Splunk Search

Splunk Search
Community Activity
dragut
I want to use the python on OS instead of Splunk in-built python as it failed to import numpy and scipy. In the searc...
by dragut New Member in Splunk Search 07-18-2018
0 0
0
0
Manoj_g
I have a base search with index , source , and the sourcetype , I want to build alert when the SUCCESS_STATUS is havi...
by Manoj_g New Member in Splunk Search 07-18-2018
0 1
0
1
splunkrocks2014
I have a search returns two rows of records (check the result from the following query): | makeresults | eval date=...
by splunkrocks2014 Communicator in Splunk Search 07-18-2018
0 1
0
1
MaxwellCrew
Hey everyone, I've got a search search = * | eval _time=_time - (6*60*60) | bucket _time span=1d # Takes the curr...
by MaxwellCrew New Member in Splunk Search 07-18-2018
0 4
0
4
ddrillic
We would like to install the Timeline and Calendar Heat Map. What do we need to do?
by ddrillic Ultra Champion in Splunk Search 07-18-2018
0 3
0
3
Mathanjey
Hello, I have 2 timecharts that are working independently, can you help to merge both to one query (as overylay), th...
by Mathanjey Explorer in Splunk Search 07-18-2018
0 2
0
2
jkalyanasundara
I have the following SPL: some search | table _time, col1, col2 | timechart span=2m useother=f values(col2) as col2 ...
by jkalyanasundara New Member in Splunk Search 07-18-2018
0 1
0
1
edigilink
I want to merge multiple events that contains the same ID into an unique event. For example: {id: 123 setDate: 201...
by edigilink Explorer in Splunk Search 07-18-2018
0 5
0
5
corematrix
I've just created a simple search which sorts people's scores (anywhere from 0 to 10000). I want to be able to show t...
by corematrix New Member in Splunk Search 07-18-2018
0 3
0
3
ksinghg
I'm running into an issue where I am receiving a flood of emails for an alert. The alert works as expected when I al...
by ksinghg Engager in Splunk Search 07-18-2018
0 0
0
0
snigdhasaxena
I have tried using bin command but as index=test| bin span=1w _time | chart count as total_count by _time, action B...
by snigdhasaxena Communicator in Splunk Search 07-18-2018
0 1
0
1
dkorlat
I'm unable to create a regex that captures the first 6 characters of a mac address and removes the hyphen characters....
by dkorlat Explorer in Splunk Search 07-18-2018
0 4
0
4
Uday_Gonti
Ex: sourcetype=abcd [search sourcetype=xyz field1=200 | table field2,field3,field4] which will be literally sourc...
by Uday_Gonti New Member in Splunk Search 07-18-2018
0 2
0
2
snigdhasaxena
I have tried using bin command but as index=test| bin span=1w _time | chart count as total_count by _time, action ...
by snigdhasaxena Communicator in Splunk Search 07-18-2018
0 2
0
2
zikpefu
I am trying to remove the +'s in between words for my table (i.e. stainless+steel to be just stainless steel) and my ...
by zikpefu New Member in Splunk Search 07-18-2018
0 2
0
2
robgarner
A user has a dashboard made of multiple searches all based on the last 24 hours of a single very large index. Some p...
by robgarner Path Finder in Splunk Search 07-18-2018
0 7
0
7
splunker969
Hi Splunk members, How Can I get some metrics to indicate things like search concurrency, search queue depth, cancel...
by splunker969 Communicator in Splunk Search 07-18-2018
0 2
0
2
Chandras11
Hi All, I have 2 sourcetypes as following:- Sourcetype_A Ticket | Main_Ticket | Value | Line | LinkedTicket Sou...
by Chandras11 Communicator in Splunk Search 07-18-2018
0 4
0
4
john_q
i want to count eventcount comparison using time trends chart for today , lastweek and last2weeks. below are the my s...
by john_q Explorer in Splunk Search 07-17-2018
0 3
0
3
andrehl
index="stage" |stats dc(customers_name) as "Distinct Customer" by sku_name sku_number |rename sku_name as Product sku...
by andrehl Explorer in Splunk Search 07-17-2018
0 3
0
3
tmmet
Hi, Could anyone please provide some information on the below? If you have an excel/csv file with server health det...
by tmmet New Member in Splunk Search 07-17-2018
0 5
0
5
mfrost8
I'm trying to use a search that looks like index=<index> sourcetype=<sourcetype> | eval site=<site> | lookup host_an...
by mfrost8 Builder in Splunk Search 07-17-2018
0 2
0
2
mcm10285
Hi, anybody has an idea on how to get a value from one search and input it to another search, then display them in a ...
by mcm10285 Communicator in Splunk Search 07-17-2018
1 9
1
9
ixixix_spl
I am looking to perform a case match search and have found that this query template attempted to answer how to define...
by ixixix_spl Explorer in Splunk Search 07-17-2018
0 3
0
3
keekkenen
Hi, all for example, I want find all transactions contains some word. How to make it more faster ? If I have too mu...
by keekkenen Engager in Splunk Search 07-17-2018
0 6
0
6
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors