Splunk Search

Splunk Search
Community Activity
Shuhei052492
Hi, I would like to know how to calculate the "number of files" field in the table colunm of "Files & directories",w...
by Shuhei052492 Path Finder in Splunk Search 10-03-2018
0 0
0
0
hartcl1
I have data that looks like this; When I perform my search the data returned by Splunk looks like this on the dashbo...
by hartcl1 Explorer in Splunk Search 10-02-2018
0 2
0
2
pretzel2
I can search for events and run stats count by host. And I can run a search of distinct number of hosts. I want t...
by pretzel2 Path Finder in Splunk Search 10-02-2018
0 8
0
8
Skins
Hi, Is there a way to search for what searches have been run over a period of time and by who - preferably listing t...
by Skins Path Finder in Splunk Search 10-02-2018
0 2
0
2
hoerberm
Hi, I need your help, I have a search like this index=test sourcetype=XY | stats count(Field1) AS f1 by action=...
by hoerberm New Member in Splunk Search 10-02-2018
0 4
0
4
m4sucess
index="index1" sourcetype=show_command | join id [ search index="index2" sourcetype=software_data ] | sort _time | ...
by m4sucess New Member in Splunk Search 10-02-2018
0 3
0
3
josedgaravito
Hi, I have a CSV file with the following structure: NAME DiskSerial ProcSerial ...
by josedgaravito New Member in Splunk Search 10-02-2018
0 1
0
1
Shashank_87
Hi, I need to join my query with a lookup which contains a field called username. I need to get the users who — exi...
by Shashank_87 Explorer in Splunk Search 10-02-2018
0 1
0
1
harishnpandey
Hi , May I please get some help on extracting 1) IP only 2) IP and corresponding port together Connection termin...
by harishnpandey Explorer in Splunk Search 10-02-2018
0 4
0
4
zaynaly
This successfully shows a combined table with users that are in Table1 and Table2. However, I want to show all users ...
by zaynaly Explorer in Splunk Search 10-02-2018
0 3
0
3
alex_kh
Hello everybody, i want to count how often does a specific pair of src-dest appear... something like src, dest, co...
by alex_kh Explorer in Splunk Search 10-02-2018
0 1
0
1
shayhibah
I have a dashboard with a chart inside it. The query of the chart is: base_search | eval _time = time| bucket _time...
by shayhibah Path Finder in Splunk Search 10-02-2018
0 5
0
5
gregorymountfor
I'd like to join two searches and run some stats to group the combined result to see how many users change/update bro...
by gregorymountfor Explorer in Splunk Search 10-02-2018
0 0
0
0
LH_SPLUNK
I like to use DATABASES. I connected DBX and made a connection. With the query: | dbxquery query="SELECT * FROM \"XXX...
by LH_SPLUNK Explorer in Splunk Search 10-02-2018
0 1
0
1
avisriv
source="something_source" topic="something_topic1" OR topic="something_topic2" earliest = "-1d" client="cpu1305" | st...
by avisriv New Member in Splunk Search 10-02-2018
0 2
0
2
dfofie
I'm trying to display a timechart based on count by a type. But, for a certain type, the value will always be 0 for...
by dfofie New Member in Splunk Search 10-01-2018
0 2
0
2
mpatel11
I have multiple fields with similar names abc*, example: abcXYZ1 abcKLM abc_DEF I want to create a new field, say 'E...
by mpatel11 Explorer in Splunk Search 10-01-2018
1 6
1
6
avisriv
How do I fill values in a timechart for a non existing event? Suppose that the event is received at 5:00AM. Then, I w...
by avisriv New Member in Splunk Search 10-01-2018
0 3
0
3
gdavid
I'm trying to get the sum of spam folders and where they are quarantined by user. Is there a better way to do this, e...
by gdavid Path Finder in Splunk Search 10-01-2018
0 2
0
2
mpatel11
Say I have 100 rows of logs. Some have only field "abcXYZ1" and not the other two. Some have field "abcKLM" and not t...
by mpatel11 Explorer in Splunk Search 10-01-2018
0 2
0
2
heatonra
I've got a search viewed as a table and one of the values of the table cell is a URL. I want to be able to click on t...
by heatonra Engager in Splunk Search 10-01-2018
1 3
1
3
exmuzzy
my transforms.conf has such lines [api-param] REGEX=^(\w+)=(.+?)\n FORMAT=$1::$2 props.conf [api] TZ = Europe/Mo...
by exmuzzy Explorer in Splunk Search 10-01-2018
0 0
0
0
WXY
Now ,I have a lookup named exchange.csv , and index="exchange_data" The data in the exchange.csv is extracted from ...
by WXY Path Finder in Splunk Search 10-01-2018
0 7
0
7
arrangineni
Is there any way we can frame a Splunk query which we can run on a search head to get the list of all the Splunk clie...
by arrangineni Path Finder in Splunk Search 10-01-2018
0 0
0
0
mtmoore
I want to run a forecast time series multiple times using one search on the remaining freespace of a number of our da...
by mtmoore Explorer in Splunk Search 10-01-2018
0 2
0
2
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...