Splunk Search

Splunk Search
Community Activity
linwqg
Hello. I new to regex and have been trying to understand how it works. Let say i have a log containing strings of i...
by linwqg New Member in Splunk Search 03-19-2018
0 5
0
5
Splunk_rocks
Hello Splunkers, I would like to calculate below EPS values for 30 days time period for each source type on one c...
by Splunk_rocks Path Finder in Splunk Search 03-19-2018
0 4
0
4
Splunk_rocks
I want to calculate the amount of change in between today's score and yesterdays. This is a file with a few days data...
by Splunk_rocks Path Finder in Splunk Search 03-19-2018
0 6
0
6
shreyasathavale
My 1st search: earliest=-2mon@mon latest=-1mon@mon index=linux (host=abc OR host=xyz) COMMAND=LMN|dedup host,PID|stat...
by shreyasathavale Communicator in Splunk Search 03-19-2018
0 6
0
6
pratibha2018
I want to merge events that are in between state=" STARTED" and state="COMPLETED" i.e. All the following events of st...
by pratibha2018 Explorer in Splunk Search 03-19-2018
0 9
0
9
anandhalagarasa
Hi Team, I got a scenario as below: index=* host=A or host=B Type=Info "Service down" In this i want the following...
by anandhalagarasa Path Finder in Splunk Search 03-19-2018
0 6
0
6
mihenn
Hello, I am searching for a possibility to build a multi-level piechart in Splunk. Does anyone knew if the is an bui...
by mihenn Path Finder in Splunk Search 03-19-2018
1 5
1
5
dmenon84
Hi All - I am having trouble extracting the following fields from a GET request . GET **/TSGene/**images/literature...
by dmenon84 Path Finder in Splunk Search 03-18-2018
0 8
0
8
TDR57
How can or is there a way of running one search and sharing the resulting data amongst multiple panels in a Dashboar...
by TDR57 Explorer in Splunk Search 03-18-2018
0 2
0
2
BearMormont
Hi, I have another question similar to the question I asked at https://answers.splunk.com/answers/624148/expanding-n...
by BearMormont Path Finder in Splunk Search 03-18-2018
0 4
0
4
ALLIACOM
hello , someone can help me to translate this pivot command in search command | pivot proofpoint proofpoint_search ...
by ALLIACOM New Member in Splunk Search 03-17-2018
0 2
0
2
leagawa
I am working with data from an application but the data has been forwarded to Splunk as raw data and appear randomly ...
by leagawa New Member in Splunk Search 03-17-2018
0 1
0
1
Shabalala9
I want to create a real-time map similar to https://cybermap.kaspersky.com/ that tracks and displays the exact locati...
by Shabalala9 New Member in Splunk Search 03-16-2018
0 1
0
1
maheshsat
Can any one help to understand & use of below command in eval index=_internal | eval Mahesh=max(1, 3, 6, 7, "foo", fi...
by maheshsat Explorer in Splunk Search 03-16-2018
0 1
0
1
maheshsat
index=_internal | eval Mahesh=replace(date, "^(\d{1,2})/(\d{1,2})/", "\2/\1/") My date 03-16-2018 I need 16-03-2018
by maheshsat Explorer in Splunk Search 03-16-2018
0 2
0
2
Kendo213
Is there a way to pull a list of running processes and the CPU % usage per process via Splunk natively? Using Powers...
by Kendo213 Communicator in Splunk Search 03-16-2018
0 2
0
2
MedralaG
As an example, I am getting weather data where in each json even I have the sunrise and sunset time for that day. The...
by MedralaG Communicator in Splunk Search 03-16-2018
0 10
0
10
kmedina1
I would like to create a live map similar to the one at Norse: http://map.norsecorp.com. Below is the search that I ...
by kmedina1 Explorer in Splunk Search 03-16-2018
0 4
0
4
mjones414
I have a set of fixed fields that define a maximum threshold with the naming convention of "resources_available_[[con...
by mjones414 Contributor in Splunk Search 03-16-2018
0 1
0
1
xinde
I tried to use | rex "^Version\s(?P(\\d{2}))$ to extract version number - it should only be 2 digit number. But 12.1....
by xinde Path Finder in Splunk Search 03-16-2018
0 8
0
8
kiselevm
I first encountered the plank system. Need any help. Have a table with multiple rows. Is it possible to assign a lin...
by kiselevm New Member in Splunk Search 03-16-2018
0 2
0
2
kiselevm
Hi all Someone can help me? We have a stream of messages that are sent from one side and received on the other. Is i...
by kiselevm New Member in Splunk Search 03-16-2018
0 1
0
1
Gawker
I have a report that provides a summary of key activity by IP. I wanted to cross check that information against the ...
by Gawker Path Finder in Splunk Search 03-16-2018
0 2
0
2
jiaqya
i am trying to join 2 indexes and ClientName. i find some rows are not joining on ClientName. but if i explicitly me...
by jiaqya Builder in Splunk Search 03-16-2018
0 6
0
6
jacqu3sy
Hi, I need a regex to extract at search time the values after ACTION[*] and up to the next character, regardless of ...
by jacqu3sy Path Finder in Splunk Search 03-16-2018
0 4
0
4
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors