Splunk Search

Splunk Search
Community Activity
Shan
Hi All, Kindly help me with regex for below sample data. Its only a sample there might be some other pattern of data...
by Shan Builder in Splunk Search 08-26-2018
0 6
0
6
robertosegantin
Hi to all, I would like to define a dynamic condition into a lookup, which uses the fields defined inside a search, ...
by robertosegantin Path Finder in Splunk Search 08-26-2018
0 5
0
5
tamakg
With the following search index=msperf sourcetype="perfmon_processor_xml" | xpath outfield=Architecture "//COMMAND/...
by tamakg Path Finder in Splunk Search 08-26-2018
0 1
0
1
fisuser1
I've created a chart that only shows run times above a 60 day average and it's corresponding average, which works per...
by fisuser1 Contributor in Splunk Search 08-26-2018
0 3
0
3
samlinsongguo
Hi I have a field with following value 16/08/2018 03:04:11 - Christian (Work notes) Remote Desktop Notes: - still u...
by samlinsongguo Communicator in Splunk Search 08-25-2018
0 4
0
4
khanlarloo
hi i have tow devices, i want to check the result of the same event in tow devices. for example if one source is blo...
by khanlarloo Explorer in Splunk Search 08-25-2018
0 2
0
2
prathapkcsc
Hi one and all, I have my log data as below for every 15min interval. 2018-08-23,16:16,11230,37393,49019 2018-08-23,...
by prathapkcsc Explorer in Splunk Search 08-24-2018
0 3
0
3
Piggyy
I need to search for fields that contain exactly 6 digits. For example, it should return fields that contain "123456...
by Piggyy New Member in Splunk Search 08-24-2018
0 3
0
3
tb5821
I tried to add a simple join onto my search but Splunk throws a 400 error {"messages":[{"type":"FATAL","text":"Miss...
by tb5821 Communicator in Splunk Search 08-24-2018
1 4
1
4
slord
I have the following data in _raw and I need to split the data at the semicolon into multiple fields in a table LOG ...
by slord Engager in Splunk Search 08-24-2018
0 4
0
4
splk_clheureux
My data : _time MODULE NOMBRE_DE_WA_ECRITS [...] 2016-07-18 20:02:37 MOD1...
by splk_clheureux Explorer in Splunk Search 08-24-2018
1 5
1
5
benj851
I am trying to find missing stores from query 2 in the below script. However, it returns no results, or all results d...
by benj851 Explorer in Splunk Search 08-24-2018
0 6
0
6
bojanz
Is it possible to have charts with both positive and negative values? For example, if I have a time series that can ...
by bojanz Communicator in Splunk Search 08-24-2018
0 3
0
3
praspai
Hi, I want to concatenate results from same field into string. How can I do that? e..g |inputlookup user.csv| tabl...
by praspai Path Finder in Splunk Search 08-24-2018
0 3
0
3
everynameIwanti
Hi. im new to Splunk. I'm trying to compare the sum(bytes) for an hour ago, and the same hour one week before by cer...
by everynameIwanti Explorer in Splunk Search 08-24-2018
0 2
0
2
christopheryu
I have a search with the following table as output: time customer circuit_id parent_circuit device_card 8:1...
by christopheryu Communicator in Splunk Search 08-24-2018
0 4
0
4
malmiran
Need to do a lookup using the hostname field from my events data and an asset name from my asset/cmdb data. However, ...
by malmiran Path Finder in Splunk Search 08-23-2018
0 5
0
5
bestSplunker
We know we can see the number of clients on the Forwarder Management page of the deployment server, but I want to sho...
by bestSplunker Contributor in Splunk Search 08-23-2018
0 1
0
1
serviceinfrastr
Hi Community, I have a question about regex and extraction I want to extract only the string between /var/log/nginx...
by serviceinfrastr Explorer in Splunk Search 08-23-2018
0 5
0
5
fisuser1
Hello - we are looking to present daily run time values of events in a search, but only display the daily run time va...
by fisuser1 Contributor in Splunk Search 08-23-2018
0 2
0
2
MikeElliott
Hi all, I have been working on integrating the Splunk Universal Forwarder into a system image that we will use to de...
by MikeElliott Communicator in Splunk Search 08-23-2018
0 4
0
4
tonahoyos
Hello, I want to divide AverageCount by AverageTotal. The problem is that Average count is separated by Sourcetype a...
by tonahoyos Explorer in Splunk Search 08-23-2018
0 12
0
12
JordanPeterson
I have a search that is currently working to give me a spark line for different event types. The search looks like th...
by JordanPeterson Path Finder in Splunk Search 08-23-2018
0 2
0
2
AnthonyTibaldi
I have a lookup file named mylookup. The lookup is a csv with the following information: SearchString, Reported_by,...
by AnthonyTibaldi Path Finder in Splunk Search 08-23-2018
0 5
0
5
mattbirk
When I try to join three sourcetypes on CommonField, I don't get all the fields to populate in a table. Example: s...
by mattbirk Explorer in Splunk Search 08-23-2018
0 2
0
2
Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...