Splunk Search

Splunk Search
Community Activity
john_q
i want to count eventcount comparison using time trends chart for today , lastweek and last2weeks. below are the my s...
by john_q Explorer in Splunk Search 07-17-2018
0 3
0
3
andrehl
index="stage" |stats dc(customers_name) as "Distinct Customer" by sku_name sku_number |rename sku_name as Product sku...
by andrehl Explorer in Splunk Search 07-17-2018
0 3
0
3
tmmet
Hi, Could anyone please provide some information on the below? If you have an excel/csv file with server health det...
by tmmet New Member in Splunk Search 07-17-2018
0 5
0
5
mfrost8
I'm trying to use a search that looks like index=<index> sourcetype=<sourcetype> | eval site=<site> | lookup host_an...
by mfrost8 Builder in Splunk Search 07-17-2018
0 2
0
2
mcm10285
Hi, anybody has an idea on how to get a value from one search and input it to another search, then display them in a ...
by mcm10285 Communicator in Splunk Search 07-17-2018
1 9
1
9
ixixix_spl
I am looking to perform a case match search and have found that this query template attempted to answer how to define...
by ixixix_spl Explorer in Splunk Search 07-17-2018
0 3
0
3
keekkenen
Hi, all for example, I want find all transactions contains some word. How to make it more faster ? If I have too mu...
by keekkenen Engager in Splunk Search 07-17-2018
0 6
0
6
m7787580
Hi Splunker, Originally I have an output like this as a raw event in Splunk:- 2018-07-17 14:56:08 MIR="TUE, 17-JUL-...
by m7787580 Explorer in Splunk Search 07-17-2018
0 2
0
2
ryan_t_gavin
For example, I have the field "received_files" with 3 values: 1, 2, and 3. I already ran "convert num(received_files...
by ryan_t_gavin New Member in Splunk Search 07-17-2018
0 0
0
0
Clovisa
Hello, I am trying to build a role that would allow the users to access to two indexes (index1 and index2). The inde...
by Clovisa Path Finder in Splunk Search 07-17-2018
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the following stats query. `wso2_wmf(RequestC...
by IRHM73 Motivator in Splunk Search 07-17-2018
1 6
1
6
gokikrishnan198
I would like to find a error occurs in the past 30, 60 and 90 days. How to do that?
by gokikrishnan198 New Member in Splunk Search 07-16-2018
0 1
0
1
flzhang132
In my dashBoard,i edit a table in sampleXML,then, The table is converted from sampleXML to HTML. and Converted code v...
by flzhang132 Explorer in Splunk Search 07-16-2018
0 1
0
1
naotoyoshida
I'm using Windows Universal Forwarder (UF) 7.1.2 in my test environment. Windows 2012 R2 (gets security event from R...
by naotoyoshida New Member in Splunk Search 07-16-2018
0 0
0
0
CryoHydra
Team, We have 3 different sourcetype on which endpoint/device are identified by different fieldname: sourcetype=x e...
by CryoHydra Path Finder in Splunk Search 07-16-2018
0 4
0
4
yagbootz48
Hello, I need some help. I'm trying to make a search where I take recipient_count and assign a "value" based on how...
by yagbootz48 New Member in Splunk Search 07-16-2018
0 3
0
3
SSchaff81
Hello splunk users, So I have a system that I am logging all errors to splunk. I have been getting a few false posi...
by SSchaff81 New Member in Splunk Search 07-16-2018
0 2
0
2
joydeep741
I have created a search to populate a lookup periodically. index x sourcetype=y | outputlookup abc.csv append=true ...
by joydeep741 Path Finder in Splunk Search 07-16-2018
0 2
0
2
aravindkv805
I have a requirement where I have to show the logs in splunk after an earlier search query. i.e Suppose I get a set o...
by aravindkv805 New Member in Splunk Search 07-16-2018
0 0
0
0
zhatsispgx
Hi there, I am trying to use the Python Splunk-SDK to query results from a search, and return a specific field that...
by zhatsispgx Path Finder in Splunk Search 07-16-2018
0 7
0
7
tjago11
Trying to find a consistent way of finding events that contain invalid JSON. We've ran into all sorts of different is...
by tjago11 Communicator in Splunk Search 07-16-2018
0 14
0
14
zikpefu
I am producing a table that will monitor what various users are searching for and I am trying to limit the amount of ...
by zikpefu New Member in Splunk Search 07-16-2018
0 2
0
2
jip31
hello i try to use the code below but everytimes i have an issue of quote or parenthesis even if i do modifications: ...
by jip31 Motivator in Splunk Search 07-16-2018
0 9
0
9
Mohsin123
Hi, I'm trying to assign the multivalue field ApixRes and RestRes to a new variable result . But , it isnt working a...
by Mohsin123 Path Finder in Splunk Search 07-16-2018
0 3
0
3
vwilson3
Greetings, I'm pretty new to Splunk. I have to create a search/alert and am having trouble with the syntax. This i...
by vwilson3 Path Finder in Splunk Search 07-16-2018
0 7
0
7
Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...