Splunk Enterprise

Splunk Enterprise
Community Activity
bud4
I have two indexes having status of Batch jobs that run in our system daily. Source 1:  Contains JobName, StartTime, ...
by bud4 Engager in Splunk Enterprise 01-20-2023
0 1
0
1
Lu23
Hi everyone,I'm very new here. I need support with extracting  this field,  "safeframe.googlesyndication.com"  from "...
by Lu23 Observer in Splunk Enterprise 01-20-2023
0 5
0
5
chandankr
by chandankr Path Finder in Splunk Enterprise 01-20-2023
0 4
0
4
MT1234
Hello, I am new to Splunk and have testing purpose. I have installed Splunk within 30 days and installed the ITE cont...
by MT1234 Loves-to-Learn Lots in Splunk Enterprise 01-19-2023
0 1
0
1
cblair
Will your SSL Certificate Checker work for Windows domain controllers?
by cblair New Member in Splunk Enterprise 01-19-2023
0 3
0
3
chandankr
I have an input of value is like an odometer so it's cumulative. I collect a sample every 15 minutes. If I want to cr...
by chandankr Path Finder in Splunk Enterprise 01-19-2023
0 7
0
7
Shakeer_Spl
Splunk UF Hi folks,Seeking help I am new to splunk I am trying to configure splunk UF, I have two vm's both vm's inst...
by Shakeer_Spl Explorer in Splunk Enterprise 01-18-2023
0 2
0
2
NullZero
I'm a Splunk PS consultant and have been assisting a client with upgrades and migration to SVA compliant architecture...
by NullZero Communicator in Splunk Enterprise 01-18-2023
0 3
0
3
altink
Dear All.When searching some database log asindex=my_db ....I have a field named "statement"  with content as example...
by altink Builder in Splunk Enterprise 01-18-2023
0 5
0
5
chandankr
was using this below Search,  ***| rex field=_raw "<measResults>\d+\s\d+\s\d+\s\d+\s\d+\s\d+\s\d+\s\d+\s(?<active_sta...
by chandankr Path Finder in Splunk Enterprise 01-18-2023
0 12
0
12
chandankr
  | rex field=_raw "measResults\W(?<avgCpuUtilization>\d{0,3})\s(?<maxCpuUtilization>\d{0,3})" | rex field=_raw "PLMN...
by chandankr Path Finder in Splunk Enterprise 01-18-2023
0 0
0
0
Ashwini008
Hi, I am trying to use this Splunk Add-on for Microsoft Cloud Services on Splunk Enterprise platform. I have followed...
by Ashwini008 Builder in Splunk Enterprise 01-17-2023
0 0
0
0
Vani_26
Hi,My query:   |tstats count where index=app-clietapp host=ahnbghjk OR host=ncsjnjsnjn sourcetype=app-clientapp sourc...
by Vani_26 Path Finder in Splunk Enterprise 01-17-2023
0 4
0
4
maxouhunterfc
event is json: {message:AZK} x 10 {message:BCK} x 5 {message:C} x 3   What Im trying to get is a table to count messa...
by maxouhunterfc Engager in Splunk Enterprise 01-17-2023
0 2
0
2
mahesh27
Hi,i have 2 hosts and 2 sources, previously i was getting data from 2 sources, but now we have teardown and resdeploy...
by mahesh27 Communicator in Splunk Enterprise 01-17-2023
0 1
0
1
AkashNTT
Hi Friends,  I am upgrading my Splunk Enterprise from 7.1 to 8.1. after upgrading Indexer search head Peer server it ...
by AkashNTT Loves-to-Learn Lots in Splunk Enterprise 01-17-2023
0 3
0
3
sini
Hi all,We have an issue with our environment (all running 8.2.8 currently on Windows Server 2016 Standard). We have a...
by sini Explorer in Splunk Enterprise 01-17-2023
0 2
0
2
shob4726
Hey,I have a Splunk Enterprise environment with servers cluster of 4 SHDs, 5 HFDs and 3 Indexers.In addition there is...
by shob4726 Observer in Splunk Enterprise 01-17-2023
0 2
0
2
Vani_26
Hi All,I am using Splunk 9.0.1 version,  is there a way to Schedule PDF Delivery option in dashboard studio.if yes pl...
by Vani_26 Path Finder in Splunk Enterprise 01-16-2023
0 1
0
1
boromir
Hi all,  I am at an impasse, and I do need some ideas how to overcome that. So here is the challenge.  1)I have CSV d...
by boromir Path Finder in Splunk Enterprise 01-16-2023
0 0
0
0
dablab
Hello,I'm hosting a Splunk Enterprise free trial on an AWS instance.  I'd like to share this with some friends to pra...
by dablab Explorer in Splunk Enterprise 01-12-2023
0 1
0
1
starr
So what happened to parsetest?$ splunk cmd parsetest couldn't run "/opt/splunk/bin/parsetest": No such file or direct...
by starr Observer in Splunk Enterprise 01-12-2023
0 0
0
0
Matilda
Hi,    I want to know how to differentiate between logs from a productive versus a non-productive license.   Thnk you...
by Matilda Explorer in Splunk Enterprise 01-12-2023
0 2
0
2
mahesh27
Hi All,how can i know whether props has been defined to particular sourcetype.how can i check it.
by mahesh27 Communicator in Splunk Enterprise 01-11-2023
0 5
0
5
Gursimar_singh
We have a distributed deployment consisting of  2 Search heads, 1 indexer, Deployment server, 2 Heavy Forwarders, Uni...
by Gursimar_singh Engager in Splunk Enterprise 01-11-2023
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...