Splunk Search

Splunk Search
Community Activity
matthew_foos
Splunkers, Search String: admon-user-lookup-update | eval src_user = (cn) | fields src_nt_domain, displayName, c...
by matthew_foos Path Finder in Splunk Search 10-12-2018
0 3
0
3
donaldwayne1975
We're using the Azure Monitoring Data Add-on to integrate Splunk and Azure. The Azure events have the subscription I...
by donaldwayne1975 Path Finder in Splunk Search 10-12-2018
0 1
0
1
memorecks
Hi guys First of all, please excuse, I'm an absolute newbie in regards to Splunk. I'm trying to do the following. Fr...
by memorecks New Member in Splunk Search 10-12-2018
0 1
0
1
djain
Hey Splunkers, Here is my original query where the sub search is getting truncated to 50000 records. index = abc so...
by djain Path Finder in Splunk Search 10-12-2018
0 11
0
11
chris94089
Greetings! I have duplicate data. But that's ok. I actually don't want to just remove my dupes, I want to create a...
by chris94089 Path Finder in Splunk Search 10-12-2018
0 6
0
6
mailmetoramu
Hi All, Actually in one of my server, some files has been deleted from the file path C\Windows\Systems32\drivers\etc...
by mailmetoramu Explorer in Splunk Search 10-12-2018
0 10
0
10
jwalzerpitt
I have the following search that shows users who are continuously being infected over a 30 day period: index=foo | s...
by jwalzerpitt Influencer in Splunk Search 10-12-2018
1 6
1
6
shaheelkhan59
Hello all, I've used the following SPL to extract some fields from my logs. I got the following result. My issue...
by shaheelkhan59 New Member in Splunk Search 10-12-2018
0 3
0
3
prachi0693
When dedup is used before sort in a query, the number of events returned is greater than the vice versa.
by prachi0693 New Member in Splunk Search 10-12-2018
0 1
0
1
celianouguier
I have some events like : _time CITY %CPU %Disk Read Time %Disk Writ...
by celianouguier Explorer in Splunk Search 10-12-2018
0 4
0
4
mwdbhyat
Hi Guys, I have a search that is working fine.. However the issue is that using the map command removes all other fi...
by mwdbhyat Builder in Splunk Search 10-12-2018
0 1
0
1
mwdbhyat
Hi guys, I have a search with subsearch that times out before it can complete. The subsearch doesnt finalise, so the...
by mwdbhyat Builder in Splunk Search 10-11-2018
0 4
0
4
saranyaa21
Hi, I have a log trace like, ...........................wages: 50 I have written a splunk query to skip all the e...
by saranyaa21 Path Finder in Splunk Search 10-11-2018
0 6
0
6
rajhemant26
How to calculate Throughput for web servers. if we have following data source. server name RAF,TAP,DFT
by rajhemant26 New Member in Splunk Search 10-11-2018
0 1
0
1
moorvogi
We have a report that runs and when you edit the report in the edit window, it will strip the space if the line wraps...
by moorvogi Path Finder in Splunk Search 10-11-2018
0 3
0
3
varun85negi
Hi, We have a query with below format: (index=A sourcetype=A1) OR (index=A sourcetype=A2) OR (index=B sourcetype=B1...
by varun85negi Engager in Splunk Search 10-11-2018
1 3
1
3
sgoodman26
We are having an issue when creating a New Field by using RegEx instead of the Field Extractor. The field itself may ...
by sgoodman26 Explorer in Splunk Search 10-11-2018
0 3
0
3
stcrispan
I have a Top Ten report going which counts the highest number of network timeout/disconnects on wireless devices by t...
by stcrispan Communicator in Splunk Search 10-11-2018
0 5
0
5
kokanne
Hi all, my query is not returning any results and I think it's an error in the query. The clauses 'as' and 'from' in ...
by kokanne Communicator in Splunk Search 10-11-2018
1 19
1
19
twh1
I have a field in my log which contains a huge text data with two different formats. I tried to catch a few parts in ...
by twh1 Communicator in Splunk Search 10-11-2018
0 3
0
3
arrangineni
I am trying to get a list of new inbound IPs/hosts, which would compare to the old data of the previous month from a ...
by arrangineni Path Finder in Splunk Search 10-11-2018
0 0
0
0
simpkins1958
I am not able to get the latest (or earliest) _time values using mstats. | mstats sum(bytes) latest(_time) where ind...
by simpkins1958 Contributor in Splunk Search 10-11-2018
0 2
0
2
anandhalagarasa
Hi Team, I need to extract the fields from the JSON format in my Search Head GUI so kindly let us know how to procee...
by anandhalagarasa Path Finder in Splunk Search 10-11-2018
0 6
0
6
twh1
I want to check the records for which CREATE_TIME matches based on my date selection from time picker control. Curren...
by twh1 Communicator in Splunk Search 10-11-2018
0 8
0
8
snorri
I have a timechart with multiple values/graphs. When hoovering my mouse over the timechart I can only see one value ...
by snorri Path Finder in Splunk Search 10-11-2018
0 4
0
4
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors