Splunk Search

Search processing language

EHariharan
Explorer

Hi Everyone,

Can any one help me with SPL to extract report of recent log sources reporting with time and the time difference from current time.

Thanks in Advance!

Tags (1)

chrisyounger
SplunkTrust
SplunkTrust

Hi @EHariharan

This is a very hard problem, however the metawoot app does the best job of providing the sort of reports you want: https://splunkbase.splunk.com/app/2949/

Silly name, excellent app 🙂

All the best.

0 Karma

EHariharan
Explorer

Thank you Chris.

But do i have any chance to extract report using query?

like adding some more query with following
* | stats values(source) by host

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Sorry I can't give you a simple answer. There are a lot of complexities becuase if you have time parsing problems, then the events won't show up in your search in the first place.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...