Splunk Search

Splunk Search
Community Activity
srobinsonxtl
This search take only a few second to come back index=* sourcetype=* (source="/opt/data/-AA_.csv" OR source="/opt/dat...
by srobinsonxtl Path Finder in Splunk Search 01-04-2018
0 4
0
4
rharrisssi
I have a string, "one:isone,two:istwo,three:isthree" The goal is to convert these to fields and values, without k...
by rharrisssi Path Finder in Splunk Search 01-04-2018
0 1
0
1
redferrari
I have a field called "user", i'm trying to extract the username from the string and create a new field called extrac...
by redferrari New Member in Splunk Search 01-04-2018
0 4
0
4
SplunkLunk
I have some events that only happen every few hours between the hours of 8AM and 6PM, M-F. So, I want to set up a lo...
by SplunkLunk Path Finder in Splunk Search 01-04-2018
0 2
0
2
N92
My question might be weird. I change the management port on one of endpoint(universal forwarder)from multiple forwar...
by N92 Path Finder in Splunk Search 01-04-2018
0 1
0
1
katzr
I am trying to write a search that if the field= Email then perform a coalese, but if the field isn't Email- just put...
by katzr Path Finder in Splunk Search 01-04-2018
0 10
0
10
jbrenner
I'm using the _rex command and I want to create a regular expression that contains a literal double quote character. ...
by jbrenner Path Finder in Splunk Search 01-04-2018
1 4
1
4
JamesPineda
New to dbs and Splunk. Querying against a CSV file of buy events. Want to return top 10 Users by purchase totals. ...
by JamesPineda New Member in Splunk Search 01-04-2018
0 1
0
1
xvxt006
Hi, I have URIs like this: /appliance/detail/v3.0/vendor/3423434erts/fridge /appliance/detail/v3.0/vendor/6757dfs32...
by xvxt006 Contributor in Splunk Search 01-04-2018
0 5
0
5
DanielWick
So I have multiple fields whose field names could end with a different values. Examples of these fields are below: fo...
by DanielWick New Member in Splunk Search 01-04-2018
0 1
0
1
zacksoft
I think we may need regex for this and I am not good at it. I need to be able to extract the last part i.e. (TMNT-17...
by zacksoft Contributor in Splunk Search 01-04-2018
0 19
0
19
swdowiarz
Hi I have the following issue. I'm using SPLUNK for real-time monitoring of chat bot. I have as well file with bann...
by swdowiarz Path Finder in Splunk Search 01-04-2018
0 9
0
9
zacksoft
I use addcoltotal for one of my columns . But my result has a lot of rows, so I have to browse a lot of pages to find...
by zacksoft Contributor in Splunk Search 01-04-2018
0 9
0
9
rajeswariramar
I'm having problem with a multi-line field extraction which I have been struggling to figure out. Below the log file...
by rajeswariramar New Member in Splunk Search 01-04-2018
0 5
0
5
auaave
Hi Guys, I have the below query using that is using the shared timepicker: today, which is counting the events from ...
by auaave Communicator in Splunk Search 01-03-2018
0 5
0
5
davidcraven02
I tried to apply this logic as I want to check if the values from con_splunkUL exists within con_UL, but for me it se...
by davidcraven02 Communicator in Splunk Search 01-03-2018
0 8
0
8
patng_nw
I am using Splunk Enterprise 6.6.2, and today I noticed an alarming problem. In order for me to troubleshoot the pro...
by patng_nw Communicator in Splunk Search 01-03-2018
0 16
0
16
Said7
Hi, I have a doubt about an inputlookup, i have a inputlookup with some ip's and i want to know how can see comunic...
by Said7 Explorer in Splunk Search 01-03-2018
0 6
0
6
alanhowlett
I'm trying to configure a field extraction but am getting some strange incisions in the output. I'm running the below...
by alanhowlett New Member in Splunk Search 01-03-2018
0 7
0
7
JamesPineda
Hi all, Student, new to Splunk and dbs. I need some help performing basic math operation against stats results. I...
by JamesPineda New Member in Splunk Search 01-03-2018
0 2
0
2
mahbs
Hi, I've got fields which contain null values. I'm writing a regular expression to capture instances where fields co...
by mahbs Path Finder in Splunk Search 01-03-2018
0 3
0
3
elliotproebstel
Our Splunk Enterprise deployment has started returning inconsistent results, and I've been unable to track the source...
by elliotproebstel Champion in Splunk Search 01-03-2018
1 6
1
6
kdwsplunk
Hello, I was wondering if there is an SPL command that will give an organized summary or listing of all field aliase...
by kdwsplunk Explorer in Splunk Search 01-03-2018
0 2
0
2
davidcraven02
I have a search which checks if the values within con_splunkUL exist within con_UL (or visa versa). I need a field ...
by davidcraven02 Communicator in Splunk Search 01-03-2018
0 1
0
1
zacksoft
The table output of my splunk query gives me an output like this. uri | tra...
by zacksoft Contributor in Splunk Search 01-03-2018
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors