Splunk Search

Splunk Search
Community Activity
youngsuh
Hi, communities,I am doing a calculation or eval command.    | eval dormancy=if(last_login="(never)",round((now()-str...
by youngsuh Contributor in Splunk Search 12-20-2023
0 1
0
1
nyajoefit22
Hello,I am trying to blacklist winevent code 4679 by   TaskCategory=Kerberos Service Ticket Operations. This regex is...
by nyajoefit22 Loves-to-Learn Lots in Splunk Search 12-20-2023
0 3
0
3
shruti14
Hi,So i have below base query :| inputlookup abc.csv where DECOMMISSIONED=N | fields DATABASE DB_VERSION APP_NAME ACT...
by shruti14 Explorer in Splunk Search 12-20-2023
0 1
0
1
mnj1809
Hello, I know that  mvsort command sort values lexicographically.But I want the output as below:62.0.3.7563.0.3.8475....
by mnj1809 Path Finder in Splunk Search 12-20-2023
0 9
0
9
Questioner
I try to make box plot graph using <viz>However, My code have this error,"Error in 'stats' command: The number of wil...
by Questioner Path Finder in Splunk Search 12-19-2023
0 2
0
2
mark_groenveld
I have a key called messageInside the value are several results but I need to only extract one result in the middle o...
by mark_groenveld Path Finder in Splunk Search 12-19-2023
0 2
0
2
michaeler
I'm trying to have a timechart showing the count of events by a category grouped by week. The search time is controll...
by michaeler Communicator in Splunk Search 12-19-2023
0 3
0
3
El_Franco
I have an index set up that holds a number of fields, one of which is a comma separated list of reference numbers and...
by El_Franco Explorer in Splunk Search 12-19-2023
0 3
0
3
ramkyreddy
this is my end_time: 1703027679.5678809After this query, it showed this output but i am getting the 1969 format| eval...
by ramkyreddy Explorer in Splunk Search 12-19-2023
0 1
0
1
ramkyreddy
TC Execution Summary for Last QuarterNo. of job runsAUSJERINDASIAugust150121110200Sept200140150220Oct100160130420I wa...
by ramkyreddy Explorer in Splunk Search 12-19-2023
0 4
0
4
riz1
0
1
MirrorCraze
I have a data like this.{     ...   name: AppName   metrics: {<!-- -->     data: [       {          details: { ...         } ...
by MirrorCraze Explorer in Splunk Search 12-18-2023
0 5
0
5
WanLohnston
Hi all, I have this query:| timechart span&#61;1s count AS TPS| eventstats max(TPS) as MaxPeakTPS| stats avg(TPS) as avgT...
by WanLohnston Explorer in Splunk Search 12-18-2023
0 4
0
4
LearningGuy
HelloWhen I turned on Total for Statistics under Format &gt; Summary, the output shows long digit after decimal point: T...
by LearningGuy Motivator in Splunk Search 12-18-2023
0 13
0
13
Dharani
Hi,below are the log details.index&#61;ABC sourcetype&#61;logging_0Below are the values of "ErrorMessages" field:invalid - 5 ...
by Dharani Path Finder in Splunk Search 12-18-2023
0 6
0
6
avi7326
This is my source code&lt;/search&gt;        &lt;option name&#61;"charting.chart"&gt;column&lt;/option&gt;        &lt;option name&#61;"charting.dr...
by avi7326 Path Finder in Splunk Search 12-18-2023
0 3
0
3
Pratyusha
Hi Everyone,I have a column chart for the below query. As shown in the below screenshot, the x-axis label is sorted i...
by Pratyusha Engager in Splunk Search 12-17-2023
0 2
0
2
balcv
I have a search that returns a list of users and the country logins have occurred from grouped by user.index&#61;o365 Use...
by balcv Contributor in Splunk Search 12-17-2023
0 2
0
2
diskioinferno
I have 2 multivalue fields (old and new) containing group lists for 1 or more users. The new values is the list of gr...
by diskioinferno Engager in Splunk Search 12-17-2023
0 3
0
3
Poojitha
Hi All,I am facing error using wildcard in multivalue field. I am using mvfind to find a string.  eval test_loc&#61;case(...
by Poojitha Communicator in Splunk Search 12-16-2023
0 7
0
7
nithys
Hi Team,I am using a query which has same index and source but fetch two results based on the search and combine to a...
by nithys Communicator in Splunk Search 12-16-2023
0 3
0
3
murad
HiKinda a new to splunk . Sending data to splunk via HEC. Its a DTO which contains various fields, one of them being ...
by murad Observer in Splunk Search 12-16-2023
0 3
0
3
mohammadsharukh
Dear All,Scenario--&gt; 1AV server is having multiple endpoint reporting to it. This AV server integrated with Splunk an...
by mohammadsharukh Path Finder in Splunk Search 12-16-2023
0 1
0
1
nkavouris
I have a search as follows:index&#61;*|search sourcetype&#61;*|spath logs{} output&#61;logs|spath serial_number output&#61;serial_num...
by nkavouris Path Finder in Splunk Search 12-15-2023
0 2
0
2
GaetanVP
Hello Splunkers,I have a Splunk HF that will receive multiple logs coming from different machines, all sending via UD...
by GaetanVP Contributor in Splunk Search 12-15-2023
1 4
1
4
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...