Splunk Search

Splunk Search
Community Activity
adamfiore
I am trying to create a search that returns only those events that have a specific username (or part of a username) i...
by adamfiore Explorer in Splunk Search 06-27-2018
0 4
0
4
msmapper
I have created a new log message that looks like 2018-06-27 11:28:01,743 WARN TestReporting , id="LJ99YUT5F1K", tra...
by msmapper Path Finder in Splunk Search 06-27-2018
0 3
0
3
ayela
Hi everyone, Recently I faced some issues when I try to do an advance search. My problem : I need to create table th...
by ayela Engager in Splunk Search 06-27-2018
0 6
0
6
pierre_weg
Hi all! I have a table as a search result: date Country cs_username 2018-06-12 Mexico mendoza 2018-06-12 Mexi...
by pierre_weg Path Finder in Splunk Search 06-27-2018
0 2
0
2
tonahoyos
Hello, I want to be able to ignore days where data was not collected. I am using the following search: index="x" | ...
by tonahoyos Explorer in Splunk Search 06-27-2018
0 3
0
3
vincenp2
does anyone know where I might be able to find a 'dummies' guide to autolookup, with a simple example if possible? I ...
by vincenp2 New Member in Splunk Search 06-27-2018
0 1
0
1
scottkurtosys
Hi I am trying to transform a couple of strings that are being capture in my Splunk logs The string are similar to ...
by scottkurtosys New Member in Splunk Search 06-27-2018
0 5
0
5
joydeep741
I want to get a value from subsearch assigned to outer search. I am trying like this index=OUTER sourcetype=OUTER_ST...
by joydeep741 Path Finder in Splunk Search 06-27-2018
0 3
0
3
Neur0mencer
Hello Splunkers! For some time I'm trying to figure out how to feed results of a DNS blacklist check versus DHCP log...
by Neur0mencer Explorer in Splunk Search 06-27-2018
0 3
0
3
andrewtrobec
Hello, I have a string field containing many words and I would like to remove all 1 and 2 character words from it. H...
by andrewtrobec Motivator in Splunk Search 06-27-2018
0 2
0
2
Chandras11
HI All, I need to give input from search1 to search2 and then get a single result from search 2 with the values from...
by Chandras11 Communicator in Splunk Search 06-27-2018
0 7
0
7
snayani
I have been trying to prepare pie chart with proper stats on types of database errors. For some unknown reasons, I am...
by snayani Explorer in Splunk Search 06-27-2018
0 4
0
4
angersleek
How do I pass in a default value for a single value chart? As in I am not looking to search anything for now in the ...
by angersleek Path Finder in Splunk Search 06-27-2018
0 2
0
2
jhigginsmq
We have a dashboard that lists a series of events representing alarms that need to be 'cleared' by the user as non-is...
by jhigginsmq Path Finder in Splunk Search 06-27-2018
0 0
0
0
gbwilson
I have a regex that should remove everything after a second underscore. When I try to search with the regex, it does...
by gbwilson Path Finder in Splunk Search 06-27-2018
0 3
0
3
pstamati
Hello everyone, I have this field with values that are retrieved withing "" but not separated by any character, and I...
by pstamati Path Finder in Splunk Search 06-27-2018
0 10
0
10
mcohen13
i have two indexes: index#1 contain raw event log. from this event log i calc for every domain the number of events s...
by mcohen13 Loves-to-Learn in Splunk Search 06-26-2018
0 3
0
3
nls7010
This is the search I used: |rest /services/authentication/users splunk_server=local |fields title |rename title ...
by nls7010 Path Finder in Splunk Search 06-26-2018
0 2
0
2
dhruv101
Hi, I have a simple checkbox as shown below - <input type="checkbox" token="eventtype" searchWhenChanged="true"> ...
by dhruv101 Path Finder in Splunk Search 06-26-2018
0 1
0
1
wills2g
Hi All, To give some context, the return function in Splunk when used with a subsearch allows you to drop the field ...
by wills2g New Member in Splunk Search 06-26-2018
0 3
0
3
eandres
I would like to plot all of my locations on a map, with an individual marker for each one. I know there is binspanlat...
by eandres Explorer in Splunk Search 06-26-2018
0 0
0
0
matthew_foos
Splunkers, Looking for a search string that will allow me to use the time picker to see how much data has been index...
by matthew_foos Path Finder in Splunk Search 06-26-2018
0 3
0
3
jkalra
I want to be able to pass multiple values to a field in a dashboard "Endpoint" . Like in the Endpoint Input I want to...
by jkalra Explorer in Splunk Search 06-26-2018
0 2
0
2
LVogeding
These are the errors I am getting: The lookup table 'endpoint_change_object_category_lookup' does not exist. It is r...
by LVogeding New Member in Splunk Search 06-26-2018
0 9
0
9
ppatrikfr
Hello splunkers, i'm gonna try to be short, I'm trying to create an HTML homepage for Splunk APP and I've been trying...
by ppatrikfr Path Finder in Splunk Search 06-26-2018
0 4
0
4
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...