Splunk Search

Splunk Search
Community Activity
sh254087
I have a lookup table that looks like this: Variable1---variable2---Score 0--- null ---3 0---500---2 500---100...
by sh254087 Communicator in Splunk Search 10-30-2017
0 1
0
1
Admiral_Marith
Right now I am tasked with creating a report for a department showing who is using elevated privileges in Linux and f...
by Admiral_Marith Explorer in Splunk Search 10-30-2017
0 2
0
2
jayakumar89
I have a single row event that populates the below values and i would like to extract eventid=389643 and STATUS=FINIS...
by jayakumar89 Explorer in Splunk Search 10-30-2017
0 3
0
3
jamesrender
How do I go from: ”metrics=[a=1,b=2,c=3]” ”metrics=[a=2,b=5,c=6]” ”metrics=[a=1,c=3,c=4]” To: “a,b,c” “1,2,3”...
by jamesrender New Member in Splunk Search 10-30-2017
0 12
0
12
arpit_arora
Hello, I am reading the following resource from Splunk documentation and I find that there are 8 types of searches in...
by arpit_arora Explorer in Splunk Search 10-30-2017
0 3
0
3
atulitm
day_receive_time="Wed, Oct 25, 2017" device_name="apple" app="mssql-db" bandwidth_consumption="161" day_receive_time...
by atulitm Path Finder in Splunk Search 10-30-2017
0 8
0
8
jurjenterpstra
I'm trying to replace the "\x22" entries in my raw results with the correct quotation marks so I can read the the ful...
by jurjenterpstra New Member in Splunk Search 10-30-2017
0 3
0
3
mahbs
Hi, I'm having a bit of trouble with this query of mine. source="xxx" host="xxx" index="xxx" sourcetype="xxx" earl...
by mahbs Path Finder in Splunk Search 10-30-2017
0 8
0
8
blurblebot
Short and sweet: Why does the search: bf=1 (no quotes) take so much longer to run than "bf=1" (with quotes?) ...
by blurblebot Communicator in Splunk Search 10-30-2017
4 2
4
2
florencegoh
Hi, I want to shown the Total as 0 if username in lookup table has not event log . Using the fillnull value , it does...
by florencegoh New Member in Splunk Search 10-30-2017
0 8
0
8
mrccasi
Hi, How can I turn multiple rows into a single row? For example, Name Skill1 Skill2 Skill3 Shine Oracle Shine ...
by mrccasi Explorer in Splunk Search 10-30-2017
0 4
0
4
Rialf1959
Hello, How to sums values from fields that may not exists? I want to sums fields (if exists ) with this pattern: netw...
by Rialf1959 Explorer in Splunk Search 10-30-2017
0 4
0
4
MonkeyK
I am trying to write some beaconing reports/dashboards. I have a few of them figured out, but now I am stuck trying ...
by MonkeyK Builder in Splunk Search 10-29-2017
0 1
0
1
tmarlette
So here's my workflow. I have a request from an outside source that wants me to scrub my data for certain IP addres...
by tmarlette Motivator in Splunk Search 10-29-2017
0 6
0
6
jorjiana88
Hi, I am trying to make a table that shows the logins outside of business hours, and to show besides if the user had...
by jorjiana88 Path Finder in Splunk Search 10-29-2017
0 1
0
1
atulitm
day_receive_time="Wed, Oct 25, 2017" device_name="apple" app="mssql-db" bandwidth_consumption="161" day_receive_time...
by atulitm Path Finder in Splunk Search 10-28-2017
0 3
0
3
vivek_manoj
I am trying to validate the testbox to accept only numeric not any other character. How to do that? Thanks in Advance...
by vivek_manoj Explorer in Splunk Search 10-28-2017
0 10
0
10
cdo_splunk
How to run multiple splunk 6.2 instances on Windows?
by cdo_splunk Splunk Employee Splunk Employee in Splunk Search 10-28-2017
2 6
2
6
avishek08
I need help extracting alert numbers from these different raw logs. I have tried using Field extractor and not having...
by avishek08 New Member in Splunk Search 10-27-2017
0 3
0
3
Mat93
Hi, I created a source type. Then I created new fields using delimiters. I would like to delete those fields but I c...
by Mat93 New Member in Splunk Search 10-27-2017
0 4
0
4
bgill0123
I have an index called weblogs and a csv lookup called socialmedia that contains 3 columns called URL TYPE and NAME....
by bgill0123 Loves-to-Learn in Splunk Search 10-27-2017
0 1
0
1
jimm
So I have events that have the following consistent layout: {value=1, key=a}, {value=2, key=b}, {value=3, key=c}, {v...
by jimm Explorer in Splunk Search 10-27-2017
0 3
0
3
mdavis43
I have a search that currently has 3 search terms... host="s2a*" "Command Aborted" OR "Internal queue full" OR "Abor...
by mdavis43 Path Finder in Splunk Search 10-27-2017
0 4
0
4
rookie507SL
Hi mates, I'm figuring out how I can show a table with matching IP addresses from 2 different vendor firewalls. So ...
by rookie507SL New Member in Splunk Search 10-27-2017
0 6
0
6
tonahoyos
Hello All, I am having an issue using the stats sum command. This is currently my search: source="Jan_Sept_FinanceS...
by tonahoyos Explorer in Splunk Search 10-27-2017
0 6
0
6
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...