Splunk Search

Splunk Search
Community Activity
Muthu_Vinith
Hi, I have two datasets for example –1.Index=abc host=def_inven, consider as Dataset A (inventory with 100 servers) a...
by Muthu_Vinith Path Finder in Splunk Search 12-09-2023
0 7
0
7
AK89
Looking for help with this rex command. I want to capture the continuous string after "invalid user" whether it has s...
by AK89 Explorer in Splunk Search 12-08-2023
0 3
0
3
smanojkumar
Hi There!   I'm facing the error "Search is waiting for the input"<form stylesheet="dashboard.css,infobutton.css" scr...
by smanojkumar Contributor in Splunk Search 12-08-2023
0 1
0
1
bharath_hk12
Hi,I have logger statements like below:Event data - {"firstName":"John","lastName":"Doe"} My query needs <rex-stateme...
by bharath_hk12 Explorer in Splunk Search 12-08-2023
0 7
0
7
vamshikn72
What is the character limit of an alert name in splunk ES?
by vamshikn72 Explorer in Splunk Search 12-07-2023
0 2
0
2
jwhughes58
I've got this searchindex=main sourcetype="bigfix" | eval raw=_raw | rex mode=sed field=raw "s/\n/ /g" | rex field=...
by jwhughes58 Contributor in Splunk Search 12-07-2023
0 1
0
1
a212830
Hi, I'm configuring some new roles, and came across the "schedule_rtsearch" capability. The doc simply says "Lets t...
by a212830 Champion in Splunk Search 12-07-2023
1 6
1
6
RENUKA1
Hello All, I need to convert the Timeline with different times into one.For example:12:05AM 12:10AM 12:15AM should be...
by RENUKA1 Loves-to-Learn Lots in Splunk Search 12-07-2023
0 3
0
3
Chandrasekhar6
index=cs | rex "Type=(?<type>[a-z]+)" | rex field=AResponse.BResponse.Message mode=sed "s/Ref number+\w+\sfailed on ...
by Chandrasekhar6 Explorer in Splunk Search 12-07-2023
0 4
0
4
Bo3432
I am trying to remove window EventCodes 4688 and 4627. Nothing I have tried has worked. Her are the things that I hav...
by Bo3432 Explorer in Splunk Search 12-07-2023
0 4
0
4
PiotrAp
Hi,I'm trying to create a query which will display events matching following conditions: 5 or more different destinat...
by PiotrAp Path Finder in Splunk Search 12-07-2023
0 2
0
2
MirrorCraze
I have some search before, and after I extract fields (name, status) from json and mvzip it together, I got this tabl...
by MirrorCraze Explorer in Splunk Search 12-07-2023
0 4
0
4
alexc
Hello all! This will be a doozy, so get ready. We are running a search with tstats generated results,  from various t...
by alexc New Member in Splunk Search 12-06-2023
0 0
0
0
Bo3432
Hello,I am trying to find a command that will allow me to create a table and only display values. when using the user...
by Bo3432 Explorer in Splunk Search 12-06-2023
0 5
0
5
ZYSanshou
So when an upstream error is logged in our splunk it has two fields that contain all the information about the error....
by ZYSanshou Engager in Splunk Search 12-06-2023
0 2
0
2
NightShark
Hello,The rex command to catch and group the Accesses multi values are not working even though the results in regex10...
by NightShark Path Finder in Splunk Search 12-06-2023
0 2
0
2
ripson
I am using Splunk 9.0.4 and I need to make a query where I extract data from a main search.So I am interested in resu...
by ripson Engager in Splunk Search 12-06-2023
0 2
0
2
Jack_Accent
Hello! Still very new to Splunk so hoping to get some clarification.My dashboard is currently using a post-process se...
by Jack_Accent Loves-to-Learn in Splunk Search 12-06-2023
0 1
0
1
nehamvinchankar
Hi all, i want to extract fields from event which is in json format INFO [processor: anchsdgeiskgcbc/5; event: 1-57d2...
by nehamvinchankar Path Finder in Splunk Search 12-06-2023
0 5
0
5
siva_cg
Hi, I am trying to create a report in which I would like to get the field value by looking into a range of values th...
by siva_cg Path Finder in Splunk Search 12-05-2023
0 13
0
13
RJ_10
can anyone please tell me  the scenario based interview questions for splunk admin role ?
by RJ_10 New Member in Splunk Search 12-05-2023
0 1
0
1
dbarba
Hello!As the subject of the question says, I'm trying to create SPL queries for several visualizations but it has bec...
by dbarba Explorer in Splunk Search 12-05-2023
0 16
0
16
Raj
Hi,How we can find the difference of these two date difference in year days hour min fromtill11/28/2023 03:38 PM11/28...
by Raj Builder in Splunk Search 12-05-2023
0 7
0
7
aaronzabell
I imported a csv into Splunk and now I need to compare two of the fields to find identical values. Compare the values...
by aaronzabell Path Finder in Splunk Search 12-05-2023
0 10
0
10
Muthu_Vinith
Hey All, I’m a splunk beginner I'm looking to create a query that to be used  as an alert, specifically to identify s...
by Muthu_Vinith Path Finder in Splunk Search 12-05-2023
0 10
0
10
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...