Splunk Search

Splunk Search
Community Activity
edigilink
I want to merge multiple events that contains the same ID into an unique event. For example: {id: 123 setDate: 201...
by edigilink Explorer in Splunk Search 07-18-2018
0 5
0
5
corematrix
I've just created a simple search which sorts people's scores (anywhere from 0 to 10000). I want to be able to show t...
by corematrix New Member in Splunk Search 07-18-2018
0 3
0
3
ksinghg
I'm running into an issue where I am receiving a flood of emails for an alert. The alert works as expected when I al...
by ksinghg Engager in Splunk Search 07-18-2018
0 0
0
0
snigdhasaxena
I have tried using bin command but as index=test| bin span=1w _time | chart count as total_count by _time, action B...
by snigdhasaxena Communicator in Splunk Search 07-18-2018
0 1
0
1
dkorlat
I'm unable to create a regex that captures the first 6 characters of a mac address and removes the hyphen characters....
by dkorlat Explorer in Splunk Search 07-18-2018
0 4
0
4
Uday_Gonti
Ex: sourcetype=abcd [search sourcetype=xyz field1=200 | table field2,field3,field4] which will be literally sourc...
by Uday_Gonti New Member in Splunk Search 07-18-2018
0 2
0
2
snigdhasaxena
I have tried using bin command but as index=test| bin span=1w _time | chart count as total_count by _time, action ...
by snigdhasaxena Communicator in Splunk Search 07-18-2018
0 2
0
2
zikpefu
I am trying to remove the +'s in between words for my table (i.e. stainless+steel to be just stainless steel) and my ...
by zikpefu New Member in Splunk Search 07-18-2018
0 2
0
2
robgarner
A user has a dashboard made of multiple searches all based on the last 24 hours of a single very large index. Some p...
by robgarner Path Finder in Splunk Search 07-18-2018
0 7
0
7
splunker969
Hi Splunk members, How Can I get some metrics to indicate things like search concurrency, search queue depth, cancel...
by splunker969 Communicator in Splunk Search 07-18-2018
0 2
0
2
Chandras11
Hi All, I have 2 sourcetypes as following:- Sourcetype_A Ticket | Main_Ticket | Value | Line | LinkedTicket Sou...
by Chandras11 Communicator in Splunk Search 07-18-2018
0 4
0
4
john_q
i want to count eventcount comparison using time trends chart for today , lastweek and last2weeks. below are the my s...
by john_q Explorer in Splunk Search 07-17-2018
0 3
0
3
andrehl
index="stage" |stats dc(customers_name) as "Distinct Customer" by sku_name sku_number |rename sku_name as Product sku...
by andrehl Explorer in Splunk Search 07-17-2018
0 3
0
3
tmmet
Hi, Could anyone please provide some information on the below? If you have an excel/csv file with server health det...
by tmmet New Member in Splunk Search 07-17-2018
0 5
0
5
mfrost8
I'm trying to use a search that looks like index=<index> sourcetype=<sourcetype> | eval site=<site> | lookup host_an...
by mfrost8 Builder in Splunk Search 07-17-2018
0 2
0
2
mcm10285
Hi, anybody has an idea on how to get a value from one search and input it to another search, then display them in a ...
by mcm10285 Communicator in Splunk Search 07-17-2018
1 9
1
9
ixixix_spl
I am looking to perform a case match search and have found that this query template attempted to answer how to define...
by ixixix_spl Explorer in Splunk Search 07-17-2018
0 3
0
3
keekkenen
Hi, all for example, I want find all transactions contains some word. How to make it more faster ? If I have too mu...
by keekkenen Engager in Splunk Search 07-17-2018
0 6
0
6
m7787580
Hi Splunker, Originally I have an output like this as a raw event in Splunk:- 2018-07-17 14:56:08 MIR="TUE, 17-JUL-...
by m7787580 Explorer in Splunk Search 07-17-2018
0 2
0
2
ryan_t_gavin
For example, I have the field "received_files" with 3 values: 1, 2, and 3. I already ran "convert num(received_files...
by ryan_t_gavin New Member in Splunk Search 07-17-2018
0 0
0
0
Clovisa
Hello, I am trying to build a role that would allow the users to access to two indexes (index1 and index2). The inde...
by Clovisa Path Finder in Splunk Search 07-17-2018
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the following stats query. `wso2_wmf(RequestC...
by IRHM73 Motivator in Splunk Search 07-17-2018
1 6
1
6
gokikrishnan198
I would like to find a error occurs in the past 30, 60 and 90 days. How to do that?
by gokikrishnan198 New Member in Splunk Search 07-16-2018
0 1
0
1
flzhang132
In my dashBoard,i edit a table in sampleXML,then, The table is converted from sampleXML to HTML. and Converted code v...
by flzhang132 Explorer in Splunk Search 07-16-2018
0 1
0
1
naotoyoshida
I'm using Windows Universal Forwarder (UF) 7.1.2 in my test environment. Windows 2012 R2 (gets security event from R...
by naotoyoshida New Member in Splunk Search 07-16-2018
0 0
0
0
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...
Top Solution Authors