Splunk Search

Splunk Search
Community Activity
brosselle
I'm currently using this in a search: index=OS sourcetype=cpu | timechart avg(pctIdle) by host This typically gives ...
by brosselle New Member in Splunk Search 06-19-2018
0 3
0
3
link22
So I want to get the stats count of two search terms in a search that looks like this: index=myIndex "searchTermA" OR...
by link22 Explorer in Splunk Search 06-19-2018
0 2
0
2
link22
So I'm aiming for a month's worth of data to be displayed as "Week 1, Week 2, Week 3, Week 4" instead of by "Apr 13, ...
by link22 Explorer in Splunk Search 06-19-2018
0 3
0
3
at1ll3y
Hello community, I'm currently building an application for a customer. Since the needs of the customer are steadily ...
by at1ll3y New Member in Splunk Search 06-19-2018
0 1
0
1
dswanson99
Hi, I was in the process of changing the index that certain events write to and came across a problem with a query I...
by dswanson99 Path Finder in Splunk Search 06-19-2018
1 6
1
6
link22
I have the x axis of my search displaying by week however I do not want this format: Apr 23 Apr 30 etc. I have my c...
by link22 Explorer in Splunk Search 06-19-2018
0 3
0
3
griggsy
Hello, I have a tstats query running which returns the data. I then want to look up the username returned as part of...
by griggsy New Member in Splunk Search 06-19-2018
0 11
0
11
xvxt006
Hi i would like to get the commands from the below pattern. For example i am looking for search, content, gcom.sugges...
by xvxt006 Contributor in Splunk Search 06-19-2018
0 4
0
4
darshildave
I want to use group by aggregate function with a field called "field1". Some events in my data donot consists of thi...
by darshildave Explorer in Splunk Search 06-19-2018
0 1
0
1
samlinsongguo
Hey I want to create a field with a time value using following commend | inputlookup task_time_worked.csv | eval de...
by samlinsongguo Communicator in Splunk Search 06-19-2018
0 3
0
3
skelly99
Hi - I am try to build a saved search that has conditions so that the full search only executes when all conditions a...
by skelly99 Explorer in Splunk Search 06-19-2018
0 0
0
0
ppanchal
index=adjusted| eval Variance=TOTAL_PAID_DRVR_MINUTE_CNT-PLAN_PAID_DRVR_MINUTE_CNT|eval test=if(Variance>=120,[search...
by ppanchal Path Finder in Splunk Search 06-18-2018
0 1
0
1
ejans100
Hi, I'm trying to see if there is an easy way to take a result from event error codes, attempting to logon a disabled...
by ejans100 Observer in Splunk Search 06-18-2018
0 1
0
1
Murali2888
Hi All, I need to lookup a value on three different kvstore fields based on its regex format. Is it possible to pass...
by Murali2888 Communicator in Splunk Search 06-18-2018
0 0
0
0
jenniferhao
I have some back_end jobs that were scheduled by cron with timeout. for example: flock -w 7200 mylock xxxx/splunkjo...
by jenniferhao Explorer in Splunk Search 06-18-2018
0 1
0
1
mugilbala
I have following log statements. 2018-06-15 14:29:04,866 GMT DEBUG (inbound-8080-205|E:APP_**12345**|R:Qka4dqva8p9TQ...
by mugilbala Engager in Splunk Search 06-18-2018
0 5
0
5
JakeInfoSec
I'm currently trying to work with a csv lookup table that has the following columns. Susp_IP, Ticket_num, date_last_s...
by JakeInfoSec Explorer in Splunk Search 06-18-2018
0 2
0
2
lhanich1
I am running queries that have results, yet the results section is blank and will not render the logs. I have a whit...
by lhanich1 Path Finder in Splunk Search 06-18-2018
0 0
0
0
jacqu3sy
Is it possible to convert the following into an epoch timestamp using strptime; 2018-05-31T06:49:13Z Or will I need...
by jacqu3sy Path Finder in Splunk Search 06-18-2018
0 2
0
2
navd
I have some strings appearing in the events , i want to extract them ,it doesnt have any keyvalue pair sample event ...
by navd New Member in Splunk Search 06-18-2018
0 3
0
3
nadirriyani
I have followed below link but not receiving expected result. Step 1 Commands.conf [shape] chunked=true filename = s...
by nadirriyani New Member in Splunk Search 06-17-2018
0 2
0
2
Sfry1981
I have a search like this where it brings back a history of an event based on the guid. The last event has the inform...
by Sfry1981 Communicator in Splunk Search 06-17-2018
0 3
0
3
aayushr
I have a very limited knowledge of splunk. I am trying to parse json data containing an array and plot it on a bargra...
by aayushr New Member in Splunk Search 06-16-2018
0 1
0
1
pbarbuto
Depending on what month it is I need to run a different sub-search. index=foo source=bar [| inputlookup servers...
by pbarbuto Path Finder in Splunk Search 06-16-2018
0 1
0
1
krish318
Hi, index="testdb" sourcetype="audt" | table Command, Duration | sort Duration | search Duration>=60. This search c...
by krish318 New Member in Splunk Search 06-16-2018
0 7
0
7
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...