Splunk Search

Splunk Search
Community Activity
jec013
Is it possible to rename an app? Would it be as easy as just renaming the directory or would this cause an issue wit...
by jec013 Explorer in Splunk Search 10-23-2018
1 4
1
4
rpappu35
Do you know of any good ways to learn and practice the search commands, the SPL, videos, websites, and any other reso...
by rpappu35 Explorer in Splunk Search 10-23-2018
0 2
0
2
rparadinha
I have logs from a SIP proxy server and I'm trying to calculate a threshold based on response status every minute. I ...
by rparadinha Explorer in Splunk Search 10-23-2018
0 3
0
3
ppatrikfr
Hello, I have a search that i want to take zeros off of. But, when i do it with replace, it loses its table formatt...
by ppatrikfr Path Finder in Splunk Search 10-23-2018
0 1
0
1
dfofie
I have a timechart, But I've liked to display another field value directly on one chart line. (see the picture) T...
by dfofie New Member in Splunk Search 10-23-2018
0 1
0
1
roopasree
After applying the time range 01/10/2018 to 05/10/2018, I am not able to get s3,s5 in output. I am getting output as...
by roopasree Engager in Splunk Search 10-23-2018
0 1
0
1
Branden
Hello. I am having trouble with a complicated query. Here's what I'm trying to do: We have events from IIS w3svc1 lo...
by Branden Builder in Splunk Search 10-23-2018
0 5
0
5
QuintonS
I have the following query: | eval week=relative_time(_time,"@w1") | eval week=strftime(week,"%m%d %V") | stats sum(...
by QuintonS Path Finder in Splunk Search 10-23-2018
0 2
0
2
bhenderson286
I'm trying to hide some table headers in a dashboard. Below is my javascript code: require(['jquery', 'splunkj...
by bhenderson286 Explorer in Splunk Search 10-23-2018
0 3
0
3
abhi04
Hi, I have a field named "statusChanged" as shown below. I need to convert this (GMT) to EST . please help on the sa...
by abhi04 Communicator in Splunk Search 10-23-2018
0 3
0
3
jvmerilla
Hi All, I am experiencing somewhat weird results when converting time to epoch in our Splunk environment. I tried to...
by jvmerilla Path Finder in Splunk Search 10-23-2018
1 6
1
6
ejmin
Here are the example images That is the example output then the second one should not be like this The TOTAL row ...
by ejmin Path Finder in Splunk Search 10-22-2018
0 2
0
2
sunnyparmar
I have one Excel sheet in which there are around 1150 bum IDs. One of example given below. bum_id a62f1ede-e3c2-418a...
by sunnyparmar Communicator in Splunk Search 10-22-2018
0 2
0
2
matthew_foos
Splunkers, Looking for some kind of time modifier that will allow the following alert to fire only if CPU has been a...
by matthew_foos Path Finder in Splunk Search 10-22-2018
0 1
0
1
DataOrg
i want the data to be deleted after a second space. EX:data is like this "lenovo thinkcentre 6.7" and i want "lenov...
by DataOrg Builder in Splunk Search 10-22-2018
0 2
0
2
jan09jan
We recently upgraded our Splunk version from 6.5 to 7.0.3 and this then caused some rex queries in dashboards to stop...
by jan09jan New Member in Splunk Search 10-22-2018
0 2
0
2
bogdan_nicolesc
Hi all, I need to make a bunch of graphs for days, weeks and months per employee. But first things first, i need fo...
by bogdan_nicolesc Communicator in Splunk Search 10-22-2018
1 6
1
6
sheaross
I have a modify date field in my ingested data. The date format of this field is MMDDYY with no "/" or "-". Is th...
by sheaross Explorer in Splunk Search 10-22-2018
0 5
0
5
synking
Hey, i need assistance in trying to figure out how to create a field and extract the text after that. I am not sure...
by synking Explorer in Splunk Search 10-22-2018
0 3
0
3
abhi04
I want to compare two columns in splunk such that it compares the values of one server with values for different othe...
by abhi04 Communicator in Splunk Search 10-22-2018
0 0
0
0
rune_hellem
The inital search is this: index=myindex myapplication UID=* IDX=* IDOK=* | dedup IDX | table _time,UID,IDX,IDOK ...
by rune_hellem Contributor in Splunk Search 10-22-2018
1 1
1
1
jip31
Hello, I use the request below index=windows sourcetype="wineventlog:system" SourceName="Disk" (EventCode=7 OR Even...
by jip31 Motivator in Splunk Search 10-22-2018
0 10
0
10
tlam_splunk
How can I use SDK or RESTfulAPI to retrieve the SPL definition inside a panel of a dashboard?
by tlam_splunk Splunk Employee Splunk Employee in Splunk Search 10-21-2018
0 1
0
1
dbcase
Hi, I have this query that finds the duration of the transaction times. index=wholesale_app buildTarget=* product...
by dbcase Motivator in Splunk Search 10-21-2018
0 4
0
4
xindeNokia
query like below: | transaction startswith="Init" endswith="FINISHED" by ip | table duration ip Each IP has multip...
by xindeNokia Path Finder in Splunk Search 10-21-2018
0 2
0
2
Get Updates on the Splunk Community!

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors