Splunk Search

Splunk Search
Community Activity
chandana204
i have this kind of data: event 1: field_name=field_value status="process" status_file="file_name" event 2: fiel...
by chandana204 Communicator in Splunk Search 01-30-2018
0 2
0
2
JarrettM
My iis data has a field name cs_uri_query, for example: Cmd=Sync&User=XYZ%5Cjqpublic%40xyz.com&DeviceId=SEC539D6F312...
by JarrettM Path Finder in Splunk Search 01-30-2018
0 3
0
3
tnoelOTS
I am Trying to build a Dashboard based on the below search with a drop down picker for time span and a drop down Butt...
by tnoelOTS Explorer in Splunk Search 01-30-2018
0 1
0
1
Uwbspeicher
Hi, I need to format a search very specifically so that the client's automation receives a report correctly. All I ne...
by Uwbspeicher New Member in Splunk Search 01-30-2018
0 3
0
3
vrmandadi
Hello, I am doing a search for selected timerange 27th to 28th index=abc... | bucket _time span=1d|eval Time=strfti...
by vrmandadi Builder in Splunk Search 01-30-2018
0 8
0
8
jroes014
I don't know why this is so hard, but I'm having issues creating a simple pie chart. I'm relatively new to Splunk and...
by jroes014 New Member in Splunk Search 01-30-2018
0 5
0
5
jamesfdally
lookup Down.csv node AS host, BBB AS Circuit Table host,Circuit,msg,_time,node, BBB I only want events to hit the t...
by jamesfdally Explorer in Splunk Search 01-30-2018
0 9
0
9
archananaveen
I search logs for these strings: "member left" OR "left cluster" OR "asking member". It gives below output. These ev...
by archananaveen Explorer in Splunk Search 01-30-2018
0 5
0
5
dbcase
Hi, I have this data and I'm challenged (not hard to do) on how to get the type extracted. On the first line type=...
by dbcase Motivator in Splunk Search 01-30-2018
0 15
0
15
macadminrohit
Hi, I am trying to analyse the Apache web access logs for the below textpayload: IP -- [Date +0000] "POST /PATH/URI...
by macadminrohit Contributor in Splunk Search 01-30-2018
0 1
0
1
dmcintosh1972
I would like to remove a prefix from a field where certain criteria are met but leave the prefix on on fields where c...
by dmcintosh1972 Explorer in Splunk Search 01-30-2018
0 1
0
1
kumar22
one particular system event count hourly the last 7 days graph each day need to display different line X - axis -- ...
by kumar22 New Member in Splunk Search 01-30-2018
0 5
0
5
jadengoho
I have a event that returns me this what i want is to have a new field that will solve the equation like number...
by jadengoho Builder in Splunk Search 01-30-2018
0 1
0
1
ronpestler1
Hello together, I probe to get the active session count from our asa logs per minute. I created a datamodel (CASA) w...
by ronpestler1 Explorer in Splunk Search 01-30-2018
0 0
0
0
ReachDataScient
I have the below search which shows 3 columns....the field1, index list and count of events. How can I add a trend li...
by ReachDataScient Explorer in Splunk Search 01-30-2018
0 2
0
2
ReachDataScient
How to display the event count per index and distinct host count per index with a trend line.
by ReachDataScient Explorer in Splunk Search 01-29-2018
0 2
0
2
CarmineCalo
Splunkers! I need to compute the duration of a event, as the difference between the two field (END_TIME and OPEN_TIM...
by CarmineCalo Path Finder in Splunk Search 01-29-2018
0 3
0
3
fraser8
index="king" source ="/King/East" I am confused why my search doesn't finish. I have a '2 month window' applied to t...
by fraser8 Engager in Splunk Search 01-29-2018
1 3
1
3
zaynaly
I have a field named "Expiry date" that contains future dates. I want to make a search that list will all entries tha...
by zaynaly Explorer in Splunk Search 01-29-2018
0 5
0
5
thomasreggi
Given the following log lines: Alpha Beta Gamma Hello World Soup I would like to query ` | first="Beta" | last="W...
by thomasreggi New Member in Splunk Search 01-29-2018
0 1
0
1
dbcase
Hi, I have the below regex and Splunk keeps telling me I have a mismatched "[" and for the life of me I can't figure...
by dbcase Motivator in Splunk Search 01-29-2018
0 2
0
2
johnward4
I'm trying to figure out the best way to extract values currently displayed under the field name "FIELD", for example...
by johnward4 Communicator in Splunk Search 01-29-2018
0 6
0
6
rebeccaweaver
So the query that is currently in use is: index=name source=source_name | fields start_time end_time src subject cat...
by rebeccaweaver New Member in Splunk Search 01-29-2018
0 3
0
3
splunkLPN
is there a way to transform a field in sha256 before indexation? in the sourcetype ? I can do that after using | e...
by splunkLPN Path Finder in Splunk Search 01-29-2018
0 1
0
1
supreetsingh75
A table with the count of failed login by a user for a day over the period of 7 days with the columns date, sourceip,...
by supreetsingh75 New Member in Splunk Search 01-29-2018
0 7
0
7
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors