Splunk Search

Splunk Search
Community Activity
Moreilly97
So I have events that are tickets that have a State eg. "New" , "In Progress" , "Completed" etc and a short_descript...
by Moreilly97 Path Finder in Splunk Search 03-12-2018
0 8
0
8
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the query below which calcluates the differenc...
by IRHM73 Motivator in Splunk Search 03-12-2018
0 14
0
14
macadminrohit
Hi, To increase the performance of the search can we use stats command rather than table command to output the resul...
by macadminrohit Contributor in Splunk Search 03-12-2018
0 5
0
5
sharad06
Hi experts, I am working with nested JSON events which look as follows: { [-] compliance: <compliance_stat...
by sharad06 Explorer in Splunk Search 03-12-2018
0 4
0
4
edrivera3
I want to join these two types of data: The following events have the recorded value for each step in a test. Test...
by edrivera3 Builder in Splunk Search 03-12-2018
0 0
0
0
bbsplunklog
I'm trying to extract a field from a Juniper log. An event would end with something like this: reason=Close - RESP\x0...
by bbsplunklog New Member in Splunk Search 03-12-2018
0 6
0
6
JoshuaJohn
I have a query that receives input from a drop-down. Example info coming from the drop-down: Static: All = * Dynamic...
by JoshuaJohn Contributor in Splunk Search 03-12-2018
0 2
0
2
splunkreal
We had problem this week with logs indexed with lower or upper case hostnames. We run this query in a scheduled macro...
by splunkreal Influencer in Splunk Search 03-12-2018
0 4
0
4
splunkreal
Hello, how to get tstats results non-case sensitive? | tstats latest(_time) as latest,earliest(_time) as earliest W...
by splunkreal Influencer in Splunk Search 03-12-2018
1 2
1
2
donaldwayne1975
Want to improve the TSTAT for the "Substantial Increase In Port Activity" correlation search. | tstats allow_old_su...
by donaldwayne1975 Path Finder in Splunk Search 03-12-2018
0 1
0
1
bomran
Hi, I want to extract a certain part of a string, for instance: Input \\domain.org\teams\team1\bla\bla\bla \\domai...
by bomran Explorer in Splunk Search 03-12-2018
0 4
0
4
Kieffer87
I'm trying to chart some phishing logs over time which contain 3 time values: _time - The time when an analyst proces...
by Kieffer87 Communicator in Splunk Search 03-12-2018
1 2
1
2
pfabrizi
I am using EVAL in my props.conf to create a multi-value field. EVAL-test = split(test,",") test = this,that,xyz ...
by pfabrizi Path Finder in Splunk Search 03-12-2018
0 1
0
1
schose
Hi all, I' searching for a possibility to invoke SPL from a field. Background: I want to dynamically display tables ...
by schose Builder in Splunk Search 03-12-2018
0 3
0
3
klchandrakanth
I have calculated % from 3 different searches and i am getting the result perfectly fine. source="log-ura" "Flag Fi...
by klchandrakanth Explorer in Splunk Search 03-12-2018
0 4
0
4
nkankur
I have data as given below in table format A B C D E F 517 2498 186 1000 250 ...
by nkankur Path Finder in Splunk Search 03-12-2018
0 5
0
5
valerie_tan
Also, how do i allow changed in the original pivot to be updated directly in the inline search?
by valerie_tan Path Finder in Splunk Search 03-12-2018
0 17
0
17
gagandeep_arora
What is an inline Search, How to create one, Impact of using it, Any Splunk documentation for inline search.
by gagandeep_arora Path Finder in Splunk Search 03-12-2018
0 4
0
4
Dakxh
Hi, I want to know if there is a way to pass parent search field value as source/input for sub-search for a differen...
by Dakxh Explorer in Splunk Search 03-11-2018
0 4
0
4
maratus2013
Hi, I'm trying to draw a polygon on choropleth map using custom kml file in Splunk (6.5.1), but the polygon not shown...
by maratus2013 New Member in Splunk Search 03-11-2018
0 0
0
0
krusovice
Hello all, I'm forming the eval query based on the value extracted from dropdown token. | eval city=if((_raw LIKE ...
by krusovice Path Finder in Splunk Search 03-11-2018
0 12
0
12
mtaylor78
So I am trying to refine my Threat Activity Detected Search to only show "Allowed" connections rather than any blocke...
by mtaylor78 Engager in Splunk Search 03-11-2018
2 1
2
1
tmak
Total shot in a dark, but i figured this is good way to build some friendships. I'm Solutions Architect with AWS Part...
by tmak Explorer in Splunk Search 03-11-2018
0 2
0
2
dave0970
How do i get this search to send the following eval shown in my email? I am getting email now but no result found sho...
by dave0970 Engager in Splunk Search 03-11-2018
0 11
0
11
tweedyloebus
I would like to be able to run a report showing the computer usage of every client on my network. Is there a way I ca...
by tweedyloebus New Member in Splunk Search 03-11-2018
0 5
0
5
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...