Splunk Search

Splunk Search
Community Activity
dlcrooks
I have a userID with 9 characters and want to search a lookup with just 7 characters. I have tried to use RegEx but ...
by dlcrooks Explorer in Splunk Search 02-07-2018
0 4
0
4
varun99
I want to add a checkbox input which just concatenates my search with something like " | search Error" if I check tha...
by varun99 Path Finder in Splunk Search 02-06-2018
0 2
0
2
packland
Hi, I'd like to create a search that detects a failover, i.e. it would compare the two latest events by host and whe...
by packland Path Finder in Splunk Search 02-06-2018
0 2
0
2
rhysbee
As we are using the AD Domain Controller security logs for audit purposes, we want a query to validate there are no m...
by rhysbee New Member in Splunk Search 02-06-2018
0 0
0
0
rrkollip
Hi , I have 2 events like below and I need to find the difference in time between 2 events. There may be a lot of o...
by rrkollip New Member in Splunk Search 02-06-2018
0 7
0
7
varun99
PFB the search query that I am using for my panel. PFA the view of th dashboard as well. index=scampservices OSIT4 ...
by varun99 Path Finder in Splunk Search 02-06-2018
0 3
0
3
neltonk
Hi, Log files contain header and summary information in the beginning of the file. The number of header + summary li...
by neltonk Path Finder in Splunk Search 02-06-2018
0 3
0
3
rvazquez8113
I have transactions logged across different sales "channels" (catering, mobileApp, faceToFace, etc.). I am trying to ...
by rvazquez8113 New Member in Splunk Search 02-06-2018
0 2
0
2
christopheryu
I have two existing fields - "narrative" and "alarm_type" that I am trying to combine into a new single field "alert_...
by christopheryu Communicator in Splunk Search 02-06-2018
1 3
1
3
dlcrooks
When searching a lookup and the user is not found then I need the result to be NULL. Any ideas?
by dlcrooks Explorer in Splunk Search 02-06-2018
0 3
0
3
dbcase
Hi, I have this XML code where I'm attempting to convert the clicked time in epoch format into a human readable time...
by dbcase Motivator in Splunk Search 02-06-2018
0 8
0
8
heybails88
I have an index from a forwarder that looks something like this: "index=indexname DEBUG Rule="Rule One" OR "Rule Two"...
by heybails88 Path Finder in Splunk Search 02-06-2018
0 23
0
23
carlyleadmin
Hi All, I am using transaction with startswith endswith and some files are not showing. So I used keepevicted=t and ...
by carlyleadmin Contributor in Splunk Search 02-06-2018
0 2
0
2
HattrickNZ
How do I format a number with commas in a column/field that has numbers and strings(using appendpipe) I have the fol...
by HattrickNZ Motivator in Splunk Search 02-06-2018
0 3
0
3
x186855
I have a desired list of blades and I had filtered out only those blade id's and now while creating a multiselect lis...
by x186855 New Member in Splunk Search 02-06-2018
0 0
0
0
maria2691
Hello Everyone I have 2 source types ProcessStart and ProcessEnd. The common field with which I need to find out the...
by maria2691 Path Finder in Splunk Search 02-06-2018
0 11
0
11
floko
Dear Community! Following situation: I have a couple of indexes which are gathering log events from several heavy fo...
by floko Explorer in Splunk Search 02-06-2018
0 5
0
5
shiv1593
Hi All, I have a field named Issues Reported, whose values go something like this. Question 1. Can I use these va...
by shiv1593 Communicator in Splunk Search 02-06-2018
0 2
0
2
MOberschelp
Hi everyone, I've got a little problem. I want to split up IP addresses in network and host part (to create a chart ...
by MOberschelp Explorer in Splunk Search 02-06-2018
1 5
1
5
msteinb4
The current search I am running calls "transaction" and then a macro to output results into my table. When I remove t...
by msteinb4 New Member in Splunk Search 02-06-2018
0 4
0
4
rfernandez2010
Hi Splunkers, I can't seem to find a efficient way to bucket my results where anything greater than 174 days gets to...
by rfernandez2010 New Member in Splunk Search 02-06-2018
0 3
0
3
davidcraven02
I need the field concate_CSV to list all concatenations for each machine but it is not working. (Actual v Desired out...
by davidcraven02 Communicator in Splunk Search 02-06-2018
0 2
0
2
sathish2k8
I want to include search box to search account and it should display the timechart also. Please help. Presently only ...
by sathish2k8 Explorer in Splunk Search 02-06-2018
0 6
0
6
soniquella
Good morning. I am looking to generate an alert for when EventCode=4740 (User lockout) is shown in the event logs fr...
by soniquella Path Finder in Splunk Search 02-06-2018
1 5
1
5
rajacybermak
DBconnect is not sending fields with NULL values to the index Is there a way to force DBconnect to do this ?
by rajacybermak Explorer in Splunk Search 02-06-2018
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors