Splunk Search

Splunk Search
Community Activity
Stevelim
I have base search that was able to get me to this form in Splunk: Name Value A ...
by Stevelim Communicator in Splunk Search 09-18-2017
0 3
0
3
known_user
search string1 - [ field1 ] search string2 [ field1 field2] search string3 [ field1 field2] I want the results of se...
by known_user Engager in Splunk Search 09-17-2017
0 2
0
2
bulu
This part of my query gets me on the street I want to be on for this report index="A" | rex mode=sed field=User_Ful...
by bulu New Member in Splunk Search 09-17-2017
0 3
0
3
jcspigler2010
Hello all Is there a way you can query event's _TCP_ROUTING key value in a search? I would assume you should be abl...
by jcspigler2010 Path Finder in Splunk Search 09-16-2017
0 9
0
9
sohaibomar
I have event data in below format: Sep 15 2017 07:06:07 app=yahoo dataconsumed=50 Sep 15 2017 08:16:07 ap...
by sohaibomar Explorer in Splunk Search 09-16-2017
0 4
0
4
hsingams2
Hello, a beginner question. I've a search query that produces a single JSON event such as this: {<!-- --> Error/type/0 : typ...
by hsingams2 Explorer in Splunk Search 09-15-2017
0 4
0
4
Nidheesh
Hi, I need to join two splunk search queries based on a common field (JoinId). All I would like to have at the out...
by Nidheesh Explorer in Splunk Search 09-15-2017
0 3
0
3
mperrenoud
I'm trying to produce a subsearch based off of a rex field. The goal of this search is to find every Deserialization ...
by mperrenoud Engager in Splunk Search 09-15-2017
0 4
0
4
jacqu3sy
Hi, How can I use a combination of an IF statement along with AND. I'm looking to run a count whereby IF the _hour ...
by jacqu3sy Path Finder in Splunk Search 09-15-2017
0 10
0
10
knarayana
how can we give a custom dynamic value for x-axis in the search? i know we can change it manually in the format tab ...
by knarayana New Member in Splunk Search 09-15-2017
0 10
0
10
chintan_shah
Hi All, Currently I have a single instance which acts as indexers as well as search head. But i am planning to inclu...
by chintan_shah Path Finder in Splunk Search 09-15-2017
0 7
0
7
SJanasek
I am trying to output the CUSTOMER_NAME via a csv lookup. my lookup file (lookup_test.csv) looks like that: CUSTOMER...
by SJanasek Path Finder in Splunk Search 09-15-2017
1 13
1
13
johnca00
Hello - I'm trying to extract a field from a CSV. The problem is the 9th position can have several different values....
by johnca00 New Member in Splunk Search 09-15-2017
0 4
0
4
Nick_Hippe
Hi all. I'm creating a dashboard for one of our systems, and am trying to create a chart that will show the previous ...
by Nick_Hippe New Member in Splunk Search 09-15-2017
0 2
0
2
mseguri
I need to obtain | metadata generated results as search events because I need to associate an alert to hosts with a t...
by mseguri New Member in Splunk Search 09-15-2017
0 9
0
9
christopheryu
Have this: search... | stats values(interfaces) AS Interfaces by circuit Thank you in advance!
by christopheryu Communicator in Splunk Search 09-15-2017
0 2
0
2
tlmayes
I have a lookup table that has several columns as follows, with no data in the "Manager" column: I have an index t...
by tlmayes Contributor in Splunk Search 09-15-2017
0 4
0
4
Skins
Ive install syslog-ng on a standalone splunk instance but cannot get it running - ive looked at the following guide :...
by Skins Path Finder in Splunk Search 09-15-2017
0 3
0
3
pfabrizi
I know I can create lookup tables and use them during a search. We would like to apply that same process to fields as...
by pfabrizi Path Finder in Splunk Search 09-15-2017
0 7
0
7
danapsimer
I have used rex to extract a URL from log message. I then want to eliminate the parameter values so I can build stat...
by danapsimer New Member in Splunk Search 09-15-2017
0 2
0
2
gcusello
Hi at all, I have a strange behaviour in ip location: I'm migrating some apps and indexes from an old infrastructure...
by SplunkTrust SplunkTrust in Splunk Search 09-15-2017
0 2
0
2
AlexeyPy
How to index the same field "A" different values for the unique ID? A set of field "A" values is finite and for each ...
by AlexeyPy Engager in Splunk Search 09-15-2017
0 3
0
3
mjones414
Sample Data: 09/12/2017 23:58:35;E;957690.hostname user&#61;NameHere group&#61;GroupHere project&#61;_pbs_project_default jobname...
by mjones414 Contributor in Splunk Search 09-14-2017
0 2
0
2
pavanae
The following is my query | metadata type&#61;hosts | search [| inputlookup hostnames.csv | rename my_hostname as host ...
by pavanae Builder in Splunk Search 09-14-2017
0 5
0
5
pavanae
How to resolve the warning "Metadata results may be incomplete: 100000 entries have been received from all peers , an...
by pavanae Builder in Splunk Search 09-14-2017
1 4
1
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors