Splunk Search

Splunk Search
Community Activity
jbrenner
I want to pipe the output of a transaction command into a rex command to parse something out of the result. Is this p...
by jbrenner Path Finder in Splunk Search 03-09-2018
0 3
0
3
baegoon
In BRO 2.5.X there are about 3 or 4 log files that have SSL Certificate information: x509.log, ssl.log, conn.log an...
by baegoon Explorer in Splunk Search 03-09-2018
0 0
0
0
Barty
Good afternoon Guys, Second question in as many days, but this one is puzzling me and my tiny useless uneducated br...
by Barty Explorer in Splunk Search 03-09-2018
0 5
0
5
splunkreal
Hello, is it normal that tstats must be without pipe | to run in a macro? The macro is scheduled. Thanks.
by splunkreal Influencer in Splunk Search 03-09-2018
0 1
0
1
jtitus3
I have a large CSV lookup table operational and working well but would like to run a search on my data that only show...
by jtitus3 Explorer in Splunk Search 03-09-2018
0 2
0
2
k_harini
I'm trying to get the eval value in subsearch and use it for further searching in the query. I guess there is issue w...
by k_harini Communicator in Splunk Search 03-09-2018
0 4
0
4
kiril123
Is it possible to increase the number of concurrent ad-hoc searches for the user, without increasing the number of sc...
by kiril123 Path Finder in Splunk Search 03-09-2018
0 2
0
2
jvmerilla
Hi All, I have 3 files in one index, Cycle 10.csv, Cycle 11.csv, and Cycle 12.csv. All of the 3 files have a "Cycl...
by jvmerilla Path Finder in Splunk Search 03-09-2018
0 1
0
1
a238574
I have a table that has 2 narrow columns. Is there a way to get splunk to display the output in multiple columns of t...
by a238574 Path Finder in Splunk Search 03-09-2018
0 1
0
1
MonkeyK
My admin team frequently needs restart our search heads while I have a long running query still running. When this h...
by MonkeyK Builder in Splunk Search 03-09-2018
0 4
0
4
ericrobinson
I have a search defining a Transaction across (2) different log files. The problem is that some fields (not all) are ...
by ericrobinson Path Finder in Splunk Search 03-09-2018
1 4
1
4
bojanisch
Hi everyone, I have a use case where I need to iterate over multiple query strings and execute each of them, so I th...
by bojanisch Path Finder in Splunk Search 03-09-2018
0 2
0
2
johnraven
HI! Could you help me changing the position of the splunk loginform in the top right corner of the splunk login page...
by johnraven Explorer in Splunk Search 03-09-2018
0 4
0
4
Alaza
Hello, How can I have a table like the picture with the time a the top, the type on the right side and a count by dat...
by Alaza Explorer in Splunk Search 03-09-2018
0 5
0
5
vrmandadi
I am using rex to split an existing field,can I use the same rex in IFX ? | rex field="External ID" "(?.*)_" I want...
by vrmandadi Builder in Splunk Search 03-08-2018
0 18
0
18
Jamesfirth
hi All, i have a 2008 r2 server that is a file share, i have setup a universal forwarder to send logs to splunk. Tha...
by Jamesfirth New Member in Splunk Search 03-08-2018
0 4
0
4
Simeon
I want to run searches against the Splunk API. How can I do this?
by Simeon Splunk Employee Splunk Employee in Splunk Search 03-08-2018
4 7
4
7
krusovice
Hi all, I've a request to come out with a table with information as below. My query so far is to extract the requir...
by krusovice Path Finder in Splunk Search 03-08-2018
0 3
0
3
johnward4
I'm trying to create a new field that is the result of the Current Date minus the time stamp when my events were crea...
by johnward4 Communicator in Splunk Search 03-08-2018
0 8
0
8
brajaram
I'm trying to add a single value to a table I use to dynamically populate a selector in a dashboard. The search I use...
by brajaram Communicator in Splunk Search 03-08-2018
0 4
0
4
flow2k
In searching, I understand that I can specify the time range using one of the presets (like "Last 4 hours") or set it...
by flow2k Explorer in Splunk Search 03-08-2018
0 1
0
1
afamoyib
Searches index=nix sourcetype=cpu host="host a" CPU="all" | eval Percent_CPU_Load = 100 - pctIdle | timechart limit...
by afamoyib Path Finder in Splunk Search 03-08-2018
0 3
0
3
wainwrid
Currently, we are running 6.6.2 and are using the geolite2 DB to do the iplocation mapping. I have read the followi...
by wainwrid Engager in Splunk Search 03-08-2018
0 1
0
1
ashishlal82
I extracted a field SNDateCreated (regex shown below), the values in this field are represented as strings. index="...
by ashishlal82 Explorer in Splunk Search 03-08-2018
0 1
0
1
ibob0304
This query capture the id from logs and make a search in the database, when there is a id value in logs it works well...
by ibob0304 Communicator in Splunk Search 03-08-2018
0 1
0
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...