Splunk Search

Splunk Search
Community Activity
tchintam
Hi, I'm using a lookup which stores maintenance periods and can be used to exclude events of downtime from my main q...
by tchintam Path Finder in Splunk Search 06-07-2018
0 0
0
0
h52huang
My data model is like: Key Source Destination 1 a b 1 b c 1 a c 1 ...
by h52huang Path Finder in Splunk Search 06-07-2018
0 4
0
4
teddyidc1101
i have extracted this log as i need to get the search id to get the SPL used. this is a search that triggers an alert...
by teddyidc1101 Communicator in Splunk Search 06-07-2018
0 4
0
4
jvmerilla
Hi, Is this possible to do in spl? For example I have these fields: What I need to do is to arrange it in this ...
by jvmerilla Path Finder in Splunk Search 06-07-2018
0 2
0
2
dragut
I have constructed a responsetime field using eval resp=endtime-startime,now I want to get a list of percentiles from...
by dragut New Member in Splunk Search 06-07-2018
0 3
0
3
nk-1
Case 1: earliest=-1d@d latest=-0d@d ... | timechart span=1h count as Samples, avg(duration) as avg vs. Case 2: earlie...
by nk-1 Path Finder in Splunk Search 06-07-2018
0 2
0
2
zhatsispgx
Hi all, I am new to using lookups and I'm a bit confused. I've created a lookup file on my splunk instance called c...
by zhatsispgx Path Finder in Splunk Search 06-07-2018
0 4
0
4
kulsplunk
Hi there, I'm trying to join two indexes to get the id-value and ingest the data into main index. Here is my scenari...
by kulsplunk Explorer in Splunk Search 06-07-2018
0 3
0
3
jelli5518
Log files are: /audit/files/20180515041511.scc145.audit.log.1 /audit/files/20180515041511.scc145.audit.log.2 /audit/...
by jelli5518 Engager in Splunk Search 06-07-2018
0 3
0
3
gbwilson
I'm trying to create a stats table in Splunk that shows the IP of VMs and the IP of the Host that supports those VMs....
by gbwilson Path Finder in Splunk Search 06-07-2018
0 1
0
1
Maniteja81
Hi, I have two queries, one gives me the test-case names, test-id details and lsf jobid details. Another query gives...
by Maniteja81 New Member in Splunk Search 06-07-2018
0 2
0
2
jfeitosa_real
Hi all, Please help me! How to create a search with the percentage of desktops with outdated antivirus. Since events...
by jfeitosa_real Path Finder in Splunk Search 06-07-2018
0 1
0
1
kiamco
so I have this query that detects anomalies in the errors from a specific source based on the mean absolute value of ...
by kiamco Path Finder in Splunk Search 06-07-2018
0 1
0
1
ramki1459
For example: raw data is 100,x,info=1,error=1,warn=1 101,x,info=1,error=1,warn=1 101,y,info=1,error=2,warn=1 101,y,...
by ramki1459 Explorer in Splunk Search 06-07-2018
0 2
0
2
Vigneshprasanna
Hi Team, I'm Facing issue in designing a query for the following requirement : Sample data : Test data : 2017-08...
by Vigneshprasanna Explorer in Splunk Search 06-07-2018
0 4
0
4
zacksoft
I have a query that end with | table jra_conn bam_conn bib_conn jra_conn, bam_conn, bib_conn are not Splunk fields...
by zacksoft Contributor in Splunk Search 06-07-2018
0 13
0
13
Valdemir_Splunk
I have a Dashboard that when i open in the search app it show the results quickly, but when i open in other one it ta...
by Valdemir_Splunk Explorer in Splunk Search 06-07-2018
0 1
0
1
btoomey
When I run the query search index=* sourcetype="XXX" earliest=-7d@d latest=-6d@d | stats count via the REST API, I ge...
by btoomey New Member in Splunk Search 06-07-2018
0 0
0
0
sanurd
Hello, I indexed data using files and directory monitor to index multiple files in a folder. I later deleted the dat...
by sanurd Path Finder in Splunk Search 06-07-2018
2 3
2
3
DEAD_BEEF
I have a numeric field that needs to be string to put be CIM compliant. I tried using tostring, but it still shows u...
by DEAD_BEEF Builder in Splunk Search 06-07-2018
0 0
0
0
Bentash
I have about 4 different tables that i am trying to join table 1 and table two have a common id, sys_id and when yo...
by Bentash Explorer in Splunk Search 06-07-2018
0 2
0
2
tchintam
I used this query: index="abc" source="xyz" | search [inputlookup example] | eval End=strptime("End_Date_Time","%Y/%...
by tchintam Path Finder in Splunk Search 06-07-2018
0 22
0
22
kwanx
Hello - searched, but no answer found. ...| return 10 "Name of Field" Gives: Name="" of="" Field="" I know that ...
by kwanx Explorer in Splunk Search 06-07-2018
0 9
0
9
Rajkumarkbm22
Dear Experts, Please provide a valuable solution for my problem. I am having the fields from JSON which is having mu...
by Rajkumarkbm22 New Member in Splunk Search 06-07-2018
0 3
0
3
evinasco
Hi team i would like to use something like that | eval foo=if(like(Description,"%[search index=prueba | fields u_id_...
by evinasco Communicator in Splunk Search 06-07-2018
0 2
0
2
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...