Splunk Search

Splunk Search
Community Activity
Log_wrangler
I am trying to monitor an application where remote users with different GeoLoc(s) and unique sourceIP(s) login and in...
by Log_wrangler Builder in Splunk Search 07-11-2018
0 9
0
9
danielwysockiar
Hi, I'm trying to find least common agent useing two commands: 1) sourcetype=access_combined| rare useragent 2) sou...
by danielwysockiar Explorer in Splunk Search 07-11-2018
0 5
0
5
gokulakrishnans
I've followed http://docs.splunk.com/Documentation/Splunk/latest/User/CreateAndConfigureFieldLookups and looked at pl...
by gokulakrishnans Explorer in Splunk Search 07-11-2018
1 2
1
2
JeffBothel
What I am looking to do is something of this nature: | stats count(eval(if(action=success))), count(eval(if(action=f...
by JeffBothel Explorer in Splunk Search 07-11-2018
1 8
1
8
sepkarimpour
Currently, I have a search where I'm looking for a specific string in a set of logs across a large number of hosts (6...
by sepkarimpour Path Finder in Splunk Search 07-11-2018
0 11
0
11
perfecto25
FYI, posting our config setting to make a 3-node Splunk SH cluster work with HAProxy (1.5.18) using pure TCP and usin...
by perfecto25 Path Finder in Splunk Search 07-11-2018
0 0
0
0
joydeep741
I have a search index=abc sourcetype=xyz | bucket created_time span=1w | stats count by date_epoch | eval date_reada...
by joydeep741 Path Finder in Splunk Search 07-11-2018
0 8
0
8
evuk
I want to query splunk so that it can find all index names that do not have _ at the beginning and query for the max(...
by evuk Engager in Splunk Search 07-11-2018
0 8
0
8
abhisheks2412
I am trying to use transaction command to correlate two event types. I need to correlate events based on value in "id...
by abhisheks2412 New Member in Splunk Search 07-11-2018
0 3
0
3
Naaba
Hi, I have this SPL request in a search : index=<my_index> (url_host="yqe-tractors.stenchkrzl.xyz" OR url_host="ste...
by Naaba New Member in Splunk Search 07-11-2018
0 0
0
0
abhi04
How to capture all the below in one variable using Regex. Below is the sample. Each line is a separate value and in a...
by abhi04 Communicator in Splunk Search 07-11-2018
0 4
0
4
Grant007701
Hi, I'm trying to combine results of varying operating systems into one, for example: Microsoft Windows Server 2008...
by Grant007701 New Member in Splunk Search 07-11-2018
0 4
0
4
znaesh
Can you please advise, what do I do if my Splunk complains often (every couple minutes) in splunkd.log in production ...
by znaesh Path Finder in Splunk Search 07-11-2018
0 4
0
4
uddhav
Hi, I am planning to display the distinct count of users logged into Splunk today. I came across, following two sear...
by uddhav New Member in Splunk Search 07-11-2018
0 1
0
1
sh254087
I have a dashboard with a drop-down that will have a list of values populated to it. When the user selects a value fr...
by sh254087 Communicator in Splunk Search 07-11-2018
0 3
0
3
jip31
Hello I need help to display two curves in my chart and the 2 curves refer to host="$field1$ and host="$field2$ So I ...
by jip31 Motivator in Splunk Search 07-11-2018
0 3
0
3
nazanin2016
Hi, I wonder whether someone may be able to help me please. I have created in a separate search with a lookup table...
by nazanin2016 Path Finder in Splunk Search 07-11-2018
1 9
1
9
saranyaa21
Hi, City:{city1: 4, city2: 3, city3: 2, city4: 5} I used this regex to get the 3rd word from the above line: (?<"C...
by saranyaa21 Path Finder in Splunk Search 07-11-2018
0 16
0
16
Log_wrangler
I created this PART 2 as the previous thread is getting long. Recap: I am trying to monitor login behavior to an on...
by Log_wrangler Builder in Splunk Search 07-10-2018
0 0
0
0
Kendo213
Any ideas on how I can get around the 10k subsearch limit? This search is quick, and works fine, however I'm hitting...
by Kendo213 Communicator in Splunk Search 07-10-2018
0 5
0
5
kdimaria
I am trying to see the average users by day but when there are no events or users for a certain day the _time field d...
by kdimaria Communicator in Splunk Search 07-10-2018
0 2
0
2
navd
I have extracted the 500 error as "server_error" and I want to count the total number of server_error by host and sh...
by navd New Member in Splunk Search 07-10-2018
0 1
0
1
brdr
Is there a way I can continue my search when first search returns 0 events. Returning 0 events is a valid scenario in...
by brdr Contributor in Splunk Search 07-10-2018
0 2
0
2
laconix
Hello, I would like to perform a search that return only a particular field value for which i don't find in any othe...
by laconix New Member in Splunk Search 07-10-2018
0 9
0
9
satkumvnr
Hi dear Splunkers I have the following JSON given by a REST calling at Google Analytics: {"kind":"analytics#realtim...
by satkumvnr New Member in Splunk Search 07-10-2018
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...