Splunk Search

Splunk Search
Community Activity
mlevsh
I have two fields, I need to compare, that contain an email address, but in different format: Format 1) firstname.las...
by mlevsh Builder in Splunk Search 10-19-2017
0 3
0
3
bbraun
Here is an overview of what I'm trying to accomplish. I have created a table that uses information in the threat acti...
by bbraun New Member in Splunk Search 10-19-2017
0 5
0
5
msarro
Hey everyone. Searching around, I see tons of answers related to converting numerical bytes into KB/MB/GB/TB. However...
by msarro Builder in Splunk Search 10-19-2017
0 5
0
5
bojanisch
Hi everyone, I'm looking forward to do some Data Science with Splunk and was very happy to read about the Metrics In...
by bojanisch Path Finder in Splunk Search 10-19-2017
0 1
0
1
wuming79
I wanted to reduce my storage space. I have already set retirement policy but my used space did not reduce although t...
by wuming79 Path Finder in Splunk Search 10-19-2017
0 1
0
1
wuming79
Hi, Referencing to http://docs.splunk.com/Documentation/Splunk/6.2.1/Capacity/Estimateyourstoragerequirements, I'm ...
by wuming79 Path Finder in Splunk Search 10-19-2017
0 1
0
1
ZacEsa
Hi, As the title says. Refer to the screenshot below too; The above is the log for the event. as you can see, ther...
by ZacEsa Communicator in Splunk Search 10-18-2017
0 3
0
3
samlinsongguo
I am doing field extraction for a log file format as below: line 1: field1, field2, field3, field4 line 2: field1, fi...
by samlinsongguo Communicator in Splunk Search 10-18-2017
0 3
0
3
kennethyeung
I have index data like below, and I want to calculate how many have a stock price higher than yesterday. date, stock,...
by kennethyeung New Member in Splunk Search 10-18-2017
0 6
0
6
stephenlclarke
I have data that looks like this: AA=value1,BB=value2,BB=value3,BB=value4 AA=value5,BB=value6,BB=value7 AA=value8,BB...
by stephenlclarke New Member in Splunk Search 10-18-2017
0 6
0
6
cspires64
I want to query the summary index and pull back KPIs with high alert severity. However, in order to do this I have to...
by cspires64 Path Finder in Splunk Search 10-18-2017
1 1
1
1
sheloaha
I have a list of files similar to this list: FileObjMgr_01235_567.log EIM_0080123_45.log EIM_01031234_56.log EIM_012...
by sheloaha Path Finder in Splunk Search 10-18-2017
0 6
0
6
yograjpatel
How to get the Total difference amount from DP - RF Search used: index=elm-*** | dedup transactionid | eval amount=...
by yograjpatel New Member in Splunk Search 10-18-2017
0 2
0
2
ankithreddy777
Hi As per the documentation given in Splunk "http://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventsto...
by ankithreddy777 Contributor in Splunk Search 10-18-2017
0 1
0
1
jamesmoriarty
Hello Splunk Community, I've tried to do my homework on the subject and I'm coming up short, so here I am. I'm a few...
by jamesmoriarty Explorer in Splunk Search 10-18-2017
0 5
0
5
agoktas
Do I need to do some fancy joined search here? I have values that will show in index 2, and I want to check index ...
by agoktas Communicator in Splunk Search 10-18-2017
0 3
0
3
gmg1956
Hi I'm new on Splunk It's possible to give an alias to a search? I'm trying to do something like this: index=Obs1 A...
by gmg1956 New Member in Splunk Search 10-18-2017
0 3
0
3
smilingajay
Hi !! I want to calculate TransactionEndTime-TransactionStartTime, where TransactionStartTime is in CaptureLocation=R...
by smilingajay New Member in Splunk Search 10-18-2017
0 1
0
1
a212830
Hi, I'm looking for options to validate that a UFW is running on servers, without actually logging into the server (...
by a212830 Champion in Splunk Search 10-18-2017
0 3
0
3
jmartens
I have defined a field extraction that seems to properly extract fields: EXTRACT-KVSAxis = KV(?:Blade)*(?<KVSAxis>[X...
by jmartens Path Finder in Splunk Search 10-18-2017
0 9
0
9
koljalauterbach
Hi everyone! I would like to format a result into a string and I don't even know where to start and if there even is...
by koljalauterbach New Member in Splunk Search 10-18-2017
0 2
0
2
mikefoti
I’m trying to troubleshoot my use of “inputlookup”. First I verify the following search works: index=ca cert_RN=”R...
by mikefoti Communicator in Splunk Search 10-18-2017
0 6
0
6
robertlynch2020
Hi I am updating a chart drilldown with a token, from "undefined" to "all" to "undefined". <option name="chartin...
by robertlynch2020 Influencer in Splunk Search 10-18-2017
0 8
0
8
zadenaji
My access_logs files are not being pulled constantly. There are large gaps between the pulling of logs. The logs ar...
by zadenaji Explorer in Splunk Search 10-18-2017
0 5
0
5
ecanmaster
Would it be possible to search for certain events within the raw data? For example, I need to find events with C:\Win...
by ecanmaster Explorer in Splunk Search 10-18-2017
0 6
0
6
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors