Splunk Search

Splunk Search
Community Activity
mmohiuddin1512
Hi All: I am unable to get the metadata host field in Splunk for the value of the database field called "HOSTNAME". ...
by mmohiuddin1512 Explorer in Splunk Search 10-25-2017
0 4
0
4
j_partsch
I have the following search index=firewall policy_name="/Common/default" request_status=blocked (violations="Access...
by j_partsch Explorer in Splunk Search 10-25-2017
0 2
0
2
nivethainspire_
My timechart is working perfectly for last 10 days but it is not working for time range above 15 days.Any idea to res...
by nivethainspire_ Explorer in Splunk Search 10-25-2017
0 3
0
3
SirHill17
Hi, I am trying to give cell value using drilldown as parameter to another dashboard. Below is how I have defined it:...
by SirHill17 Communicator in Splunk Search 10-25-2017
0 7
0
7
Mike6960
I have the following search: ..index bla bla... | eval eD_A=strptime(D_A, "%Y-%m-%d %H:%M:%S.%N") , eD_AV=strptime(D...
by Mike6960 Path Finder in Splunk Search 10-25-2017
0 6
0
6
hettervik
Hi, I've got these strange XML logs, where each log has (among other things) a username and an arbitrary number of h...
by hettervik Builder in Splunk Search 10-24-2017
0 6
0
6
jwalzerpitt
I am trying search events where the destination IP is in a lookup table consisting of a list of CIDR ranges (and thre...
by jwalzerpitt Influencer in Splunk Search 10-24-2017
0 5
0
5
katzr
So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup ...
by katzr Path Finder in Splunk Search 10-24-2017
0 1
0
1
deastman
$execution$ $host$ $user$ |eval moresearch=if(execution=index=index1,"",($authentication$) OR ($configuration$) OR ($...
by deastman Path Finder in Splunk Search 10-24-2017
0 11
0
11
AbubakarShahid
I am having issues with displaying data based off the results from the lookup table. I am using this search below, w...
by AbubakarShahid New Member in Splunk Search 10-24-2017
0 3
0
3
pavanae
I have a query as below | metadata type=hosts | search [| inputlookup hosts_test.csv | eval host=lower(my_hostname...
by pavanae Builder in Splunk Search 10-24-2017
0 2
0
2
serwin
I'm looking for a way to traffic the average ssh traffic between two IP addresses (source IP and destination IP) and ...
by serwin Explorer in Splunk Search 10-24-2017
0 1
0
1
splunkrocks2014
I have a data feed with CEF format. Splunk picks up the key value pairs except the value with the whitespaces, for i...
by splunkrocks2014 Communicator in Splunk Search 10-24-2017
0 5
0
5
siddharthmis
Hi, How do I get "7515-36283" between "Result:" and "/ Value" from following text: Result: 75153-6283 / Value "Res...
by siddharthmis Explorer in Splunk Search 10-24-2017
0 2
0
2
jared_anderson
I have a field with event IDs. Some of the IDs indicate an issue, while some of them indicate the opposite. eventid=...
by jared_anderson Path Finder in Splunk Search 10-24-2017
0 5
0
5
N92
I want to ignore below user name. So I written following manner is it correct? ......| where NOT (user="*$" OR user=...
by N92 Path Finder in Splunk Search 10-24-2017
0 1
0
1
florencegoh
I have list of lookup list yyyy which I want to shown the latest login based on max login time and also user that did...
by florencegoh New Member in Splunk Search 10-24-2017
0 7
0
7
nieivan
Hi I'm trying to combine fields in multiple search result in one output table as overall result, for example: Sear...
by nieivan New Member in Splunk Search 10-24-2017
0 2
0
2
splunk_worker
Hi I want identify the long running searches who are running more than 5 min and stop them. I'm able to find the l...
by splunk_worker Path Finder in Splunk Search 10-23-2017
1 4
1
4
vik123ash
Error: Update failed. First exception on row 0 with id abcd; first error: INVALID_EMAIL_ADDRESS, Email: invalid ema...
by vik123ash Explorer in Splunk Search 10-23-2017
0 3
0
3
rsokolova
Thanks in advance, Having a hard time trying to put 3 searches together to sum both search counts by PO. Please see ...
by rsokolova Path Finder in Splunk Search 10-23-2017
0 3
0
3
pavanae
I have a query as follows to display the list of hosts which are seen in last 24 hours and hosts which are not seen i...
by pavanae Builder in Splunk Search 10-23-2017
0 14
0
14
jared_anderson
I want to create charts based on number of results. I have tried "172.20.3.6 (199.0.8.62 OR 199.0.8.57) StoresOutBo...
by jared_anderson Path Finder in Splunk Search 10-23-2017
0 2
0
2
pavanae
I have a lookup search as follows |inputlookup hostnames.csv Which displays the results as follows my_hostname...
by pavanae Builder in Splunk Search 10-23-2017
0 5
0
5
ejespiritu
Hi All, Is there an easier way in designing the charts? What i've found is using css but building one from scratch...
by ejespiritu Explorer in Splunk Search 10-23-2017
0 8
0
8
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...