Splunk Search

Splunk Search
Community Activity
baf879
Hi everyone, On my Universal Forwarder, I'm able to effectively blacklist Windows event codes when I do it based on ...
by baf879 Path Finder in Splunk Search 03-08-2018
1 28
1
28
surekhasplunk
| rest /services/authentication/users splunk_server=local | search [| rest /services/authentication/current-context |...
by surekhasplunk Communicator in Splunk Search 03-08-2018
0 1
0
1
balbano
0
6
chhawu
How to find out the event with max duration? I used command transaction to group events and I want to find out the ev...
by chhawu New Member in Splunk Search 03-08-2018
0 5
0
5
pal_sumit1
Let suppose,In a list(owner_name) as owner_name we are having following values, shyam ram Shyam Shyam And we have to...
by pal_sumit1 Path Finder in Splunk Search 03-08-2018
0 4
0
4
iomega311
I have a .csv file with multiple columns. This is an auto-generated .csv file, and I only need to search against one ...
by iomega311 Explorer in Splunk Search 03-08-2018
0 2
0
2
chrisschum
I'm getting log data from a system that uses codes for each entry and I'd like to replace or add a description of the...
by chrisschum Path Finder in Splunk Search 03-08-2018
0 3
0
3
tatery
Hello, I need to prepare statistics of some events occurrences and this is my data in splunk: 07-03-18;11:55:14;id...
by tatery Engager in Splunk Search 03-08-2018
0 12
0
12
emichels
Is there something like a "sql database view" in splunk to hide the complexity of a search/report from the end user?
by emichels Loves-to-Learn in Splunk Search 03-08-2018
0 2
0
2
kmaron
I'm having issues trying to break out individual events that are combined into multi-value fields When I do a table ...
by kmaron Motivator in Splunk Search 03-08-2018
0 4
0
4
hettervik
Hi, I've encountered this problem a couple of times now. I have a dashboard where some of the panels run on a base ...
by SplunkTrust SplunkTrust in Splunk Search 03-08-2018
6 7
6
7
dabany
How can I transfer data from splunk to syslog? I did not understand the explanation in the link: http://docs.splunk.c...
by dabany Engager in Splunk Search 03-08-2018
0 1
0
1
jwillaime
So, I have this search on events that cover from the 28th of February to the 6th of March, 2018: Some basic search...
by jwillaime Explorer in Splunk Search 03-07-2018
0 3
0
3
auaave
Hi, I want to create dashboard that displays the 4 weeks data by week number. The database normally have 3 months of...
by auaave Communicator in Splunk Search 03-07-2018
0 10
0
10
ledion
Does anyone know how to craft a search to find George Bush's stolen watch?
by ledion Path Finder in Splunk Search 03-07-2018
3 7
3
7
tdunphy_
Hi all, I have a column in splunk that I want to use to show totals. I would like for the dollar sign ($) to appear ...
by tdunphy_ Explorer in Splunk Search 03-07-2018
0 2
0
2
rvoninski_splun
I'm asking this question on behalf of a customer. We are ingesting XML data and it comes in clean. Timestamp is bein...
by rvoninski_splun Splunk Employee Splunk Employee in Splunk Search 03-07-2018
0 8
0
8
rakeshyv0807
Hi, I am trying to sum up all the field values grouped by a field value(suppose fieldA) in my initial query and I g...
by rakeshyv0807 Explorer in Splunk Search 03-07-2018
0 1
0
1
dangerusty
I have connection logs for a database. I need to identify users making certain queries. I'd like to: Search for a st...
by dangerusty Engager in Splunk Search 03-07-2018
0 2
0
2
howyagoin
I've got some data I'm matching with a rex akin to: | rex max_match=5 field=_raw "(?<myvalue>\d{4})" However, if ...
by howyagoin Contributor in Splunk Search 03-07-2018
0 2
0
2
ChhayaV
hi, I want to upload a bunch of files in a splunk i have a zipped file named SP.zip which is containing all the log ...
by ChhayaV Communicator in Splunk Search 03-07-2018
0 5
0
5
xiaohenry
I have 2 searches and i want to join the results of both of them into 1 table of x_requestid's. The respective result...
by xiaohenry Explorer in Splunk Search 03-07-2018
0 7
0
7
jordanking1992
Hello, Here is a sample log event I would like to filter: 20180307 11:11:08.795 [process:flow] [INFO] Thread is ret...
by jordanking1992 Path Finder in Splunk Search 03-07-2018
0 3
0
3
rajim
I need to have the first qualifier of a FQDN string. I have used the below mentioned query to do so. But it's not rec...
by rajim Path Finder in Splunk Search 03-07-2018
0 4
0
4
robertlynch2020
Hi Normally have code like this <selection> <set token="time_selection.earliest">$start$</set> ...
by robertlynch2020 Influencer in Splunk Search 03-07-2018
0 8
0
8
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...