Splunk Search

Splunk Search
Community Activity
deastman
I have an input lookup file. Say 'ApprovedUsers.csv'. This contains a single field SamAccountName. I want to c...
by deastman Path Finder in Splunk Search 11-22-2017
0 7
0
7
Naren26
Assume, I have two panels - PanelA, PanelB. I have to show the result in PanelA only if the event for train is more r...
by Naren26 Path Finder in Splunk Search 11-22-2017
0 5
0
5
dbcase
Hi, I have this query index=wholesale_app buildTarget=comcast analyticType=SessionStart |rename Properties.platfo...
by dbcase Motivator in Splunk Search 11-22-2017
0 2
0
2
rzhang520
Hi, I have a form has field inputs and a panel to display the search results in a table. Our users are complainting ...
by rzhang520 Engager in Splunk Search 11-21-2017
0 6
0
6
doweaver
I'm attempting to create a field extraction from the web UI (I'm not an admin and don't have access to "*.conf" files...
by doweaver Path Finder in Splunk Search 11-21-2017
1 10
1
10
bcarnot
I have this start event. I am using the "Phonecall" as the key in the transaction. 1. InteractionEvent on Phonecall-...
by bcarnot Path Finder in Splunk Search 11-21-2017
0 4
0
4
nishitdarade
Hi Splunkers, I am looking for some help in creation of regular expression to Anonymize data with a regular expressi...
by nishitdarade Explorer in Splunk Search 11-21-2017
0 9
0
9
saifullakhalid
This is what I am doing extract value until the first occurrence of char & using the search string index="prod_c...
by saifullakhalid Explorer in Splunk Search 11-21-2017
0 12
0
12
howardsamuels
Trying to search a connections log, top 10 hosts sending the most traffic, need some help, thanks.
by howardsamuels New Member in Splunk Search 11-21-2017
0 3
0
3
varunghai
Hi, I have created a query to fetch the status of some jobs in a particular format. There are different scheduled jo...
by varunghai Engager in Splunk Search 11-21-2017
0 2
0
2
gcescatto
Hi! I'm having trouble removing the values 0.5, 1 and 1.5 from the Y-axis in the following dashboard: But I need i...
by gcescatto New Member in Splunk Search 11-21-2017
0 1
0
1
robertlynch2020
Hi I have set up a data model and I am reading in millions of data lines. The issue is some data lines are not disp...
by robertlynch2020 Influencer in Splunk Search 11-21-2017
1 2
1
2
deepa_purushoth
For example, Category | CategoryGroup |Price AAA|Apple |80 AAA|Apple |90 BBB|Banana|40 BBB|Butterfruit|90 I want to ...
by deepa_purushoth Engager in Splunk Search 11-21-2017
0 6
0
6
ansif
Hi All, Please help me to extract the email ids which is not between <> angle brackets. Sample event: someone@doma...
by ansif Motivator in Splunk Search 11-21-2017
0 7
0
7
anuremanan88
We are collecting logs from McAfee and Splunk pulls information for each host every 1 Hr. The logs have two fields ho...
by anuremanan88 Explorer in Splunk Search 11-21-2017
0 9
0
9
cameronwt
I am working with Exchange 2010 data. I have the MessageID, Sender, Recipients, and _time. Depending on the event typ...
by cameronwt Engager in Splunk Search 11-21-2017
0 1
0
1
jrodriguezap
Hello I'm trying to do a substr to strings such as: google-public-dns-b.google.com cachewas.tdp.net.pe b.resolvers.L...
by jrodriguezap Contributor in Splunk Search 11-21-2017
0 5
0
5
Mike6960
In the following search I want to have the average for the events where GB_w is < 15 days | stats earliest(A_Z) AS A...
by Mike6960 Path Finder in Splunk Search 11-21-2017
0 1
0
1
AKG1_old1
Hi, My requirement is to set some token based on the output of search query. my search query return one row and I wa...
by AKG1_old1 Builder in Splunk Search 11-21-2017
1 3
1
3
sangs8788
I have below event from GC log, 2017-11-20T23:13:13.311-0800: 205957.353: [GC (Allocation Failure) 5152315K->4647798...
by sangs8788 Communicator in Splunk Search 11-21-2017
0 2
0
2
chaitalynavare
How can I get results only when 3 consecutive files exceeds 1 KB limit? I tried this with below Query however not ge...
by chaitalynavare Engager in Splunk Search 11-21-2017
0 4
0
4
Kitteh
As stated I want the latest value in "Hash Value" and "Type" column to be filled instead of being "NA" and "Unknown" ...
by Kitteh Path Finder in Splunk Search 11-21-2017
0 9
0
9
jared_anderson
Data: Nov 16 12:50:51 172.23.0.29 Nov 16 12:50:51 dc01 Microsoft_Windows_security_auditing.[1688]: Domain\user1: Secu...
by jared_anderson Path Finder in Splunk Search 11-20-2017
0 8
0
8
mohan_ac
We have few custom apps in our splunk enterprise instance which were opening to all user before. Suddenly custom apps...
by mohan_ac Explorer in Splunk Search 11-20-2017
0 1
0
1
kiran331
Hi, I'm ingesting the data in JSON format. we have a field event.user, which is auto extracted. is there a way to ex...
by kiran331 Builder in Splunk Search 11-20-2017
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...