Splunk Search

Splunk Search
Community Activity
patriciof1
Hi everybody. I've been having this problem with a search in splunk for quite some time. I have two queries that wor...
by patriciof1 New Member in Splunk Search 01-25-2018
0 1
0
1
rickettw
I want to find users who visited more than 1,000 urls in a month and the field name is cs_uri. I tried this: source...
by rickettw New Member in Splunk Search 01-25-2018
0 9
0
9
rmsit
Hi all, How would I go about merging multiple values on multiple lines so all values are captured? Currenlty, I am ...
by rmsit Communicator in Splunk Search 01-25-2018
0 5
0
5
carlyleadmin
Hi All, i kind of already have this working but wondering what else can be done with this?what other approaches i ca...
by carlyleadmin Contributor in Splunk Search 01-25-2018
0 5
0
5
akhan92394
I have a search which looks for VA scanning activity from firewalls threat logs, I am attempting to have an alert tri...
by akhan92394 Explorer in Splunk Search 01-25-2018
0 4
0
4
xsstest
I have a index naming is "IDS" . It's has 4 sourcetypes. The event of the index is very large. an average of 1.3 mil...
by xsstest Communicator in Splunk Search 01-25-2018
0 1
0
1
LH_SPLUNK
I've two sources with a Name-Town-Phone list. Now I like to count the entries mentioned in both sources. For example:...
by LH_SPLUNK Explorer in Splunk Search 01-25-2018
0 8
0
8
LeeZeeYuen
I have a field called "ipexist" in the dataset that have two values; empty(Which is defaulted as null in Splunk) and ...
by LeeZeeYuen New Member in Splunk Search 01-25-2018
0 39
0
39
SplunkNewbie18
Hi, I've read through transpose command to try suit into the statistics I would want to view but it doesn't seems to...
by SplunkNewbie18 New Member in Splunk Search 01-25-2018
0 2
0
2
SplunkNewbie18
Hi, I read through forums on how to extract URLs using regex. But couldn't find those on how to exclude them. For e...
by SplunkNewbie18 New Member in Splunk Search 01-24-2018
0 4
0
4
neltonk
Hi, I am new to Splunk and Regex. I have a folder : D:\SplunkForwarderCache\TimeSyncLogs\Linux. This folder contains...
by neltonk Path Finder in Splunk Search 01-24-2018
0 3
0
3
nawazns5038
How can we change the ulimits of Splunk to the desired value ? I have edited the /etc/security/limits.conf file and ...
by nawazns5038 Builder in Splunk Search 01-24-2018
1 15
1
15
CarmineCalo
Splunkers! How should i modify the regula expression | rex field=duration "(?<hour>\d{2}):(?<min>\d{2}):(?<sec>\d{2...
by CarmineCalo Path Finder in Splunk Search 01-24-2018
0 3
0
3
hsingams2
I've an event where some field "values" can be concatenated/evaluated to generate a field "name" that exists in the s...
by hsingams2 Explorer in Splunk Search 01-24-2018
0 2
0
2
jspigler2010
I am looking for a way to filter the results that I am returning from an initial SPL search, a join command keying of...
by jspigler2010 Explorer in Splunk Search 01-24-2018
0 2
0
2
the_wolverine
Stats can be used to get the most recent X value of Y, for example: | stats latest(x) by y How do I get the most rec...
by the_wolverine Champion in Splunk Search 01-24-2018
0 3
0
3
HattrickNZ
I have the following: _time condition delivery sent 1 21/01/2018 0:00 0:00 264464 331477 2 22/01...
by HattrickNZ Motivator in Splunk Search 01-24-2018
1 4
1
4
HattrickNZ
I have the following table from my search: index=core ... | timechart span=5m sum(deliverySucceeded) as deliverySu...
by HattrickNZ Motivator in Splunk Search 01-24-2018
0 5
0
5
bgill0123
I have created a static list of users in a dropdown on one of my dashboards. There are only 15 of them so I decided n...
by bgill0123 Loves-to-Learn in Splunk Search 01-24-2018
0 4
0
4
CarmineCalo
Splunkers! I need to solve this problem. Basically, starting from a Service Catalogue (having the same AppID linked ...
by CarmineCalo Path Finder in Splunk Search 01-24-2018
0 2
0
2
ddrillic
We wonder whether the workflow UI has SPL commands. Meaning, can we perform the same workflow tasks via commands?
by ddrillic Ultra Champion in Splunk Search 01-24-2018
0 0
0
0
akhil36109
Hello everyone, In the above command i got the average memory raw per customer for a day(span=1d). But i need it for ...
by akhil36109 New Member in Splunk Search 01-24-2018
0 5
0
5
guimilare
Hello Splunkers, here is my scenario: I have a field actionType that can assume two values: "S" or "A". Based on act...
by guimilare Communicator in Splunk Search 01-24-2018
1 5
1
5
LordLeet
Hello, I'm performing some aggregations on my indexed data and I'm doing them based on a field that stores date and...
by LordLeet Path Finder in Splunk Search 01-24-2018
0 1
0
1
pfries54
I want to add data of a network, for example 192.168.0.0/24. But when i select TCP/UDP, and i add 192.168.0.* on "Acc...
by pfries54 New Member in Splunk Search 01-24-2018
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...