Splunk Search

Splunk Search
Community Activity
joemiller
I'm having trouble extracting key/value pairs from a set of data. I think there are two separate problems that are ma...
by joemiller Path Finder in Splunk Search 10-16-2018
0 6
0
6
jiaqya
i have 2 columns , one which has install status and the other which has the exception status. install status has yes/...
by jiaqya Builder in Splunk Search 10-16-2018
0 4
0
4
swetar
Can anyone please suggest to me how I can break this event... PATH="/user/hive/datastore/xyz.db/file_name1" PATH="/u...
by swetar New Member in Splunk Search 10-15-2018
0 6
0
6
teddyidc1101
I have this data Owner Branch# Bname O1 B1 Bname1 O1 B2 Bname2 O2 B1 Bname3 O2 B3 Bname4 O2 B4 Bname5 O3 ...
by teddyidc1101 Communicator in Splunk Search 10-15-2018
0 3
0
3
jrnastase
Hello all, Currently I have acquired a timechart in the format: Field_A / Field_B / Field_C / Field_D / Total //// ...
by jrnastase Explorer in Splunk Search 10-15-2018
0 1
0
1
dbcase
Hi, I have the below data and looking to determine the API call name . For the first one the name would be alarmS...
by dbcase Motivator in Splunk Search 10-15-2018
0 4
0
4
nick405060
There are a few other similar questions on Splunk answers, but each answer has been tailored to each asker's use case...
by nick405060 Motivator in Splunk Search 10-15-2018
0 1
0
1
landen99
I am interested in indexing all user's OS search history, web search history, and web browsing history from any brows...
by landen99 Motivator in Splunk Search 10-15-2018
0 5
0
5
highsplunker
Hey guys, It seems that if a field in Splunk index contains Non English characters - the search is very slow. I would...
by highsplunker Contributor in Splunk Search 10-15-2018
0 6
0
6
Log_wrangler
I have events like this.... <22>2018-10-10T09:38:50.631063-05:00 m0074417 sendmail[16942]: w9AEM7sO030350: to=<thisg...
by Log_wrangler Builder in Splunk Search 10-15-2018
0 1
0
1
luke222010
I am running the following search: index=fi | stats last(BP) as start,first(BP) as last by Name | eval diff=last-sta...
by luke222010 Engager in Splunk Search 10-15-2018
0 0
0
0
junxianli
How do I pass an event's field value into a subsearch to retrieve another field? At the moment, I can't use join bec...
by junxianli Explorer in Splunk Search 10-15-2018
4 4
4
4
a212830
Hi, We are frequently required to validate that data is being received by Splunk from multiple servers. The lists o...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
a212830
Hi, I have a query that uses this search to look for hosts that we need to validate: |tstats count WHERE index=* AN...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
dsmeerkat
So here are the results from my "Scanned" field: 20Certificates.pdf 20from=20GLA-PTX164760.pdf 20from=20a=20Xerox.pd...
by dsmeerkat Explorer in Splunk Search 10-15-2018
0 1
0
1
widomj
Is it possible to run multiple searches without having to open multiple browser tabs? Does Splunk have a built in tab...
by widomj New Member in Splunk Search 10-15-2018
0 2
0
2
jamesmoriarty
Hello! I've recently upgraded a test server of mine from 6.x.x to 7.2.x to find a weird bug and I'm wondering if any...
by jamesmoriarty Explorer in Splunk Search 10-15-2018
1 3
1
3
jip31
hello I use the request below but i would like to have an example of doing this code more performant following splun...
by jip31 Motivator in Splunk Search 10-15-2018
0 2
0
2
Sp3ctre11
So we have a lookup and an index : We need to correlate the prefix from the lookup with the data from the index, if...
by Sp3ctre11 New Member in Splunk Search 10-14-2018
0 7
0
7
jafarmat
Hi, So i'm having this rule... index=logs sourcetype=console_test_1 "[Status] Discovered" | rex "<regex rule...
by jafarmat New Member in Splunk Search 10-14-2018
0 4
0
4
landen99
Let's say I have a search that immediately goes into a lookup with a filtered kvstore of 1 million events followed by...
by landen99 Motivator in Splunk Search 10-14-2018
0 1
0
1
Esperteyu
Hi, I'm trying to get a timeline of the percentage of a particular error code among the total of logs. And, based on...
by Esperteyu Explorer in Splunk Search 10-14-2018
0 8
0
8
asdusert
Here is my query : index="basicdataapi" source="/data/api-process/logs/equitydata-rawdata-producer/application.log" ...
by asdusert Engager in Splunk Search 10-14-2018
0 3
0
3
flzhang132
I want to group by virtual machine and then find the latest time project name in each group. How would I implement t...
by flzhang132 Explorer in Splunk Search 10-13-2018
0 3
0
3
rajhemant26
Hello everyone. Want to display the output only for the time which crosses 18 months (earliest time)
by rajhemant26 New Member in Splunk Search 10-13-2018
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...