Splunk Search

Splunk Search
Community Activity
jhayIV
Using this query below could you help me identify servers that were added on a daily basis? example today is friday 1...
by jhayIV Engager in Splunk Search 10-14-2017
0 1
0
1
bryso25
Hello, Im very new with Splunk. Can you please tell me what is missing on my search string eventtype=security * use...
by bryso25 New Member in Splunk Search 10-14-2017
0 2
0
2
andrewtrobec
Hello All, I am trying to write a single rex command that will handle a number of different field entires. Basicall...
by andrewtrobec Motivator in Splunk Search 10-14-2017
0 2
0
2
agoktas
Hello, We have the following search: index="blah" | stats values(Change), values(Volume), values(Price) by Symbol...
by agoktas Communicator in Splunk Search 10-13-2017
0 2
0
2
rrustong
I'm having a difficult time getting what I believe is a simple eval command to work as I would expect. What I'm tryi...
by rrustong Explorer in Splunk Search 10-13-2017
0 3
0
3
markmcd
I am trying to extract a field from logs that look like this: Apr 28 07:45:22.992 On [2:18]20.5.4.1:5070 sent to 102...
by markmcd Path Finder in Splunk Search 10-13-2017
1 5
1
5
vasud
I have some device logs and am trying to determine the outage (downtime) duration.  Problem I have here is that event...
by vasud New Member in Splunk Search 10-13-2017
0 1
0
1
tonahoyos
I have the following search: index="data_integration" host="sampledata" sourcetype="csv" Object_Account="4*" OR Obje...
by tonahoyos Explorer in Splunk Search 10-13-2017
0 12
0
12
griffinpair
I want to use the count from the first search "FilesImported" as criteria in the where clause of the subsearch. Files...
by griffinpair Path Finder in Splunk Search 10-13-2017
0 2
0
2
splunkgk
What is the best way to delete or re-assign the orphaned searches?. I have around more than 100 orphaned searches whi...
by splunkgk Path Finder in Splunk Search 10-13-2017
0 2
0
2
safiasheikh
Hey, I am trying to drill down from one dashboard to another and show a table with the selected category in the tar...
by safiasheikh New Member in Splunk Search 10-13-2017
0 1
0
1
mightaswelby
Trying to compare response time from yesterday to today. This search seems to be working, but very, very slow. Any ...
by mightaswelby Explorer in Splunk Search 10-13-2017
0 4
0
4
archananaveen
eventtype=* |stats count by eventtype which works. However, in a dashboard below query doesn't work. Any suggestions...
by archananaveen Explorer in Splunk Search 10-13-2017
0 2
0
2
benbabich
I want to find all names in Account_Name that end with a $ and not ones that don't. IE: I want NAME1$ but not NAME2. ...
by benbabich Explorer in Splunk Search 10-13-2017
0 4
0
4
Parameshwara
My search result: _time Location Total 01/01/13 12:00:00.000 AM Location 1 12 02/01/13 ...
by Parameshwara Path Finder in Splunk Search 10-13-2017
0 5
0
5
kdimaria
So, I have a search query that calculates a field but I wanted to know if there is a way to check if it is a certain ...
by kdimaria Communicator in Splunk Search 10-13-2017
0 1
0
1
yograjpatel
{<!-- --> "ERROR_CODE" : "XXX-XXX-00000", "ERROR_DESC" : "Success." }, "accountBalances" : {<!-- --> "accountNumber13...
by yograjpatel New Member in Splunk Search 10-13-2017
0 7
0
7
Nadal7noval
I have a log mentioned below: ERROR: Cannot retrieve requested details in 103 ms cause: [50000] ERROR: Building prof...
by Nadal7noval New Member in Splunk Search 10-13-2017
0 2
0
2
IRHM73
Hi, I wonder whether someone can help me please. I'm using the query below to extract the different actions performe...
by IRHM73 Motivator in Splunk Search 10-13-2017
0 2
0
2
venu08673
HI, a&#61;0.54689556898 b&#61;1.25698 c&#61;0.5 d&#61;51 I want output like a&#61;0.54 b&#61;1.25 c&#61;0.50 d&#61;51.00 Please do needful, how t...
by venu08673 New Member in Splunk Search 10-13-2017
0 4
0
4
umsundar2015
Hi, When i run a search for 7 days , i am getting correct count for all 7 days .But when i run for 30 days then i am...
by umsundar2015 Path Finder in Splunk Search 10-13-2017
0 6
0
6
karthi2809
How to calculate response time for this particular event ? I used to transaction command to club the data for same t...
by karthi2809 Builder in Splunk Search 10-13-2017
0 1
0
1
chow11
In Splunk, how do I figure out which lookup .csv file a certain index is using? In other words, how to find which ind...
by chow11 New Member in Splunk Search 10-13-2017
0 8
0
8
sphc
Everything repeats from VULN to VULN It is necessary to pull out the Number of VULN, severity, cveid, CVSS_BASE, CON...
by sphc Explorer in Splunk Search 10-13-2017
0 3
0
3
snipedown21
I have a field outcomeIndicator in my data, that holds values 0,1,5,8. 0 and 1 mean a success of the event, and 5 an...
by snipedown21 Path Finder in Splunk Search 10-13-2017
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...