Splunk Search

Splunk Search
Community Activity
robettinger
Hi, I am trying to do the following: 1 - Search an index; 2 - For each result, search for matches in lookup table 1,...
by robettinger Explorer in Splunk Search 02-08-2018
0 14
0
14
neltonk
I am working with clock sync log files. The top 3 lines have the ip address -> MAC address mapping... The rest of the...
by neltonk Path Finder in Splunk Search 02-07-2018
0 1
0
1
matthewssa
Hi! My goal is to be able to tie together events from Linux events and Windows events in order to track Windows user...
by matthewssa Path Finder in Splunk Search 02-07-2018
0 4
0
4
charliedgz
SPLUNK NINJAS! I NEED YOUR HELP! I have a firewall issue where any IP outside of our intranet, Splunk throws errors ...
by charliedgz Path Finder in Splunk Search 02-07-2018
0 2
0
2
kulick
Data Set Characteristics We have an index containing ~100k events that are each about 1k in size, making a roughly 1...
by kulick Path Finder in Splunk Search 02-07-2018
0 0
0
0
macadminrohit
Hi Experts, I have got a requirement where I have a few events where one of the fields contains some keyword say "Un...
by macadminrohit Contributor in Splunk Search 02-07-2018
0 6
0
6
AVOLLMER
I have a search: index=examp1 sourcetype=json application=myservice NOT [|inputlookup aps_test_filter.csv where appl...
by AVOLLMER Explorer in Splunk Search 02-07-2018
0 6
0
6
dg_fuze
I have a group of log entries with an id field, and a status field. For a given id, over a given amount of time, stat...
by dg_fuze New Member in Splunk Search 02-07-2018
0 3
0
3
matstap
I need to search a lookup table for rows that match an input string in any field. I've tried |inputlookup...... | se...
by matstap Communicator in Splunk Search 02-07-2018
0 5
0
5
cdgill
Here is my search query, though this issue is common across a number of different custom searches we are attempting: ...
by cdgill Explorer in Splunk Search 02-07-2018
0 3
0
3
samwatson45
I have two files which I have uploaded into Splunk, and both work as intended. One is a detailed file containing peo...
by samwatson45 Path Finder in Splunk Search 02-07-2018
0 10
0
10
katrinamara
I need to do a table which look like this (see below). As of now my table look like this How can I make the month...
by katrinamara Path Finder in Splunk Search 02-07-2018
0 8
0
8
jwalzerpitt
I'm seeing a weird issue - I have two Splunk instances, one for prod and one for dev. I have a lookup created that lo...
by jwalzerpitt Influencer in Splunk Search 02-07-2018
0 5
0
5
johnward4
I'm trying to figure out how to display just the Total for an overlay instead of displaying the value of each stacked...
by johnward4 Communicator in Splunk Search 02-07-2018
0 3
0
3
Naren26
Consider I am having two string - "YY02State" and "Y02State" In the above strings, I have to extract the fields like...
by Naren26 Path Finder in Splunk Search 02-07-2018
0 4
0
4
shiv1593
Hi All, I have two data fields, called "Issues" and "Complete issue" which look like this. What I want to do is th...
by shiv1593 Communicator in Splunk Search 02-07-2018
0 2
0
2
JeToJedno
I frequently have to create stats reports where some parts are, essentially, executable in parallel with others. An ...
by JeToJedno Explorer in Splunk Search 02-07-2018
0 3
0
3
jagadeeshm
Here is my SPL - | gentimes start=02/07/2017 end=02/08/2017 increment=1h | convert timeformat="%Y-%m-%d %H:%M:%S" ...
by jagadeeshm Contributor in Splunk Search 02-07-2018
0 4
0
4
zacksoft
Not sure if this can be achieved by eval command. A bit silly question indeed. "I want to know the value of the fiel...
by zacksoft Contributor in Splunk Search 02-07-2018
0 12
0
12
zacksoft
I want to convert my default _time field to UNIX/Epoch time and have it in a different field. This is how the Time fi...
by zacksoft Contributor in Splunk Search 02-07-2018
0 8
0
8
dlcrooks
I have a userID with 9 characters and want to search a lookup with just 7 characters. I have tried to use RegEx but ...
by dlcrooks Explorer in Splunk Search 02-07-2018
0 4
0
4
varun99
I want to add a checkbox input which just concatenates my search with something like " | search Error" if I check tha...
by varun99 Path Finder in Splunk Search 02-06-2018
0 2
0
2
packland
Hi, I'd like to create a search that detects a failover, i.e. it would compare the two latest events by host and whe...
by packland Path Finder in Splunk Search 02-06-2018
0 2
0
2
rhysbee
As we are using the AD Domain Controller security logs for audit purposes, we want a query to validate there are no m...
by rhysbee New Member in Splunk Search 02-06-2018
0 0
0
0
rrkollip
Hi , I have 2 events like below and I need to find the difference in time between 2 events. There may be a lot of o...
by rrkollip New Member in Splunk Search 02-06-2018
0 7
0
7
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...