Splunk Search

Splunk Search
Community Activity
utsav45
Hi All, We've set up an alert to flag AD Service account passwords are reset. Below is the alert condition: index=...
by utsav45 Explorer in Splunk Search 10-04-2018
0 4
0
4
josephinemho
I created values for the average CPU, memory and swap memory usage and managed to get it in a column chart. I'd like ...
by josephinemho Path Finder in Splunk Search 10-04-2018
0 8
0
8
jfriedman_ofigl
My data looks like this: { [-] computer_dns_name: computer.domain.com computer_sid: 22264db9ce59...
by jfriedman_ofigl Explorer in Splunk Search 10-04-2018
0 4
0
4
dsha
We have two different search queries with no unique fields and we would like to get the below info: we would like t...
by dsha Engager in Splunk Search 10-04-2018
0 8
0
8
qhma
I created a chart with too many columns, like following: source="/abc/def/aaa.log | chart count(eval(searchmatch("12...
by qhma New Member in Splunk Search 10-04-2018
0 1
0
1
anlai2
I currently have a search that shows a line chart of events according to a "Created" date field, but would like to sh...
by anlai2 Engager in Splunk Search 10-04-2018
0 0
0
0
nick405060
| makeresults | eval a=1024.0 | eval b=.15 | eval c=a*(1.0-b) | table a b c gives a b c 1024.0 0.15 870 ...
by nick405060 Motivator in Splunk Search 10-04-2018
0 3
0
3
smichalski
Dear Splunkers, I face logs, where special characters have been encoded into Unicode codepoints (e. g. \u0301 instea...
by smichalski Explorer in Splunk Search 10-04-2018
3 3
3
3
mitchellthom
I'm getting strange behavior with a sort, and wondered if anyone knows why. If I run: index=os source=/var/log/sla...
by mitchellthom Engager in Splunk Search 10-04-2018
0 2
0
2
alex_kh
Hello Folks, i have folowing question I have folowing search index=indexA OR index=indexB OR indexC user=alex OR ip...
by alex_kh Explorer in Splunk Search 10-04-2018
0 2
0
2
Shark2112
Hello! I want to find local IPs that communicate with outside IPs every 5 minutes, for example: ...
by Shark2112 Communicator in Splunk Search 10-04-2018
0 1
0
1
ADRIANODL
Hi splunkers, Suppose I have the following table: Date ItemsPurchased UnitPrice 1/1/1111 20 0.5 2/1/1111 10 1 3/1...
by ADRIANODL Explorer in Splunk Search 10-03-2018
0 7
0
7
JoshuaJohn
Trying to capture multiple groups, basically after the colon MacAddress : 7A:AA:82:31:24:B1 Manufactu...
by JoshuaJohn Contributor in Splunk Search 10-03-2018
0 4
0
4
patricianaguit
I need to find another way instead of eventstats for my search. Is there a way where I can tag the events and add an...
by patricianaguit Explorer in Splunk Search 10-03-2018
0 2
0
2
patricianaguit
is there a way where I can tag events and add another field based on hierarchy? For example: Id 1 has different ini...
by patricianaguit Explorer in Splunk Search 10-03-2018
0 4
0
4
jip31
Hello In a report, i used the code below in order to search for an error code in my events. But, when a code is fou...
by jip31 Motivator in Splunk Search 10-03-2018
0 2
0
2
alex129
I am doing a search and evaluating count, avg RT based on some URL patterns. Below are the URLs for my category pages...
by alex129 New Member in Splunk Search 10-03-2018
0 8
0
8
jcleary47
I have a search to identify when a particular server activates "hardware mode" and doesn't exit within a certain time...
by jcleary47 Path Finder in Splunk Search 10-03-2018
0 2
0
2
russell120
Hi, I have two lookup files below: masterinventory.csv type make model year storeID keycode...
by russell120 Communicator in Splunk Search 10-03-2018
0 3
0
3
gnoellbn
Hello, I'm trying to figure out a way to extract values where the field has multiple spaces in it. When I do a sim...
by gnoellbn Explorer in Splunk Search 10-03-2018
0 8
0
8
m4sucess
index="index1 sourcetype="sourcetype1" | join deviceId [ search index="index2" sourcetype="sourcetype2" productFamil...
by m4sucess New Member in Splunk Search 10-03-2018
0 7
0
7
lukasz92
Hi, How can I get 'raw' earliest and latest value before doing search? I need the epoch seconds format, so -1d@d co...
by lukasz92 Communicator in Splunk Search 10-03-2018
1 10
1
10
edwardrose
Hello All I am not sure how to show the row count in my dashboard. I have one panel that searches a list of hosts...
by edwardrose Contributor in Splunk Search 10-03-2018
0 2
0
2
nkchaitanya
Want to capture the latest occurrence of "working_condition_check - status -" which is "Stopped". Please help me in...
by nkchaitanya Explorer in Splunk Search 10-03-2018
0 2
0
2
gcescatto
I have the following JSON, but I'm not really familiar with Splunk's rex function. I tried this command without succe...
by gcescatto New Member in Splunk Search 10-03-2018
0 1
0
1
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors