Splunk Search

Splunk Search
Community Activity
mkrauss1
Assume the following records: Nov 17 19:24:51 x.x.x.x Nov 17 19:24:51 myserver (appx): 1510943091.801 520 192.168.0....
by mkrauss1 Explorer in Splunk Search 11-17-2017
0 5
0
5
obiwan1129
I have a query I'm working on where not all the values I feed it are in the index I am querying against. For examp...
by obiwan1129 New Member in Splunk Search 11-17-2017
0 1
0
1
johnansett
Hey guys, Looking for some help with a search. When a user starts first logs into an application to on board themse...
by johnansett Communicator in Splunk Search 11-17-2017
0 5
0
5
agdavidson
Hi there. I am new to SPL and wondering how to make a particular query more efficient. In particular, I want to creat...
by agdavidson New Member in Splunk Search 11-17-2017
0 1
0
1
ddrillic
We have a couple of automatic lookups and I don't see them in the SH under /opt/splunk/etc/apps/<app_name>/lookups W...
by ddrillic Ultra Champion in Splunk Search 11-17-2017
1 3
1
3
varunghai
Hi, i want to combine the results from my search query with a lookup table that i have uploaded. They both have 1 co...
by varunghai Engager in Splunk Search 11-17-2017
0 5
0
5
surekhasplunk
Hi, I have a calculated field call Percentage which is required for other calculations but i dont want that value...
by surekhasplunk Communicator in Splunk Search 11-17-2017
0 5
0
5
maniishpawar
Hi I have this query and trying to do a eval case on the rex field value returned base | rex "#TAGRESPONSE.*RESPONSE...
by maniishpawar Path Finder in Splunk Search 11-17-2017
1 7
1
7
guilmxm
Hi, I have a strong request from my client that wants to be to be able to view events resulting from a SPL search in...
by guilmxm Influencer in Splunk Search 11-17-2017
0 2
0
2
surekhasplunk
I have a dashboard table with fields like below. Area field2 filed3 UK 100 200 US 300 400 In the dri...
by surekhasplunk Communicator in Splunk Search 11-17-2017
0 14
0
14
koshyk
Hi We have a regex/requirement to extract col1,col2,col3,col4 everytime. But the data may not contain col3 onwards ev...
by koshyk Super Champion in Splunk Search 11-17-2017
0 2
0
2
jrfrost
I have a field extraction that gets the message number from the raw message string .{22}\s0-9 The message string is...
by jrfrost Explorer in Splunk Search 11-17-2017
1 3
1
3
krishnakanthgup
In general after we make changes in .conf files splunk instance should restart. If we deploy splunk in production en...
by krishnakanthgup New Member in Splunk Search 11-17-2017
0 3
0
3
5plunked
hi, I have searched high and low for the instructions but cant seem to find the settings for enabling the search he...
by 5plunked Explorer in Splunk Search 11-16-2017
0 2
0
2
super_virus
Hi , Very new to splunk. I need to search a index with two strings example: "ABC1" "XVZ2" And create a line graphs...
by super_virus New Member in Splunk Search 11-16-2017
0 2
0
2
stakor
So, I am going through windows logs, and have output that works for me with something like: index=windows sourcetype...
by stakor Path Finder in Splunk Search 11-16-2017
0 1
0
1
JoshuaJohn
I am not sure why I am not getting results with this query, any suggestions? index= ______ | stats max(_time) as las...
by JoshuaJohn Contributor in Splunk Search 11-16-2017
1 1
1
1
eransh10
Hi splunk guru's. I'm trying to find a way (using SPL only - i am not an admin) to do the following: My vulnerability...
by eransh10 New Member in Splunk Search 11-16-2017
0 2
0
2
abdulvehhaba
Hi I want to calculate/simulate a data to analysis price difference, my data set in picture, left is my data set, r...
by abdulvehhaba Path Finder in Splunk Search 11-16-2017
0 6
0
6
abdulvehhaba
Hi I have data like this I am joined uuid over market data together like that But there is 4 times date column...
by abdulvehhaba Path Finder in Splunk Search 11-16-2017
0 5
0
5
splunkreal
Hello guys, I'd like to check changes on the Checkpoint firewall logs but I haven't any result : index=xxx host=yyy...
by splunkreal Influencer in Splunk Search 11-16-2017
0 1
0
1
oneillryan93
I'm attempting to use a subsearch to extract a number of integers in order to transpose those integers as columns. He...
by oneillryan93 New Member in Splunk Search 11-16-2017
0 1
0
1
romgo75
Hello, On my servers I used combined Apache logs, but I added two other fields at the end of the logs : SSL_PROTOCOL...
by romgo75 New Member in Splunk Search 11-16-2017
0 2
0
2
yoyu777
Hi, This question may be a bit unusual. While I know SPL is already kind of "simple" enough to get a hang of for mos...
by yoyu777 Explorer in Splunk Search 11-16-2017
0 4
0
4
splunker1981
Hello Splunkers - Can't figure out for the life of me how to use eval or if statement to call a custom search comma...
by splunker1981 Path Finder in Splunk Search 11-16-2017
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors