Splunk Search

Splunk Search
Community Activity
navd
I want to extract a field from the log event using regex .following is the sample log event , can someone tell me how...
by navd New Member in Splunk Search 06-19-2018
0 1
0
1
DerBastler
Hey there. This isn't a specific code question but rather a more general question regarding limitations of lookups. F...
by DerBastler New Member in Splunk Search 06-19-2018
0 2
0
2
zhatsispgx
Hi all, I have the following data being indexed by splunk: POST /somendpoint.asmx HTTP/1.1 Host: somehost Connect...
by zhatsispgx Path Finder in Splunk Search 06-19-2018
0 2
0
2
ErikaE
I'm looking for an efficient way to build multiple parent child event pairs into a flat string of parent,children,gra...
by ErikaE Communicator in Splunk Search 06-19-2018
1 2
1
2
link22
I would like to have a chart that shows the different values (I used a unique field extraction for this) found and di...
by link22 Explorer in Splunk Search 06-19-2018
0 2
0
2
patb23
[updated the question based on feedback] I am trying to join events from these 2 log entries Events of Type 1 dateTi...
by patb23 Engager in Splunk Search 06-19-2018
0 4
0
4
brosselle
I'm currently using this in a search: index=OS sourcetype=cpu | timechart avg(pctIdle) by host This typically gives ...
by brosselle New Member in Splunk Search 06-19-2018
0 3
0
3
link22
So I want to get the stats count of two search terms in a search that looks like this: index=myIndex "searchTermA" OR...
by link22 Explorer in Splunk Search 06-19-2018
0 2
0
2
link22
So I'm aiming for a month's worth of data to be displayed as "Week 1, Week 2, Week 3, Week 4" instead of by "Apr 13, ...
by link22 Explorer in Splunk Search 06-19-2018
0 3
0
3
at1ll3y
Hello community, I'm currently building an application for a customer. Since the needs of the customer are steadily ...
by at1ll3y New Member in Splunk Search 06-19-2018
0 1
0
1
dswanson99
Hi, I was in the process of changing the index that certain events write to and came across a problem with a query I...
by dswanson99 Path Finder in Splunk Search 06-19-2018
1 6
1
6
link22
I have the x axis of my search displaying by week however I do not want this format: Apr 23 Apr 30 etc. I have my c...
by link22 Explorer in Splunk Search 06-19-2018
0 3
0
3
griggsy
Hello, I have a tstats query running which returns the data. I then want to look up the username returned as part of...
by griggsy New Member in Splunk Search 06-19-2018
0 11
0
11
xvxt006
Hi i would like to get the commands from the below pattern. For example i am looking for search, content, gcom.sugges...
by xvxt006 Contributor in Splunk Search 06-19-2018
0 4
0
4
darshildave
I want to use group by aggregate function with a field called "field1". Some events in my data donot consists of thi...
by darshildave Explorer in Splunk Search 06-19-2018
0 1
0
1
samlinsongguo
Hey I want to create a field with a time value using following commend | inputlookup task_time_worked.csv | eval de...
by samlinsongguo Communicator in Splunk Search 06-19-2018
0 3
0
3
skelly99
Hi - I am try to build a saved search that has conditions so that the full search only executes when all conditions a...
by skelly99 Explorer in Splunk Search 06-19-2018
0 0
0
0
ppanchal
index=adjusted| eval Variance=TOTAL_PAID_DRVR_MINUTE_CNT-PLAN_PAID_DRVR_MINUTE_CNT|eval test=if(Variance>=120,[search...
by ppanchal Path Finder in Splunk Search 06-18-2018
0 1
0
1
ejans100
Hi, I'm trying to see if there is an easy way to take a result from event error codes, attempting to logon a disabled...
by ejans100 Observer in Splunk Search 06-18-2018
0 1
0
1
Murali2888
Hi All, I need to lookup a value on three different kvstore fields based on its regex format. Is it possible to pass...
by Murali2888 Communicator in Splunk Search 06-18-2018
0 0
0
0
jenniferhao
I have some back_end jobs that were scheduled by cron with timeout. for example: flock -w 7200 mylock xxxx/splunkjo...
by jenniferhao Explorer in Splunk Search 06-18-2018
0 1
0
1
mugilbala
I have following log statements. 2018-06-15 14:29:04,866 GMT DEBUG (inbound-8080-205|E:APP_**12345**|R:Qka4dqva8p9TQ...
by mugilbala Engager in Splunk Search 06-18-2018
0 5
0
5
JakeInfoSec
I'm currently trying to work with a csv lookup table that has the following columns. Susp_IP, Ticket_num, date_last_s...
by JakeInfoSec Explorer in Splunk Search 06-18-2018
0 2
0
2
lhanich1
I am running queries that have results, yet the results section is blank and will not render the logs. I have a whit...
by lhanich1 Path Finder in Splunk Search 06-18-2018
0 0
0
0
jacqu3sy
Is it possible to convert the following into an epoch timestamp using strptime; 2018-05-31T06:49:13Z Or will I need...
by jacqu3sy Path Finder in Splunk Search 06-18-2018
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...