Splunk Search

Splunk Search
Community Activity
syjayaraj
Dear Team, I have data in this format, as shown in actual and expecting results as shown in expected. Is this achiev...
by syjayaraj Explorer in Splunk Search 10-05-2018
0 3
0
3
Mohsin123
Hi , i want a syntax for this: if Response_time>3000 then Response_time="gt3SEC" else if Response_time>1000 and Re...
by Mohsin123 Path Finder in Splunk Search 10-05-2018
0 7
0
7
baskarkrishnanc
I have data in splunk as following: log: [INFO ] 17:01:43.572 : [main] o.a.k.c.Processor:process(103): response ...
by baskarkrishnanc Engager in Splunk Search 10-05-2018
0 7
0
7
cpomerantzuniso
I have a JSON object that includes a field that is an array of strings. So something like this: { "tags": [ "v...
by cpomerantzuniso New Member in Splunk Search 10-05-2018
0 1
0
1
karthi2809
how do I set if condition if the "failurepercentage" is greater than 10 as amber and greater than 20 should be severe...
by karthi2809 Builder in Splunk Search 10-05-2018
0 1
0
1
naga1105
We have a message in logs which prints based on values sent in request. Ex in logs : "service-1 requested with typ...
by naga1105 New Member in Splunk Search 10-05-2018
0 1
0
1
andreiraduta
Hello, I have a list of users and the time they entered a building. I'm trying to find the earliest + latest time. ...
by andreiraduta New Member in Splunk Search 10-05-2018
0 1
0
1
akarivaratharaj
I am trying to add the below CSV file data into Splunk as an input through the ‘Add Data’ section. Time, Main_Release...
by akarivaratharaj Communicator in Splunk Search 10-05-2018
0 4
0
4
punixtr
I have a splunk query which results in the output as: INFO :url="some_url": APIFilter.onComplete@87 : type=finalRes...
by punixtr New Member in Splunk Search 10-05-2018
0 8
0
8
manijain
For example i have the below search eval Time_To_Map=strftime(strptime(STATUS_TIME,"%Y-%m-%d-%H.%M.%S.%3N"),"%H.%M"...
by manijain New Member in Splunk Search 10-04-2018
0 1
0
1
richard_temple
I am collecting the logs for an application and I'm trying to chart how many users are connecting to it over time. My...
by richard_temple New Member in Splunk Search 10-04-2018
0 1
0
1
utsav45
Hi All, We've set up an alert to flag AD Service account passwords are reset. Below is the alert condition: index=...
by utsav45 Explorer in Splunk Search 10-04-2018
0 4
0
4
josephinemho
I created values for the average CPU, memory and swap memory usage and managed to get it in a column chart. I'd like ...
by josephinemho Path Finder in Splunk Search 10-04-2018
0 8
0
8
jfriedman_ofigl
My data looks like this: { [-] computer_dns_name: computer.domain.com computer_sid: 22264db9ce59...
by jfriedman_ofigl Explorer in Splunk Search 10-04-2018
0 4
0
4
dsha
We have two different search queries with no unique fields and we would like to get the below info: we would like t...
by dsha Engager in Splunk Search 10-04-2018
0 8
0
8
qhma
I created a chart with too many columns, like following: source="/abc/def/aaa.log | chart count(eval(searchmatch("12...
by qhma New Member in Splunk Search 10-04-2018
0 1
0
1
anlai2
I currently have a search that shows a line chart of events according to a "Created" date field, but would like to sh...
by anlai2 Engager in Splunk Search 10-04-2018
0 0
0
0
nick405060
| makeresults | eval a=1024.0 | eval b=.15 | eval c=a*(1.0-b) | table a b c gives a b c 1024.0 0.15 870 ...
by nick405060 Motivator in Splunk Search 10-04-2018
0 3
0
3
smichalski
Dear Splunkers, I face logs, where special characters have been encoded into Unicode codepoints (e. g. \u0301 instea...
by smichalski Explorer in Splunk Search 10-04-2018
3 3
3
3
mitchellthom
I'm getting strange behavior with a sort, and wondered if anyone knows why. If I run: index=os source=/var/log/sla...
by mitchellthom Engager in Splunk Search 10-04-2018
0 2
0
2
alex_kh
Hello Folks, i have folowing question I have folowing search index=indexA OR index=indexB OR indexC user=alex OR ip...
by alex_kh Explorer in Splunk Search 10-04-2018
0 2
0
2
Shark2112
Hello! I want to find local IPs that communicate with outside IPs every 5 minutes, for example: ...
by Shark2112 Communicator in Splunk Search 10-04-2018
0 1
0
1
ADRIANODL
Hi splunkers, Suppose I have the following table: Date ItemsPurchased UnitPrice 1/1/1111 20 0.5 2/1/1111 10 1 3/1...
by ADRIANODL Explorer in Splunk Search 10-03-2018
0 7
0
7
JoshuaJohn
Trying to capture multiple groups, basically after the colon MacAddress : 7A:AA:82:31:24:B1 Manufactu...
by JoshuaJohn Contributor in Splunk Search 10-03-2018
0 4
0
4
patricianaguit
I need to find another way instead of eventstats for my search. Is there a way where I can tag the events and add an...
by patricianaguit Explorer in Splunk Search 10-03-2018
0 2
0
2
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors