Splunk Search

Splunk Search
Community Activity
ThomasLehenberg
I want to set up a timechart, showing three different status. Now I found this SPL online, which was modified by myse...
by ThomasLehenberg New Member in Splunk Search 04-05-2018
0 3
0
3
Mike6960
I have two sourcetypes. In both, there is a field present that has the same value in both but just another name, let'...
by Mike6960 Path Finder in Splunk Search 04-05-2018
0 6
0
6
dileepsri9
Hi, I have created a query which gives me date, and start and end time of a job in the below format. Date ...
by dileepsri9 Engager in Splunk Search 04-05-2018
0 10
0
10
kaphie2002
I have a new splunk instance and I am seeing log entries for the splunk cloud host logs with host names: dx* idx-i-...
by kaphie2002 New Member in Splunk Search 04-05-2018
0 2
0
2
danielsavage
At the moment I have a final dropdown input which has options for hosts already predetermined in it from previous dro...
by danielsavage New Member in Splunk Search 04-04-2018
0 13
0
13
northwarks
One of the things I'm using Splunk to monitor is electricity usage, one of the fields indexed is the accumulative Kw ...
by northwarks Engager in Splunk Search 04-04-2018
0 8
0
8
brajaram
Events in my sourcetype contain a build time, and an ID field. A given ID can have multiple events, and each event co...
by brajaram Communicator in Splunk Search 04-04-2018
0 5
0
5
h3xm0nk37
Hello, Sorry for may what be an easy question, I have been searching for hours to find a solution to my problem. I...
by h3xm0nk37 New Member in Splunk Search 04-04-2018
0 3
0
3
donaldwayne1975
Trying to figure out how to get a transaction search to show results where there are 5 or more failed logons (4625) a...
by donaldwayne1975 Path Finder in Splunk Search 04-04-2018
0 1
0
1
harsush
Hi Team, need your help sourcetype=amc| search environment=* |top 5 showperc=f countfield="repeat_count" environme...
by harsush Path Finder in Splunk Search 04-04-2018
0 2
0
2
Lowell
Is there a way for a search to determine its own sample ratio at search time? This would be helpful when scaling res...
by Lowell Super Champion in Splunk Search 04-04-2018
0 3
0
3
Riosrr
I have 3 different time date fields in my logs with 2 being redundant and the other being a different measure. Time_A...
by Riosrr New Member in Splunk Search 04-04-2018
0 4
0
4
tkwaller_2
Hello I have a field in my events that is named info_date_resReviewed in format "2017-09-24 00:00:00" and I'd like t...
by tkwaller_2 Communicator in Splunk Search 04-04-2018
0 1
0
1
santosh_sshanbh
I have a requirement to monitor a rolling log file from a folder. The name of the file is like below CalculationMgr-...
by santosh_sshanbh Path Finder in Splunk Search 04-04-2018
0 4
0
4
jodros
I am trying not to reinvent the wheel. There is a requirement where WinEventLogs are indexed as csv files. The sour...
by jodros Builder in Splunk Search 04-04-2018
0 2
0
2
ehowardl3
I'm trying to create a dashboard that displays one dash panel if the user enters "*" into a text input, and display a...
by ehowardl3 Path Finder in Splunk Search 04-04-2018
1 4
1
4
1132307
index=abcd source=xyz | FILTERS | eval s= case(S > 0 AND S <= 2, "V", S > 0 AND S <= 3, "O", S > 3 AND S <= 4, "D", ...
by 1132307 New Member in Splunk Search 04-04-2018
0 4
0
4
taha13
Hello, I have a little problem with the filtering date, I need a way to filter my dashboard so as to have the informa...
by taha13 Explorer in Splunk Search 04-04-2018
0 10
0
10
ngaviran
I am trying to query and not able to get the output , only i am getting host names, Avg response , count , but need S...
by ngaviran New Member in Splunk Search 04-04-2018
0 3
0
3
erictodor
I'm searching on Windows Security Auditing logs and the Security_ID field but when I do, I'm realizing that there is ...
by erictodor New Member in Splunk Search 04-04-2018
0 2
0
2
kavana
We want to query data from DB Using DB CONNECT but the value of "where condition" is variable. For example,the value...
by kavana Explorer in Splunk Search 04-04-2018
0 3
0
3
karthi2809
Three type of status: status:400 status:404 status:500 need total count and status count. if count of status more th...
by karthi2809 Builder in Splunk Search 04-04-2018
0 2
0
2
lpolo
Has anyone calculated the Percentile Distribution using Splunk? Thanks, Lp
by lpolo Motivator in Splunk Search 04-04-2018
0 1
0
1
afarmer
I've looked at splunkbase for "whois" apps and searched the community for whois-type scripts, but found none that mee...
by afarmer Explorer in Splunk Search 04-03-2018
0 1
0
1
pramit46
I have data like this: `a----b----c----d` `10----12----30----5` `50----34----46----55` `22----23----98----56` `32---...
by pramit46 Contributor in Splunk Search 04-03-2018
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors