Splunk Search

Splunk Search
Community Activity
fisuser1
Hello - we are looking to present daily run time values of events in a search, but only display the daily run time va...
by fisuser1 Contributor in Splunk Search 08-23-2018
0 2
0
2
MikeElliott
Hi all, I have been working on integrating the Splunk Universal Forwarder into a system image that we will use to de...
by MikeElliott Communicator in Splunk Search 08-23-2018
0 4
0
4
tonahoyos
Hello, I want to divide AverageCount by AverageTotal. The problem is that Average count is separated by Sourcetype a...
by tonahoyos Explorer in Splunk Search 08-23-2018
0 12
0
12
JordanPeterson
I have a search that is currently working to give me a spark line for different event types. The search looks like th...
by JordanPeterson Path Finder in Splunk Search 08-23-2018
0 2
0
2
AnthonyTibaldi
I have a lookup file named mylookup. The lookup is a csv with the following information: SearchString, Reported_by,...
by AnthonyTibaldi Path Finder in Splunk Search 08-23-2018
0 5
0
5
mattbirk
When I try to join three sourcetypes on CommonField, I don't get all the fields to populate in a table. Example: s...
by mattbirk Explorer in Splunk Search 08-23-2018
0 2
0
2
macoo
Why does mvexpand X remove events with X=NULL? As simple as that. It's illogical from my perspective, unless it's on...
by macoo Explorer in Splunk Search 08-23-2018
4 3
4
3
nick405060
How do I convert a CC to a country name in Splunk, or vice versa? Since Splunk Answers won't let me post this quest...
by nick405060 Motivator in Splunk Search 08-23-2018
1 6
1
6
ronbuzon
Need assistance regex to reformat the field the field is Message. And the output is "Reason: Details: Attributes: ...
by ronbuzon New Member in Splunk Search 08-23-2018
0 11
0
11
AKG1_old1
Hello, I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface ...
by AKG1_old1 Builder in Splunk Search 08-23-2018
0 7
0
7
tb5821
I'm running my search over the last 7 days and attempting to get the earliest time along with the value of the count ...
by tb5821 Communicator in Splunk Search 08-23-2018
0 1
0
1
ChrisCLewis
Hi, I am looking for some help on how to remove the malformed expression error coming from the query below, many th...
by ChrisCLewis Communicator in Splunk Search 08-23-2018
0 7
0
7
michel_hc
Hello, I'm new with Java SDK and this is what I don't understand in my use of it so far : Question 1: I am using t...
by michel_hc New Member in Splunk Search 08-23-2018
0 6
0
6
lyds
Hello, I have a log that records data bit by bit. I want to combine them to have only one row of data. ...
by lyds Explorer in Splunk Search 08-23-2018
0 3
0
3
limalbert
Captured fields are Account, RequestorCode, Service, and ElapsedTime. An Account will have multiple RequestorCode, an...
by limalbert Path Finder in Splunk Search 08-22-2018
0 14
0
14
jenny_life
hello everyone, I'd like to know how to combine three types of charts in one chart. I'd like to make just one chart ...
by jenny_life Path Finder in Splunk Search 08-22-2018
0 9
0
9
ankithreddy777
Hi, When we restart splunk forwarder from deployment -server does it start 1) based on user defined in boot script O...
by ankithreddy777 Contributor in Splunk Search 08-22-2018
0 3
0
3
vjzone
One of the queries i'm using has a variable with a "-" and splunk is unable to get me the stats count using the varia...
by vjzone Path Finder in Splunk Search 08-22-2018
0 8
0
8
thefuzz4
So I have this data Aug 22 09:13:46 someservername <118>1 2018-08-22T09:13:46.743+00:00 ip.address LOGSTASH - - - ...
by thefuzz4 Path Finder in Splunk Search 08-22-2018
0 8
0
8
faustof
I have a list large list of products. I need to search the list but filtering out some results based on the partial v...
by faustof Explorer in Splunk Search 08-22-2018
0 2
0
2
mwcooley
Hi, I have the following search that displays a table with time as rows and conferenceID as columns. i only want to...
by mwcooley Explorer in Splunk Search 08-22-2018
0 2
0
2
patouellet
Hello Splunk Ninjas, First time I've seen this: I have two fields, clearly regognised as numeric fields by Splunk. T...
by patouellet Path Finder in Splunk Search 08-22-2018
0 2
0
2
reetesh121
Part A: index=web splunk_server_group=hotel sourcetype=hotellog eventname=hotel-book earliest=-3d| eval dateyearwe...
by reetesh121 New Member in Splunk Search 08-22-2018
0 1
0
1
syjayaraj
The string is a single line, i am unable to extract all matching value in this line. The interesting fields that Splu...
by syjayaraj Explorer in Splunk Search 08-22-2018
0 3
0
3
alanzchan
I'm trying to append a two tables on a common key. I am using |appendcols but the two tables are not internally joine...
by alanzchan Path Finder in Splunk Search 08-22-2018
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...