Splunk Search

Splunk Search
Community Activity
jjryanjj
Running Splunk 6.2.4. Search results are displayed but message says "22 errors occured while the search was executing...
by jjryanjj New Member in Splunk Search 07-06-2018
0 9
0
9
mlevsh
One of our Splunk users is running the following search: index=customindex fieldip!=10.0.0.0/8 fieldip!="0.0.0.0" |...
by mlevsh Builder in Splunk Search 07-06-2018
0 3
0
3
Isaor
Hello, I do a alarm that detects 10 logins in one minute, but i need to detect this 10 logins from the same ip in 1 ...
by Isaor New Member in Splunk Search 07-06-2018
0 2
0
2
Ragate
I want to divide events in one field by events in another field that would then display in a dashboard as a single va...
by Ragate Explorer in Splunk Search 07-06-2018
0 2
0
2
dtakacssplunk
I would like to download all the jobs that are being executed currently / if possible in past. Something like the Jo...
by dtakacssplunk Explorer in Splunk Search 07-06-2018
0 1
0
1
aqudoos
Hi all! I am currently getting stats of current day as followed Port Count 25 25 443 75 53 990 I wan...
by aqudoos Explorer in Splunk Search 07-06-2018
0 3
0
3
gabarrygowin
Hi all, Struggling to get my Service Now times to evaluate just tickets older than 30 days. The date picker isn't p...
by gabarrygowin Path Finder in Splunk Search 07-06-2018
0 3
0
3
svemurilv
I had 2 different sourcetypes on each contains the Domain, hostname,ipaddress sourcer1 having data like. Domain...
by svemurilv Path Finder in Splunk Search 07-06-2018
0 3
0
3
Clovisa
Hi ! I am trying to display a timechart that gives the data of a week, and the data of the same week but one year ear...
by Clovisa Path Finder in Splunk Search 07-06-2018
0 3
0
3
NealM
Hi, I am completely new to Splunk and I have a specific need to address so please be patient with my newbie incompet...
by NealM New Member in Splunk Search 07-06-2018
0 5
0
5
memow8
Hi Pros, I want to merge results of two queries together and need some help in achieving the best possible way to do...
by memow8 New Member in Splunk Search 07-06-2018
0 1
0
1
drultima
I am trying to get a chart of IIS result codes (mapped as sc_status) and ignore crap data. For example, one of the r...
by drultima New Member in Splunk Search 07-06-2018
0 2
0
2
VI371887
Hi All, I am trying to group different errors that i have extracted to run transform commands, like stats, chart, e...
by VI371887 Path Finder in Splunk Search 07-06-2018
0 1
0
1
Mohsin123
Hi , Can I use an eval statement inside an if? I have to implement something like this : I have two fields : one ...
by Mohsin123 Path Finder in Splunk Search 07-06-2018
0 10
0
10
anurag0011
How to correlate events in ITSI ? New to Splunk ITSI Example CPU and DB alerts collection based on CI match . Cur...
by anurag0011 New Member in Splunk Search 07-05-2018
0 2
0
2
dhruv101
Hi, I am aware that an eval in the parent search cannot be used in a subsearch like this - | eval foo = ..... | e...
by dhruv101 Path Finder in Splunk Search 07-05-2018
0 1
0
1
dhruv101
Hello, How do I do something like this in splunk? eval base_starttime = [search index="app_event"| eval starttime =...
by dhruv101 Path Finder in Splunk Search 07-05-2018
0 2
0
2
dhruv101
Hi, I have a query with 5 joins but I am sure that this can be reduced to just one join. I cant figure out the syntax...
by dhruv101 Path Finder in Splunk Search 07-05-2018
0 0
0
0
bschaap
I'm trying to parse out the exception type and exception message from the DB Connect dbx_server logs. I'm having som...
by bschaap Path Finder in Splunk Search 07-05-2018
0 5
0
5
mmoermans
Hi there, trying to exclude some events through the use of a lookup but it's not working for some reason: index=mai...
by mmoermans Path Finder in Splunk Search 07-05-2018
0 3
0
3
pjdwyer
I am trying to see the events that have null values for a variable called 'Issuer', but I can't seem to find a way to...
by pjdwyer Explorer in Splunk Search 07-05-2018
0 7
0
7
brianMiller94
Hello, I am trying to show the last 5 minute count with a larger time period spark chart. index="iis" |stats sparkl...
by brianMiller94 Engager in Splunk Search 07-05-2018
0 2
0
2
Ragate
Hi. I have two sources that I am trying to merge and dedup similar data. They both have a license key, one was longer...
by Ragate Explorer in Splunk Search 07-05-2018
0 13
0
13
boppana
Hi , Currently am running below SPlunk Search Query where am using earliest=-0d@d latest=-2m. earliest=-0d@d latest...
by boppana New Member in Splunk Search 07-05-2018
0 4
0
4
joydeep741
I have a splunk query index=abc sourcetype=xyz | timechart by field1 This gives me data like _time column1 cloum...
by joydeep741 Path Finder in Splunk Search 07-05-2018
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...