Splunk Search

Splunk Search
Community Activity
ringbbg
HI All. I have a simple dashboard where the data in the statistic table changes everytime you change the dropdown inp...
by ringbbg Engager in Splunk Search 09-29-2017
0 1
0
1
christoffertoft
I have the following search term .... | | stats count(eval(action="failure")) as fails, count(eval(action="success"...
by christoffertoft Communicator in Splunk Search 09-29-2017
0 7
0
7
fre
Hi and thanks for reading in advance, I have two tables: events for status=50* on a /submissions URL endpoint, let'...
by fre Engager in Splunk Search 09-28-2017
0 4
0
4
puneetkharband1
need to print dates from Thanksgiving onward for the rest of the week until Monday index="test" source="test" date=*...
by puneetkharband1 Path Finder in Splunk Search 09-28-2017
0 4
0
4
mk197m
How to remove duplicate device_id within five min interval for 24 hours search, for example : 10:00am device id =aa...
by mk197m New Member in Splunk Search 09-28-2017
0 1
0
1
sunnyparmar
I have one user (scpet) to whom I assigned rights and roles of some apps. Now the user is facing a problem that he is...
by sunnyparmar Communicator in Splunk Search 09-28-2017
0 4
0
4
kiran331
Hi I have distinguishedName values from Ldap query, how can I convert it to canonical names using Regex? for eg: C...
by kiran331 Builder in Splunk Search 09-28-2017
0 2
0
2
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 4
0
4
letpeter
I would like to capture the value of used_memory_peak_human =>"26.28M" as it increases or decreases from all servers....
by letpeter New Member in Splunk Search 09-28-2017
0 2
0
2
mlange2007
The JSON part to extract is MESSAGES. We created a REGEX which works in the search, but it should be also added perma...
by mlange2007 New Member in Splunk Search 09-28-2017
0 1
0
1
frizzoS3
Guided and Manual Mode? Real Time and Continuous? Is one more efficient then the other? Thank you. Frank
by frizzoS3 New Member in Splunk Search 09-28-2017
0 2
0
2
mateibos
Hello, I am extracting from a database the list of the largest 20 tables. The format would be something like =: For...
by mateibos New Member in Splunk Search 09-28-2017
0 1
0
1
Hemnaath
Hi All Currently we are facing an issue for Some of the universal forwarders have had their hostname updated, but it ...
by Hemnaath Motivator in Splunk Search 09-28-2017
0 17
0
17
katzr
So i am trying to convert some of my searches from joins to appendcol to improve performance but I am running into so...
by katzr Path Finder in Splunk Search 09-28-2017
0 4
0
4
bgagliardi1
I'm working with ServiceNow incident logs and I'm trying to group events weekly, based on their final state in the we...
by bgagliardi1 Path Finder in Splunk Search 09-28-2017
0 5
0
5
packet_hunter
So I noticed that when I run two searches like the following and I am looking for a value, in this case some computer...
by packet_hunter Contributor in Splunk Search 09-28-2017
0 1
0
1
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 2
0
2
francly
Hi I can use the search string to get the statistics output index=data sourcetype="data1" host=HOSTA | stats count ...
by francly Explorer in Splunk Search 09-28-2017
0 8
0
8
khanlarloo
hi i have one problem in making report. in my report result i have repeated name how can I avoid to not show the rep...
by khanlarloo Explorer in Splunk Search 09-27-2017
0 3
0
3
dsmithson8812
I'm lost. I'm trying to capture the _time and UserName (custom field) from a search and use the _time to find events...
by dsmithson8812 Engager in Splunk Search 09-27-2017
0 14
0
14
nabeel652
I have a field in Windows Backup Events named VolumesInfo Sample: <VolumeInfoItem Name="System" OriginalAccessPath="...
by nabeel652 Builder in Splunk Search 09-27-2017
0 3
0
3
alaking
Hello, I am trying to create a correlation search that will detect users accessing devices for which they aren't aut...
by alaking Explorer in Splunk Search 09-27-2017
0 1
0
1
vik78
For a simple query - index=app_au ms.ab=true I have a raw output of - {"dtm":"2017-09-27 10:44:42.389 PDT", "log...
by vik78 New Member in Splunk Search 09-27-2017
0 1
0
1
gabarrygowin
Hi all, Very close with the offerings in other JSON/SPATH posts but just not getting it done. We have a JSON format...
by gabarrygowin Path Finder in Splunk Search 09-27-2017
0 2
0
2
bhupalbobbadi
I have event data as follows: a,b,",1,2,3,",c,d And I have lookup table as follows key, value 1, one 2, ...
by bhupalbobbadi Path Finder in Splunk Search 09-27-2017
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...