Splunk Search

Splunk Search
Community Activity
matthewb4
I have a lookup abc.csv with the following values... **header1, header2** value1a, value2a value1b, value2b value1c,...
by matthewb4 Path Finder in Splunk Search 09-19-2017
0 4
0
4
virgilg
Hi, I have a search like this: sourcetype=syslog AND host="xxx.xxx.xxx.xxx" AND mpkg | stats count by username, ope...
by virgilg Explorer in Splunk Search 09-19-2017
2 2
2
2
ssaenger
Hi All, I have created an index and sourcetype for two logs files. I have set up my props.conf to extract the date/t...
by ssaenger Communicator in Splunk Search 09-19-2017
0 2
0
2
jh007
I am not sure how to approach what I am attempting to do. In short, I have a field that contains some specific strin...
by jh007 New Member in Splunk Search 09-19-2017
0 6
0
6
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the query below to list the current user accou...
by IRHM73 Motivator in Splunk Search 09-19-2017
0 4
0
4
tmurray3
Trying to use the results of one query in the sub query search. I am not getting the results I expected. The first ...
by tmurray3 Path Finder in Splunk Search 09-19-2017
0 2
0
2
marina_rovira
Hello all, I have some csv files that I'm updating to splunk as lookup files, but there are some german/spanish/fren...
by marina_rovira Contributor in Splunk Search 09-19-2017
0 19
0
19
forrest_NUS
I have an all-in-one environment, which indexed VPN logs. I also want to forward the vpn raw logs to the third party...
by forrest_NUS New Member in Splunk Search 09-19-2017
0 5
0
5
arindam23
Hello, I am trying to create a dashboard in Splunk displaying real-time survey results from sources like Qualtrics, ...
by arindam23 New Member in Splunk Search 09-18-2017
0 3
0
3
ddrillic
We have some messages saying - Search peer <host> has the following message: Received event for unconfigured/disabl...
by ddrillic Ultra Champion in Splunk Search 09-18-2017
0 7
0
7
JordanPeterson
I'm looking at a specific email recipient. I want to see the percentage of emails they receive from specific senders....
by JordanPeterson Path Finder in Splunk Search 09-18-2017
0 4
0
4
vanderaj2
Sounds like I have a manifest file/hashing issue that appears whenever I restart splunkd on an endpoint, like the fol...
by vanderaj2 Path Finder in Splunk Search 09-18-2017
0 4
0
4
dlugasny
Hi, our network count ~9000 Servers. Most of them running in the separate network IP segments. I would like to kind...
by dlugasny New Member in Splunk Search 09-18-2017
0 7
0
7
tlmayes
I have a query below that produces the sum of bandwidth used by remote intermediate forwarders. The output give me a...
by tlmayes Contributor in Splunk Search 09-18-2017
0 5
0
5
ecanmaster
I found this search from woodcock user and it basically searches for successful logins after several failed attempts:...
by ecanmaster Explorer in Splunk Search 09-18-2017
0 2
0
2
nanceda
I know this question has probably been asked before but I've tried it a LOT of ways. Splunk 5.0.4 build 172409 on Wi...
by nanceda New Member in Splunk Search 09-18-2017
0 5
0
5
splunk_newb
I have a search that results in showing the time a phone was in a call in seconds by using sum(duration) of the event...
by splunk_newb Explorer in Splunk Search 09-18-2017
0 2
0
2
sohaibomar
I have results in following table format: half app_name dataconsumed ----------------------------------- first...
by sohaibomar Explorer in Splunk Search 09-18-2017
0 4
0
4
ablake1
Hello, I have two types of events: clicks and searches. I want to group two searches into a transaction if they don...
by ablake1 Engager in Splunk Search 09-18-2017
0 4
0
4
pjbuchan596
Hello, I'm attempting to display three calculated fields (total_meeting_hours, total_use_no_meeting_hours, and hours_...
by pjbuchan596 Explorer in Splunk Search 09-18-2017
0 4
0
4
Stevelim
I have base search that was able to get me to this form in Splunk: Name Value A ...
by Stevelim Communicator in Splunk Search 09-18-2017
0 3
0
3
known_user
search string1 - [ field1 ] search string2 [ field1 field2] search string3 [ field1 field2] I want the results of se...
by known_user Engager in Splunk Search 09-17-2017
0 2
0
2
bulu
This part of my query gets me on the street I want to be on for this report index="A" | rex mode=sed field=User_Ful...
by bulu New Member in Splunk Search 09-17-2017
0 3
0
3
jcspigler2010
Hello all Is there a way you can query event's _TCP_ROUTING key value in a search? I would assume you should be abl...
by jcspigler2010 Path Finder in Splunk Search 09-16-2017
0 9
0
9
sohaibomar
I have event data in below format: Sep 15 2017 07:06:07 app=yahoo dataconsumed=50 Sep 15 2017 08:16:07 ap...
by sohaibomar Explorer in Splunk Search 09-16-2017
0 4
0
4
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...