Splunk Search

Splunk Search
Community Activity
ronnybruska
Hi there, i created a table: Date | Value1 | Value2 | Percentage The last line should be: "total" | total of Valu...
by ronnybruska New Member in Splunk Search 05-11-2018
0 2
0
2
garujoey
Hi there, I am a newbie in Splunk and trying to do some search using the rex. The log body is like: blah blah Dest...
by garujoey Engager in Splunk Search 05-10-2018
0 6
0
6
mjones414
I'm trying to add more specific data to a particular field by replacing it with another value when other conditions e...
by mjones414 Contributor in Splunk Search 05-10-2018
0 1
0
1
Splunk_rocks
I need to construct props and transforms for below sample search. index=blaa sourcetype=my_source | rex field=X__Ed...
by Splunk_rocks Path Finder in Splunk Search 05-10-2018
0 11
0
11
santosh_hb
I am getting the following error due to which, the log file is not getting indexed daily. Log file name is like: db...
by santosh_hb Explorer in Splunk Search 05-10-2018
0 5
0
5
brdr
I have a lookup table with 3 fields: host, user, p_time The events in the lookup table will contain 12 months of dat...
by brdr Contributor in Splunk Search 05-10-2018
1 6
1
6
jon_d_irish_ctr
I want to setup a search that determines which countries have connected to my network over the past "x" hours, and th...
by jon_d_irish_ctr Path Finder in Splunk Search 05-10-2018
0 7
0
7
skallaje
So, I have this following format for my log entries. FIELD1-FIELD2-FIELD3-FIELD4-FIELD5-FIELD6 and logs are like .....
by skallaje Engager in Splunk Search 05-10-2018
0 2
0
2
macadminrohit
This is my regex : Test Name\","value":"(?.*)},{"key" and my test string is : {"key":"Test Name","value":"GET:Corp...
by macadminrohit Contributor in Splunk Search 05-10-2018
0 4
0
4
vrmandadi
I am trying to do field extraction from the _time only the month,date and year but just not getting it.I know strftim...
by vrmandadi Builder in Splunk Search 05-10-2018
0 7
0
7
vikramyadav
When I login I get too many logon events. How do I filter successful events? This is the query:- index="wineventlog"...
by vikramyadav Contributor in Splunk Search 05-10-2018
2 1
2
1
jyotirmayee_tri
I am getting duplicate logs from particular index , please let me know how to rectify this.
by jyotirmayee_tri New Member in Splunk Search 05-10-2018
0 1
0
1
oliverj
I have 2 sites configured with a multisite cluster. Site 1: Indexer, manager, independent search head. Site 1: Indexe...
by oliverj Communicator in Splunk Search 05-10-2018
0 5
0
5
RRajneesh
Hi, I have the below output : "(|01/01/16|01/01/18|01/05/18|04/02/18|05/01/17|05/05/16|05/08/17|)" The desired ou...
by RRajneesh New Member in Splunk Search 05-10-2018
0 4
0
4
sarwshai
This is the eval statement i am using along with case but getting error. eval total=case(critical>0 AND high>0,criti...
by sarwshai Communicator in Splunk Search 05-10-2018
0 10
0
10
aamirs291
Everyone, The events on splunk for me have data in the following format : ticket_num,actual_start_time,finish_time...
by aamirs291 Path Finder in Splunk Search 05-10-2018
0 5
0
5
wvalente
Hi guys, I have to configure the timespan to roll data to warm, cold and frozen. The question is: How can configur...
by wvalente Explorer in Splunk Search 05-10-2018
0 4
0
4
landen99
I want to click on an entry in a table and see the record or records behind it in a new window. I found one question ...
by landen99 Motivator in Splunk Search 05-10-2018
1 17
1
17
jiaqya
I have a file to index which has a date field ( currentdate) . How to configure the input regex so as to use this fie...
by jiaqya Builder in Splunk Search 05-10-2018
0 2
0
2
nabeel652
I have two tables in a dashboard, The top one lists all the WAN links and the bottom one shows the detailed link util...
by nabeel652 Builder in Splunk Search 05-10-2018
0 2
0
2
jeffsegal
I am trying to create a report that would tell me if an item that should be available within a certain timeframe (i.e...
by jeffsegal Explorer in Splunk Search 05-09-2018
0 7
0
7
andrewbeak
Hi, I'm using JSON extract on my rows. I want to use the value that is contained in "message.time" instead of _time...
by andrewbeak Path Finder in Splunk Search 05-09-2018
0 11
0
11
Chandras11
Hi Everyone, I have a very small conceptual doubt. Does the eval case do case insensitive compare or will it compare...
by Chandras11 Communicator in Splunk Search 05-09-2018
0 5
0
5
mkoh
If I search, I can see the count value of each field for one minute, and also want to know the sum count value 10 min...
by mkoh New Member in Splunk Search 05-09-2018
0 4
0
4
pavanae
I have a query as follows index=abc sourcetype=def | stats count by field_A | eval mb=round(count/1024/1024,2) whi...
by pavanae Builder in Splunk Search 05-09-2018
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors