Splunk Search

Splunk Search
Community Activity
jcolin101
Hi, I wondering Why Splunk Enterprise shows at Data Summary the earliest event from 48 years ago. Can it be erased o...
by jcolin101 New Member in Splunk Search 02-13-2018
0 2
0
2
vkumar6
Hi How can I create a PIE chart using multiple subsearches? notable | search source="ENV: Windows Privilege Escala...
by vkumar6 Explorer in Splunk Search 02-13-2018
0 1
0
1
tschn00
I have written a python script whose purpose is to add a line to a file every time the specified command is called in...
by tschn00 Explorer in Splunk Search 02-13-2018
1 4
1
4
cxfuent29
I am using a lookup csv file. events have userid and CSV file has userid. Some of the event file userid's are not o...
by cxfuent29 New Member in Splunk Search 02-13-2018
0 1
0
1
alanhowlett
We are trying to carry out a field extraction in a log that contains xml output. We have worked out the regex to get...
by alanhowlett New Member in Splunk Search 02-13-2018
0 2
0
2
ksbuchanan
Here is my search: source="WinEventLog:Security" EventCode="4723" OR EventCode="529" | eval UserName=coalesce(User_N...
by ksbuchanan Explorer in Splunk Search 02-13-2018
0 11
0
11
tamduong16
I have the following search: index="monthlycdr" | eval "transporttype"=replace('Transport Type',"\"","") | eval "t...
by tamduong16 Contributor in Splunk Search 02-13-2018
0 5
0
5
Sukisen1981
Hi, I have a CSV with something like the one shown. first field is order id and second field is product code. ordr ...
by Sukisen1981 Champion in Splunk Search 02-13-2018
0 2
0
2
bcarr12
Hello everyone, I am sure this is a relatively easy regex to build but I was hoping for some assistance, my regex ex...
by bcarr12 Path Finder in Splunk Search 02-13-2018
0 9
0
9
Naren26
I have to forecast data for next 15 days, based on the last 30 days data. I have used the following query: sourcetyp...
by Naren26 Path Finder in Splunk Search 02-13-2018
0 3
0
3
paulalbert
I am trying to join the results of two searches so it looks like this: CWID, authorization_pk,weillCornellEduPrimary...
by paulalbert Engager in Splunk Search 02-13-2018
0 9
0
9
rajumedipally
I have two sources Send Log and Received Log Send Log has four fields namely A B C D. (Combination of 4 fields as uni...
by rajumedipally New Member in Splunk Search 02-13-2018
0 2
0
2
deva1995
tstats is working on the fields like source, sourcetype, _time etc, however, I want to use tstats on other fields of ...
by deva1995 Explorer in Splunk Search 02-13-2018
0 2
0
2
SGun
Trying to search with ldapsearch a list of specific users. | ldapsearch domain="default" search="(&(samAccountType=...
by SGun Explorer in Splunk Search 02-13-2018
0 37
0
37
ebruozys
I'm trying to compare the same date field between two different events. An event has the following fields that are i...
by ebruozys Path Finder in Splunk Search 02-13-2018
0 5
0
5
alexm2a
Hi there, I have some data like this activity_id: 1131c134-d771-41e7-918d-d42772fc1316 date_time: 20...
by alexm2a Engager in Splunk Search 02-13-2018
0 3
0
3
dlcrooks
I am trying to set the Name to Unknown if the ID is XYZ else populate it with the name value. I have Eval name=if(...
by dlcrooks Explorer in Splunk Search 02-13-2018
0 13
0
13
kiran331
Hi, I have a field with values URL and port, how to trim away the port and only use URL? For example, abc.net:9090 ...
by kiran331 Builder in Splunk Search 02-12-2018
1 3
1
3
rewritex
I'm trying to configure a time-based lookup (temporal lookup) but it doesn't seem to be working as expected. Any advi...
by rewritex Contributor in Splunk Search 02-12-2018
0 5
0
5
zsanchez113
Hey all, I'm trying to extract fields from openSCAP logs and I'm having difficulties pulling the CCE/DISA fields, w...
by zsanchez113 Explorer in Splunk Search 02-12-2018
0 2
0
2
umesh_waghode
We are trying to configure SAML integration for our Splunk On-Premise instance with our identity provider. Per the do...
by umesh_waghode Engager in Splunk Search 02-12-2018
2 18
2
18
joachimroshan
I have two lookups A,B with fields APIKEY, ENDPOINT. How do I compare the missing value for the column ENDPOINT in lo...
by joachimroshan New Member in Splunk Search 02-12-2018
0 1
0
1
diddyb
I'm trying to shorten up a timechart search by removing the xmlkv function. I've tried numerous times using rex an...
by diddyb New Member in Splunk Search 02-12-2018
0 5
0
5
cfurstenau
I have a search that returns the following table: | Key | Value | |---------|---------| | user | bob |...
by cfurstenau Engager in Splunk Search 02-12-2018
1 6
1
6
ddrillic
A little bit strange as this time stamp is not being recognized -
by ddrillic Ultra Champion in Splunk Search 02-12-2018
1 4
1
4
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors