Splunk Search

Splunk Search
Community Activity
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 4
0
4
letpeter
I would like to capture the value of used_memory_peak_human =>"26.28M" as it increases or decreases from all servers....
by letpeter New Member in Splunk Search 09-28-2017
0 2
0
2
mlange2007
The JSON part to extract is MESSAGES. We created a REGEX which works in the search, but it should be also added perma...
by mlange2007 New Member in Splunk Search 09-28-2017
0 1
0
1
frizzoS3
Guided and Manual Mode? Real Time and Continuous? Is one more efficient then the other? Thank you. Frank
by frizzoS3 New Member in Splunk Search 09-28-2017
0 2
0
2
mateibos
Hello, I am extracting from a database the list of the largest 20 tables. The format would be something like =: For...
by mateibos New Member in Splunk Search 09-28-2017
0 1
0
1
Hemnaath
Hi All Currently we are facing an issue for Some of the universal forwarders have had their hostname updated, but it ...
by Hemnaath Motivator in Splunk Search 09-28-2017
0 17
0
17
katzr
So i am trying to convert some of my searches from joins to appendcol to improve performance but I am running into so...
by katzr Path Finder in Splunk Search 09-28-2017
0 4
0
4
bgagliardi1
I'm working with ServiceNow incident logs and I'm trying to group events weekly, based on their final state in the we...
by bgagliardi1 Path Finder in Splunk Search 09-28-2017
0 5
0
5
packet_hunter
So I noticed that when I run two searches like the following and I am looking for a value, in this case some computer...
by packet_hunter Contributor in Splunk Search 09-28-2017
0 1
0
1
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 2
0
2
francly
Hi I can use the search string to get the statistics output index=data sourcetype="data1" host=HOSTA | stats count ...
by francly Explorer in Splunk Search 09-28-2017
0 8
0
8
khanlarloo
hi i have one problem in making report. in my report result i have repeated name how can I avoid to not show the rep...
by khanlarloo Explorer in Splunk Search 09-27-2017
0 3
0
3
dsmithson8812
I'm lost. I'm trying to capture the _time and UserName (custom field) from a search and use the _time to find events...
by dsmithson8812 Engager in Splunk Search 09-27-2017
0 14
0
14
nabeel652
I have a field in Windows Backup Events named VolumesInfo Sample: <VolumeInfoItem Name="System" OriginalAccessPath="...
by nabeel652 Builder in Splunk Search 09-27-2017
0 3
0
3
alaking
Hello, I am trying to create a correlation search that will detect users accessing devices for which they aren't aut...
by alaking Explorer in Splunk Search 09-27-2017
0 1
0
1
vik78
For a simple query - index=app_au ms.ab=true I have a raw output of - {"dtm":"2017-09-27 10:44:42.389 PDT", "log...
by vik78 New Member in Splunk Search 09-27-2017
0 1
0
1
gabarrygowin
Hi all, Very close with the offerings in other JSON/SPATH posts but just not getting it done. We have a JSON format...
by gabarrygowin Path Finder in Splunk Search 09-27-2017
0 2
0
2
bhupalbobbadi
I have event data as follows: a,b,",1,2,3,",c,d And I have lookup table as follows key, value 1, one 2, ...
by bhupalbobbadi Path Finder in Splunk Search 09-27-2017
0 2
0
2
molinarf
I have been getting a message that says that a file has been improperly modified or missing. The result of the integr...
by molinarf Communicator in Splunk Search 09-27-2017
0 1
0
1
chetan1974
I have log events such as activity:http://xyz/rest/876 http://xyz/rest/223 http://xyz/rest/263 http://xyz/rest/4534 h...
by chetan1974 Engager in Splunk Search 09-27-2017
0 1
0
1
chambern
So, I tried https://answers.splunk.com/answers/480296/how-to-add-an-additional-column-in-my-results-from.html?utm_sou...
by chambern New Member in Splunk Search 09-27-2017
0 2
0
2
mk197m
example dated newest to oldest : { "ip_address": "255.255.255.255","loss_pct": 0, "device_id": "ABC"} { "ip_address"...
by mk197m New Member in Splunk Search 09-27-2017
0 2
0
2
pm771
The following query did not return any results: ... | stats count(EVAL(error_code=2000)) ... I had to use lower-ca...
by pm771 Communicator in Splunk Search 09-27-2017
1 5
1
5
krrish0930
i have a requirement to merge two tables **table 1** appname | source app1 | src1 app2 | ...
by krrish0930 New Member in Splunk Search 09-27-2017
0 6
0
6
jrosecbt
I am attempting to create a custom trigger condition for the alert below that will only trigger if the dest_ip does n...
by jrosecbt New Member in Splunk Search 09-27-2017
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...