Splunk Search

Search processing language

EHariharan
Explorer

Hi Everyone,

Can any one help me with SPL to extract report of recent log sources reporting with time and the time difference from current time.

Thanks in Advance!

Tags (1)

chrisyounger
SplunkTrust
SplunkTrust

Hi @EHariharan

This is a very hard problem, however the metawoot app does the best job of providing the sort of reports you want: https://splunkbase.splunk.com/app/2949/

Silly name, excellent app 🙂

All the best.

0 Karma

EHariharan
Explorer

Thank you Chris.

But do i have any chance to extract report using query?

like adding some more query with following
* | stats values(source) by host

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Sorry I can't give you a simple answer. There are a lot of complexities becuase if you have time parsing problems, then the events won't show up in your search in the first place.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...