Splunk Search

Splunk Search
Community Activity
Carolina
Hi, Use a regex to extract some fields from my log with the regex101.com tool. but when I do the search for the mix ...
by Carolina Engager in Splunk Search 11-14-2017
0 3
0
3
FrankSPL
Hi all, I have some issues with the results from using | table * I start with a simple data selection: source...
by FrankSPL Path Finder in Splunk Search 11-14-2017
0 2
0
2
syokota_splunk
Hi regex masters, Please help me. Below are sample xml logs. Incident Number: 151719935 Date Of Incident: 12/02...
by syokota_splunk Splunk Employee Splunk Employee in Splunk Search 11-14-2017
0 9
0
9
tpirozzi
Hi Everyone, So I have data like this in my lookup table fields A | B | C 10| 2 | red 4 | 6 | red 9 | 1 | red...
by tpirozzi Explorer in Splunk Search 11-14-2017
0 1
0
1
erikwie
Upgraded from 6.1 to 7.0 and now none of my old searches gives any results i.e dashboard searces. As a Splunk rookie...
by erikwie Path Finder in Splunk Search 11-14-2017
0 4
0
4
lordhans
My organization using something called Ticketer to in Splunk to auto-generate an incident form when something shows u...
by lordhans Explorer in Splunk Search 11-13-2017
0 3
0
3
Mike6960
I've got the followingsearch: | stats values earliest(AG_Z) AS A_Z values earliest(D_AG) AS D_A_I | eval eA_Z=strpt...
by Mike6960 Path Finder in Splunk Search 11-13-2017
0 13
0
13
GaneshK
From NFR perspective trying to figure out how to use Splunk to extract user behavior pattern during peak load conditi...
by GaneshK New Member in Splunk Search 11-13-2017
0 2
0
2
jpayne1
list(x) does not return all values. If I have white space as my value, list omits it. Here is a simplified example of...
by jpayne1 New Member in Splunk Search 11-13-2017
0 2
0
2
mseidel
Hello everybody, I am new to Splunk and I try to anonymize an email adress of my Logfile with the help of files pro...
by mseidel New Member in Splunk Search 11-13-2017
0 2
0
2
Kaushikkatta03
Below is the error we got [hsplunkp01] Dispatch Runner: Configuration initialization for /opt/splunk/var/run/search...
by Kaushikkatta03 Explorer in Splunk Search 11-13-2017
0 1
0
1
dbcase
Hi, I have this data Time Event 11/13/17 5:12:53.000 PM { [-] analyticType: SessionEnd bui...
by dbcase Motivator in Splunk Search 11-13-2017
0 3
0
3
lordhans
The Splunk logs I'm working with are big and don't come with any predefined useful fields. I want to extract a dynami...
by lordhans Explorer in Splunk Search 11-13-2017
0 2
0
2
ddrillic
The following | rex "^(?:[^,\n]*,){8}\"\w+\":\"/(?P<apiURL3>\w+/\w+/\w+/\w+\.\d+/\w+\.\w+)" produces for us the desir...
by ddrillic Ultra Champion in Splunk Search 11-13-2017
0 9
0
9
shikhanshu
Within the same index and sourcetype, I have some rows containing type=master and many more rows containing type=slav...
by shikhanshu Path Finder in Splunk Search 11-13-2017
0 1
0
1
cyberhumint
What would be the correct expression to extract only the email address that follows "email="? I then want to call tha...
by cyberhumint New Member in Splunk Search 11-13-2017
0 9
0
9
skoelpin
I made a dashboard with a single base search passing the results to downstream panels. When I make my panels dependen...
by SplunkTrust SplunkTrust in Splunk Search 11-13-2017
1 8
1
8
danielgp89
Hello Everyone! I want to remove the first two letters from my fields "\n" how can I do it? \nCDIARIA2 \nCDIARIAC \...
by danielgp89 Path Finder in Splunk Search 11-13-2017
0 11
0
11
nmayafit
Hi, I have log line according to the next template: [2017-11-03 13:55:52,945] [MYPROJ] [EMAIL=xxx@yyy.com] But I wa...
by nmayafit Path Finder in Splunk Search 11-13-2017
0 4
0
4
splunker969
Hi , I have a list of firewall hosts names and some ips of firewall and i created the lookup of all host names of fir...
by splunker969 Communicator in Splunk Search 11-13-2017
1 5
1
5
bcyates
I have a lookup table with personal financial transactions on it. They list like they do when you review transactions...
by bcyates Communicator in Splunk Search 11-13-2017
0 3
0
3
samsingnok52
Error : " Error 'Could not find all of the specified lookup fields in the lookup table.' for conf '(?::){0}XmlWinEve...
by samsingnok52 Engager in Splunk Search 11-13-2017
0 1
0
1
blairmd
Hello friendly Splunk community, May I ask your assistance in dealing with a multivalue field that sometimes contain...
by blairmd New Member in Splunk Search 11-13-2017
0 4
0
4
zacksoft
I have a query that gives me the count of certain events with keyword 'ab' OR with keyword 'pq'. The query is like th...
by zacksoft Contributor in Splunk Search 11-13-2017
0 7
0
7
zacksoft
My splunk query is , host=x OR host=y OR host=z nfs1 | stats count as nfs1_count In the above case nfs1 field is s...
by zacksoft Contributor in Splunk Search 11-13-2017
0 34
0
34
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors