
The goal here is to let the search filter on the full values but only return a portion (substring) of the "Message" f...
by rossboss1989 Engager in Splunk Search 10-28-2018
0 1
0
1
Splunkster45
I am using Python API call to get Splunk data. I was running to a limit where I was hitting a limit of 50k. I saw thi...
by Splunkster45 Communicator in Splunk Search 10-28-2018
0 1
0
1
nhvardhan58
Hi All, I have two source type , for example. 1) sourcetype 1 2) sourcetype 2 In sourcetype 1 I have a string wh...
by nhvardhan58 Explorer in Splunk Search 10-28-2018
0 2
0
2
soumidutta
Hi , Can it be possible to write switch case statements in Splunk like other programming languages? If so, can you ...
by soumidutta Explorer in Splunk Search 10-27-2018
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...
Top Solution Authors