Splunk Search

Splunk Search
Community Activity
Maniteja81
Hi, I have two queries, one gives me the test-case names, test-id details and lsf jobid details. Another query gives...
by Maniteja81 New Member in Splunk Search 06-07-2018
0 2
0
2
jfeitosa_real
Hi all, Please help me! How to create a search with the percentage of desktops with outdated antivirus. Since events...
by jfeitosa_real Path Finder in Splunk Search 06-07-2018
0 1
0
1
kiamco
so I have this query that detects anomalies in the errors from a specific source based on the mean absolute value of ...
by kiamco Path Finder in Splunk Search 06-07-2018
0 1
0
1
ramki1459
For example: raw data is 100,x,info=1,error=1,warn=1 101,x,info=1,error=1,warn=1 101,y,info=1,error=2,warn=1 101,y,...
by ramki1459 Explorer in Splunk Search 06-07-2018
0 2
0
2
Vigneshprasanna
Hi Team, I'm Facing issue in designing a query for the following requirement : Sample data : Test data : 2017-08...
by Vigneshprasanna Explorer in Splunk Search 06-07-2018
0 4
0
4
zacksoft
I have a query that end with | table jra_conn bam_conn bib_conn jra_conn, bam_conn, bib_conn are not Splunk fields...
by zacksoft Contributor in Splunk Search 06-07-2018
0 13
0
13
Valdemir_Splunk
I have a Dashboard that when i open in the search app it show the results quickly, but when i open in other one it ta...
by Valdemir_Splunk Explorer in Splunk Search 06-07-2018
0 1
0
1
btoomey
When I run the query search index=* sourcetype="XXX" earliest=-7d@d latest=-6d@d | stats count via the REST API, I ge...
by btoomey New Member in Splunk Search 06-07-2018
0 0
0
0
sanurd
Hello, I indexed data using files and directory monitor to index multiple files in a folder. I later deleted the dat...
by sanurd Path Finder in Splunk Search 06-07-2018
2 3
2
3
DEAD_BEEF
I have a numeric field that needs to be string to put be CIM compliant. I tried using tostring, but it still shows u...
by DEAD_BEEF Builder in Splunk Search 06-07-2018
0 0
0
0
Bentash
I have about 4 different tables that i am trying to join table 1 and table two have a common id, sys_id and when yo...
by Bentash Explorer in Splunk Search 06-07-2018
0 2
0
2
tchintam
I used this query: index="abc" source="xyz" | search [inputlookup example] | eval End=strptime("End_Date_Time","%Y/%...
by tchintam Path Finder in Splunk Search 06-07-2018
0 22
0
22
kwanx
Hello - searched, but no answer found. ...| return 10 "Name of Field" Gives: Name="" of="" Field="" I know that ...
by kwanx Explorer in Splunk Search 06-07-2018
0 9
0
9
Rajkumarkbm22
Dear Experts, Please provide a valuable solution for my problem. I am having the fields from JSON which is having mu...
by Rajkumarkbm22 New Member in Splunk Search 06-07-2018
0 3
0
3
evinasco
Hi team i would like to use something like that | eval foo=if(like(Description,"%[search index=prueba | fields u_id_...
by evinasco Communicator in Splunk Search 06-07-2018
0 2
0
2
msarro
Just curious about this. Most of the regular expressions I see splunk use look nothing like standard/posix regular ex...
by msarro Builder in Splunk Search 06-07-2018
4 8
4
8
tchintam
My query is: search[|inputlookup abc | stats count(Numbers) as sum| eval end=strptime(End_Date_Time,"%Y/%m/%d %H:%M:...
by tchintam Path Finder in Splunk Search 06-07-2018
0 4
0
4
RobertRi
Hi! I get sometimes messages that some savedsearches are skipped. The only information what I get is an event in th...
by RobertRi Communicator in Splunk Search 06-07-2018
0 2
0
2
angersleek
I am trying to combine the results from 2 different search queries into a single time chart. I am using "Shared Time ...
by angersleek Path Finder in Splunk Search 06-07-2018
0 1
0
1
Bentash
Using | where _time>=info_min_time AND (_time<=info_max_time OR info_max_time="+Infinity") on a .csv to be able to se...
by Bentash Explorer in Splunk Search 06-07-2018
0 12
0
12
Rajkumarkbm2
Hi , I want to expand as erach event for the attached example
by Rajkumarkbm2 Explorer in Splunk Search 06-07-2018
0 2
0
2
criedman
Hi, i want to search the events from the last 10 minutes based on the secondary datetime field from a event. Normal...
by criedman Explorer in Splunk Search 06-07-2018
0 2
0
2
JRamirezEnosys
Hello Splunkers, I've been trying to show in a Single Value Visualization 3 different percentage values. My search ...
by JRamirezEnosys Explorer in Splunk Search 06-07-2018
0 5
0
5
manuarora12
I have events event_starttime, event_endtime, event_duration, event_name I want chart of events falling in common ti...
by manuarora12 New Member in Splunk Search 06-07-2018
0 3
0
3
tmwhitm
Looking for assistance in creating a lookup table with UrLs, my syntax below does not work. Any ideas on how to use a...
by tmwhitm New Member in Splunk Search 06-07-2018
0 4
0
4
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...