Splunk Search

Splunk Search
Community Activity
smoir_splunk
When I do a search with |from datamodel, the search results are the same as when I do a search with |datamodel, but t...
by smoir_splunk Splunk Employee Splunk Employee in Splunk Search 12-01-2017
0 3
0
3
kteng2024
Hi there, Below is the query for which i need the multi field value for job type and organization. index=abc sourc...
by kteng2024 Path Finder in Splunk Search 12-01-2017
0 3
0
3
DEAD_BEEF
I have anti-virus data and I want to plot the the types of alerts on a chart over time. I want to plot the data such...
by DEAD_BEEF Builder in Splunk Search 12-01-2017
0 5
0
5
jamescasey2
First, new to regex, so don't really know where to start. I've done some Google searching and up and down Splunk Ans...
by jamescasey2 New Member in Splunk Search 12-01-2017
0 3
0
3
chandanaberi
I am new to splunk, I have two field names: status and ip_address, status has different field values, status=200, 3...
by chandanaberi Explorer in Splunk Search 12-01-2017
0 13
0
13
elliotproebstel
We have a number of scheduled searches that run every few minutes to search for events recently indexed that match ce...
by elliotproebstel Champion in Splunk Search 12-01-2017
1 9
1
9
vrmandadi
I have the below query index=abc sourcetype=xy.. |timechart span=1d count as events by host | addtotals time ...
by vrmandadi Builder in Splunk Search 12-01-2017
0 21
0
21
minura
I am trying to create a dashboard of CPU and Memory usage from some log files. Because of the way the data is inputte...
by minura Engager in Splunk Search 12-01-2017
0 7
0
7
mahbs
Hi, I'm trying to list data per field. I've used stats list which works partially, it lists all the data for both fi...
by mahbs Path Finder in Splunk Search 12-01-2017
0 11
0
11
smakwana
Hi Splunkers, I am looking for some help in modifying current regex to meet our updated project criteria. Link: htt...
by smakwana Explorer in Splunk Search 12-01-2017
1 5
1
5
dreschke
Hi Splunkers, I am looking for some help in creation of regular expression to Anonymize data with a regular expressi...
by dreschke Explorer in Splunk Search 11-30-2017
0 5
0
5
rfernandez2010
Hello I'm new to Splunk and I'm stuck trying to create what should be a simple table. Basically, I have a database o...
by rfernandez2010 New Member in Splunk Search 11-30-2017
0 1
0
1
katzr
Hello, I have a new set of users who I want to only be able to access 2 specific lookups. However, those lookups nee...
by katzr Path Finder in Splunk Search 11-30-2017
0 6
0
6
srobinsonxtl
All, I have the following Data: (192 of these) and trying to split the data into a multi-lined event, to extract th...
by srobinsonxtl Path Finder in Splunk Search 11-30-2017
0 9
0
9
splunker1981
Hello Splunk experts, I'm trying to figure out a better way to handle the large number of case statements that I wou...
by splunker1981 Path Finder in Splunk Search 11-30-2017
0 1
0
1
9738078959
i have a data like below.... ID | Name | 2017-12 |2018-01|2018-02|2018-03 X123 |aaa | 90 | ...
by 9738078959 Engager in Splunk Search 11-30-2017
0 9
0
9
JacobPN
Hi all, As I understand it, the cofilter command counts how many times pairs of items occur. If the same user views...
by JacobPN Path Finder in Splunk Search 11-30-2017
0 1
0
1
Mike6960
Is it possible to search results from a count when they are odd or even? So the results only show the lines/events wh...
by Mike6960 Path Finder in Splunk Search 11-30-2017
0 6
0
6
AnmolKohli
We have a requirement wherein we want to check if logs have not been updated in last 24 hours. There are around 20 in...
by AnmolKohli Explorer in Splunk Search 11-30-2017
0 1
0
1
jvmerilla
Hi, I'm doing some search query where I used timechart command that creates fields. Now, what I want to do is to som...
by jvmerilla Path Finder in Splunk Search 11-30-2017
0 3
0
3
cwl
以下のサーチ文で、regexreplacementプロセッサーがかなりのCPUリソースを使用していることまではわかりましたが、どのように問題のREGEXを特定できますでしょうか。 index=_internal source=*me...
by cwl Contributor in Splunk Search 11-30-2017
0 1
0
1
saurabhkunte
Hi All, I have a lookup table where I am maintaining States of a field. It's rather a chatty table and grows to a la...
by saurabhkunte Path Finder in Splunk Search 11-29-2017
0 1
0
1
timcolpo
I have the following SPL that is used to compute an average duration from events with 2 dates for the last 3 months. ...
by timcolpo Explorer in Splunk Search 11-29-2017
0 4
0
4
pavanae
I have defined a field extraction in a macro as below my_search | eval field_A="EventCode: " + EventCode + "; Event...
by pavanae Builder in Splunk Search 11-29-2017
0 2
0
2
mvagionakis
Hello, I'm trying to combine values from two events and to make a table with them. Let me explain you. I have the sa...
by mvagionakis Path Finder in Splunk Search 11-29-2017
0 9
0
9
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors