Splunk Search

Splunk Search
Community Activity
sant1ago
Hello, I want to compare several values to get the highest one. For example: index / count ....................
by sant1ago New Member in Splunk Search 10-05-2018
0 2
0
2
syjayaraj
Dear Team, I have data in this format, as shown in actual and expecting results as shown in expected. Is this achiev...
by syjayaraj Explorer in Splunk Search 10-05-2018
0 3
0
3
Mohsin123
Hi , i want a syntax for this: if Response_time>3000 then Response_time="gt3SEC" else if Response_time>1000 and Re...
by Mohsin123 Path Finder in Splunk Search 10-05-2018
0 7
0
7
baskarkrishnanc
I have data in splunk as following: log: [INFO ] 17:01:43.572 : [main] o.a.k.c.Processor:process(103): response ...
by baskarkrishnanc Engager in Splunk Search 10-05-2018
0 7
0
7
cpomerantzuniso
I have a JSON object that includes a field that is an array of strings. So something like this: { "tags": [ "v...
by cpomerantzuniso New Member in Splunk Search 10-05-2018
0 1
0
1
karthi2809
how do I set if condition if the "failurepercentage" is greater than 10 as amber and greater than 20 should be severe...
by karthi2809 Builder in Splunk Search 10-05-2018
0 1
0
1
naga1105
We have a message in logs which prints based on values sent in request. Ex in logs : "service-1 requested with typ...
by naga1105 New Member in Splunk Search 10-05-2018
0 1
0
1
andreiraduta
Hello, I have a list of users and the time they entered a building. I'm trying to find the earliest + latest time. ...
by andreiraduta New Member in Splunk Search 10-05-2018
0 1
0
1
akarivaratharaj
I am trying to add the below CSV file data into Splunk as an input through the ‘Add Data’ section. Time, Main_Release...
by akarivaratharaj Communicator in Splunk Search 10-05-2018
0 4
0
4
punixtr
I have a splunk query which results in the output as: INFO :url="some_url": APIFilter.onComplete@87 : type=finalRes...
by punixtr New Member in Splunk Search 10-05-2018
0 8
0
8
manijain
For example i have the below search eval Time_To_Map=strftime(strptime(STATUS_TIME,"%Y-%m-%d-%H.%M.%S.%3N"),"%H.%M"...
by manijain New Member in Splunk Search 10-04-2018
0 1
0
1
richard_temple
I am collecting the logs for an application and I'm trying to chart how many users are connecting to it over time. My...
by richard_temple New Member in Splunk Search 10-04-2018
0 1
0
1
utsav45
Hi All, We've set up an alert to flag AD Service account passwords are reset. Below is the alert condition: index=...
by utsav45 Explorer in Splunk Search 10-04-2018
0 4
0
4
josephinemho
I created values for the average CPU, memory and swap memory usage and managed to get it in a column chart. I'd like ...
by josephinemho Path Finder in Splunk Search 10-04-2018
0 8
0
8
jfriedman_ofigl
My data looks like this: { [-] computer_dns_name: computer.domain.com computer_sid: 22264db9ce59...
by jfriedman_ofigl Explorer in Splunk Search 10-04-2018
0 4
0
4
dsha
We have two different search queries with no unique fields and we would like to get the below info: we would like t...
by dsha Engager in Splunk Search 10-04-2018
0 8
0
8
qhma
I created a chart with too many columns, like following: source="/abc/def/aaa.log | chart count(eval(searchmatch("12...
by qhma New Member in Splunk Search 10-04-2018
0 1
0
1
anlai2
I currently have a search that shows a line chart of events according to a "Created" date field, but would like to sh...
by anlai2 Engager in Splunk Search 10-04-2018
0 0
0
0
nick405060
| makeresults | eval a=1024.0 | eval b=.15 | eval c=a*(1.0-b) | table a b c gives a b c 1024.0 0.15 870 ...
by nick405060 Motivator in Splunk Search 10-04-2018
0 3
0
3
smichalski
Dear Splunkers, I face logs, where special characters have been encoded into Unicode codepoints (e. g. \u0301 instea...
by smichalski Explorer in Splunk Search 10-04-2018
3 3
3
3
mitchellthom
I'm getting strange behavior with a sort, and wondered if anyone knows why. If I run: index=os source=/var/log/sla...
by mitchellthom Engager in Splunk Search 10-04-2018
0 2
0
2
alex_kh
Hello Folks, i have folowing question I have folowing search index=indexA OR index=indexB OR indexC user=alex OR ip...
by alex_kh Explorer in Splunk Search 10-04-2018
0 2
0
2
Shark2112
Hello! I want to find local IPs that communicate with outside IPs every 5 minutes, for example: ...
by Shark2112 Communicator in Splunk Search 10-04-2018
0 1
0
1
ADRIANODL
Hi splunkers, Suppose I have the following table: Date ItemsPurchased UnitPrice 1/1/1111 20 0.5 2/1/1111 10 1 3/1...
by ADRIANODL Explorer in Splunk Search 10-03-2018
0 7
0
7
JoshuaJohn
Trying to capture multiple groups, basically after the colon MacAddress : 7A:AA:82:31:24:B1 Manufactu...
by JoshuaJohn Contributor in Splunk Search 10-03-2018
0 4
0
4
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...