Splunk Search

Splunk Search
Community Activity
mseidel
Hello everybody, I am new to Splunk and I try to anonymize an email adress of my Logfile with the help of files pro...
by mseidel New Member in Splunk Search 11-13-2017
0 2
0
2
Kaushikkatta03
Below is the error we got [hsplunkp01] Dispatch Runner: Configuration initialization for /opt/splunk/var/run/search...
by Kaushikkatta03 Explorer in Splunk Search 11-13-2017
0 1
0
1
dbcase
Hi, I have this data Time Event 11/13/17 5:12:53.000 PM { [-] analyticType: SessionEnd bui...
by dbcase Motivator in Splunk Search 11-13-2017
0 3
0
3
lordhans
The Splunk logs I'm working with are big and don't come with any predefined useful fields. I want to extract a dynami...
by lordhans Explorer in Splunk Search 11-13-2017
0 2
0
2
ddrillic
The following | rex "^(?:[^,\n]*,){8}\"\w+\":\"/(?P<apiURL3>\w+/\w+/\w+/\w+\.\d+/\w+\.\w+)" produces for us the desir...
by ddrillic Ultra Champion in Splunk Search 11-13-2017
0 9
0
9
shikhanshu
Within the same index and sourcetype, I have some rows containing type=master and many more rows containing type=slav...
by shikhanshu Path Finder in Splunk Search 11-13-2017
0 1
0
1
cyberhumint
What would be the correct expression to extract only the email address that follows "email="? I then want to call tha...
by cyberhumint New Member in Splunk Search 11-13-2017
0 9
0
9
skoelpin
I made a dashboard with a single base search passing the results to downstream panels. When I make my panels dependen...
by SplunkTrust SplunkTrust in Splunk Search 11-13-2017
1 8
1
8
danielgp89
Hello Everyone! I want to remove the first two letters from my fields "\n" how can I do it? \nCDIARIA2 \nCDIARIAC \...
by danielgp89 Path Finder in Splunk Search 11-13-2017
0 11
0
11
nmayafit
Hi, I have log line according to the next template: [2017-11-03 13:55:52,945] [MYPROJ] [EMAIL=xxx@yyy.com] But I wa...
by nmayafit Path Finder in Splunk Search 11-13-2017
0 4
0
4
splunker969
Hi , I have a list of firewall hosts names and some ips of firewall and i created the lookup of all host names of fir...
by splunker969 Communicator in Splunk Search 11-13-2017
1 5
1
5
bcyates
I have a lookup table with personal financial transactions on it. They list like they do when you review transactions...
by bcyates Communicator in Splunk Search 11-13-2017
0 3
0
3
samsingnok52
Error : " Error 'Could not find all of the specified lookup fields in the lookup table.' for conf '(?::){0}XmlWinEve...
by samsingnok52 Engager in Splunk Search 11-13-2017
0 1
0
1
blairmd
Hello friendly Splunk community, May I ask your assistance in dealing with a multivalue field that sometimes contain...
by blairmd New Member in Splunk Search 11-13-2017
0 4
0
4
zacksoft
I have a query that gives me the count of certain events with keyword 'ab' OR with keyword 'pq'. The query is like th...
by zacksoft Contributor in Splunk Search 11-13-2017
0 7
0
7
zacksoft
My splunk query is , host=x OR host=y OR host=z nfs1 | stats count as nfs1_count In the above case nfs1 field is s...
by zacksoft Contributor in Splunk Search 11-13-2017
0 34
0
34
a212830
Hi, How would I count a combination of fields in splunk? For example, I have a "from_ip_addr" and a "to_ip_addr" in ...
by a212830 Champion in Splunk Search 11-12-2017
0 6
0
6
behudelson
I have a very large set of retail data. The significant fields for this query are store_no, transaction_amt, zip, eth...
by behudelson Path Finder in Splunk Search 11-12-2017
0 3
0
3
abdulvehhaba
Hi I want to calculate/simulate a data to analysis price difference, my data set in picture, Process like this ...
by abdulvehhaba Path Finder in Splunk Search 11-12-2017
0 5
0
5
matansocher
Hi, I have a data that contains the field 'regression_target'. I want to get the top 10 rows by 'regression_tests' f...
by matansocher Contributor in Splunk Search 11-12-2017
0 3
0
3
JgTheGreat
Hello All, Sorry relativly new to splunk - and so this query may be a pile of garbage! To sumerise, i have a query ...
by JgTheGreat Engager in Splunk Search 11-12-2017
0 3
0
3
FrankSPL
Hi All, I have a large data set with lots of fields and I want that in a table. However this is not working correctl...
by FrankSPL Path Finder in Splunk Search 11-12-2017
0 3
0
3
JgTheGreat
Hello, I'm looking for a query, which looks for successful [ or unsuccessful ] brute force attempts, and then to ta...
by JgTheGreat Engager in Splunk Search 11-11-2017
0 3
0
3
MonkeyK
Sometimes I write a brutal search that takes a very long time to run and then realize that I need to do something mor...
by MonkeyK Builder in Splunk Search 11-10-2017
0 2
0
2
kunalpatil111
|tlp|lasttime|reporttime|count|itype|indicator|cc|asn|asn_desc|confidence|description|tags|rdata| provider .... i ha...
by kunalpatil111 New Member in Splunk Search 11-10-2017
0 2
0
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...