Splunk Search

Splunk Search
Community Activity
landen99
I want to click on an entry in a table and see the record or records behind it in a new window. I found one question ...
by landen99 Motivator in Splunk Search 05-10-2018
1 17
1
17
jiaqya
I have a file to index which has a date field ( currentdate) . How to configure the input regex so as to use this fie...
by jiaqya Builder in Splunk Search 05-10-2018
0 2
0
2
nabeel652
I have two tables in a dashboard, The top one lists all the WAN links and the bottom one shows the detailed link util...
by nabeel652 Builder in Splunk Search 05-10-2018
0 2
0
2
jeffsegal
I am trying to create a report that would tell me if an item that should be available within a certain timeframe (i.e...
by jeffsegal Explorer in Splunk Search 05-09-2018
0 7
0
7
andrewbeak
Hi, I'm using JSON extract on my rows. I want to use the value that is contained in "message.time" instead of _time...
by andrewbeak Path Finder in Splunk Search 05-09-2018
0 11
0
11
Chandras11
Hi Everyone, I have a very small conceptual doubt. Does the eval case do case insensitive compare or will it compare...
by Chandras11 Communicator in Splunk Search 05-09-2018
0 5
0
5
mkoh
If I search, I can see the count value of each field for one minute, and also want to know the sum count value 10 min...
by mkoh New Member in Splunk Search 05-09-2018
0 4
0
4
pavanae
I have a query as follows index=abc sourcetype=def | stats count by field_A | eval mb=round(count/1024/1024,2) whi...
by pavanae Builder in Splunk Search 05-09-2018
0 2
0
2
gilbxrtx_7
I want to create a field which extract values, however I have some field values that I want to extract which contain ...
by gilbxrtx_7 New Member in Splunk Search 05-09-2018
0 12
0
12
rakeshyv0807
Hi - I have a query where it results in total number of results of number of people logged into an application and I...
by rakeshyv0807 Explorer in Splunk Search 05-09-2018
0 8
0
8
sachinsingh2005
I have total 12 hosts which are coming through my sourcetype (input) and are below: UK1 App Server 1 UK1 App Server ...
by sachinsingh2005 Explorer in Splunk Search 05-09-2018
0 9
0
9
dwong2
.....search | eval Type=case(like(publishId,"%U"),"unsubscribed",like(publishId,"%S"),"subscribed") | stats count by...
by dwong2 New Member in Splunk Search 05-09-2018
0 4
0
4
sarathipattam
Hi, below is my query index_ sourcetype=main | stats count(eval(level="Error")) as ERRORS count(eval(level="Inform...
by sarathipattam New Member in Splunk Search 05-09-2018
0 3
0
3
pavanae
I have a query as below field_A!="A" AND (field_B="abc" OR field_B="def" OR field_B="ghi" OR field_B="jkl" OR field...
by pavanae Builder in Splunk Search 05-09-2018
0 1
0
1
bscavotto
I have a powershell script that audits some files and creates an Windows application event log with the filepaths of ...
by bscavotto New Member in Splunk Search 05-09-2018
0 5
0
5
harry2007gsp
I have multiple searches in splunk which use the same lookup table. Is it possible I can check among all the searches...
by harry2007gsp Path Finder in Splunk Search 05-09-2018
0 3
0
3
bruno_eduardo
I need to remove a list of servers from my search. This list changes once a month so I thought of using a lookup tabl...
by bruno_eduardo Path Finder in Splunk Search 05-09-2018
0 6
0
6
DTERM
The following is a sample entry from a splunk index... lastOccurrence=2012-06-25 18:42:38.0|firstOccurrence=2012-06-...
by DTERM Contributor in Splunk Search 05-09-2018
0 7
0
7
pavanae
I have two different queries like below Query 1 :- field_1!="A" AND field_2="B" OR field_1!="A" AND field_2="C" OR ...
by pavanae Builder in Splunk Search 05-09-2018
0 2
0
2
Splunkster45
I have a value a_b_c. How do I extract the last '_' item. So in this case it'd be 'c'. The number of of underscores i...
by Splunkster45 Communicator in Splunk Search 05-09-2018
0 2
0
2
cdion3537
I need to be able to compare report results over the period of a time. The report itself takes minutes to run for a 1...
by cdion3537 New Member in Splunk Search 05-09-2018
0 1
0
1
Skins
Looking to do a search which shows start time and end time when _raw events were 0 over a say 24hr period. Trying to...
by Skins Path Finder in Splunk Search 05-09-2018
0 5
0
5
rashid47010
I have I want to send windows logs through heavy forwarder to indexer. on windows server, I install universal forwa...
by rashid47010 Communicator in Splunk Search 05-09-2018
0 8
0
8
auaave
Hey Guys, I have a daily report that is showing the # of orders planned and completed for the day. However, sometime...
by auaave Communicator in Splunk Search 05-08-2018
0 3
0
3
Harishma
Can someone please explain in simple layman terms how Splunk SEARCHES Hadoop Data? I understand it doesn't store them...
by Harishma Communicator in Splunk Search 05-08-2018
1 2
1
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...