Splunk Search

Splunk Search
Community Activity
shreyasathavale
My 1st search: earliest=-2mon@mon latest=-1mon@mon index=linux (host=abc OR host=xyz) COMMAND=LMN|dedup host,PID|stat...
by shreyasathavale Communicator in Splunk Search 03-19-2018
0 6
0
6
pratibha2018
I want to merge events that are in between state=" STARTED" and state="COMPLETED" i.e. All the following events of st...
by pratibha2018 Explorer in Splunk Search 03-19-2018
0 9
0
9
anandhalagarasa
Hi Team, I got a scenario as below: index=* host=A or host=B Type=Info "Service down" In this i want the following...
by anandhalagarasa Path Finder in Splunk Search 03-19-2018
0 6
0
6
mihenn
Hello, I am searching for a possibility to build a multi-level piechart in Splunk. Does anyone knew if the is an bui...
by mihenn Path Finder in Splunk Search 03-19-2018
1 5
1
5
dmenon84
Hi All - I am having trouble extracting the following fields from a GET request . GET **/TSGene/**images/literature...
by dmenon84 Path Finder in Splunk Search 03-18-2018
0 8
0
8
TDR57
How can or is there a way of running one search and sharing the resulting data amongst multiple panels in a Dashboar...
by TDR57 Explorer in Splunk Search 03-18-2018
0 2
0
2
BearMormont
Hi, I have another question similar to the question I asked at https://answers.splunk.com/answers/624148/expanding-n...
by BearMormont Path Finder in Splunk Search 03-18-2018
0 4
0
4
ALLIACOM
hello , someone can help me to translate this pivot command in search command | pivot proofpoint proofpoint_search ...
by ALLIACOM New Member in Splunk Search 03-17-2018
0 2
0
2
leagawa
I am working with data from an application but the data has been forwarded to Splunk as raw data and appear randomly ...
by leagawa New Member in Splunk Search 03-17-2018
0 1
0
1
Shabalala9
I want to create a real-time map similar to https://cybermap.kaspersky.com/ that tracks and displays the exact locati...
by Shabalala9 New Member in Splunk Search 03-16-2018
0 1
0
1
maheshsat
Can any one help to understand & use of below command in eval index=_internal | eval Mahesh=max(1, 3, 6, 7, "foo", fi...
by maheshsat Explorer in Splunk Search 03-16-2018
0 1
0
1
maheshsat
index=_internal | eval Mahesh=replace(date, "^(\d{1,2})/(\d{1,2})/", "\2/\1/") My date 03-16-2018 I need 16-03-2018
by maheshsat Explorer in Splunk Search 03-16-2018
0 2
0
2
Kendo213
Is there a way to pull a list of running processes and the CPU % usage per process via Splunk natively? Using Powers...
by Kendo213 Communicator in Splunk Search 03-16-2018
0 2
0
2
MedralaG
As an example, I am getting weather data where in each json even I have the sunrise and sunset time for that day. The...
by MedralaG Communicator in Splunk Search 03-16-2018
0 10
0
10
kmedina1
I would like to create a live map similar to the one at Norse: http://map.norsecorp.com. Below is the search that I ...
by kmedina1 Explorer in Splunk Search 03-16-2018
0 4
0
4
mjones414
I have a set of fixed fields that define a maximum threshold with the naming convention of "resources_available_[[con...
by mjones414 Contributor in Splunk Search 03-16-2018
0 1
0
1
xinde
I tried to use | rex "^Version\s(?P(\\d{2}))$ to extract version number - it should only be 2 digit number. But 12.1....
by xinde Path Finder in Splunk Search 03-16-2018
0 8
0
8
kiselevm
I first encountered the plank system. Need any help. Have a table with multiple rows. Is it possible to assign a lin...
by kiselevm New Member in Splunk Search 03-16-2018
0 2
0
2
kiselevm
Hi all Someone can help me? We have a stream of messages that are sent from one side and received on the other. Is i...
by kiselevm New Member in Splunk Search 03-16-2018
0 1
0
1
Gawker
I have a report that provides a summary of key activity by IP. I wanted to cross check that information against the ...
by Gawker Path Finder in Splunk Search 03-16-2018
0 2
0
2
jiaqya
i am trying to join 2 indexes and ClientName. i find some rows are not joining on ClientName. but if i explicitly me...
by jiaqya Builder in Splunk Search 03-16-2018
0 6
0
6
jacqu3sy
Hi, I need a regex to extract at search time the values after ACTION[*] and up to the next character, regardless of ...
by jacqu3sy Path Finder in Splunk Search 03-16-2018
0 4
0
4
timmag
Say I have one lookup which has various fields like host, source and other stuff. And another lookup which has fields...
by timmag Explorer in Splunk Search 03-16-2018
0 5
0
5
ivog
Hi, Can someone recommend a linux utility to reliably benchmark IOPS on local, NFS and iSCSI volumes? I need someth...
by ivog Engager in Splunk Search 03-15-2018
1 2
1
2
abhi04
How to use message name as argument for transaction command? I have logs relate to a particular message ID for one so...
by abhi04 Communicator in Splunk Search 03-15-2018
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors