Splunk Search

Splunk Search
Community Activity
AKG1_old1
Hi, In my log file one field called Script Name contains some unnecessary details, which I want to remove. My requi...
by AKG1_old1 Builder in Splunk Search 08-15-2017
0 2
0
2
katzr
Hello, I am trying to add fields for month and include the count of tickets in each month. I bolded the part of the ...
by katzr Path Finder in Splunk Search 08-15-2017
0 3
0
3
JustRoot
I am looking to write an alert that would query a report I have saved that runs every day. I would like it to look fo...
by JustRoot Path Finder in Splunk Search 08-15-2017
0 2
0
2
mumblingsages
I've given all my data 1 of 3 possible event types. In addition, each event has a field "foo" (which contains roughly...
by mumblingsages Path Finder in Splunk Search 08-15-2017
0 5
0
5
kaushik1218
Below is the example of single request with multiple lines where ServiceType is different. Required result to be a...
by kaushik1218 New Member in Splunk Search 08-15-2017
0 2
0
2
JustRoot
Hello, So currently, one of my indices logs has the file path which contains the file name but doesn't have a separa...
by JustRoot Path Finder in Splunk Search 08-15-2017
0 4
0
4
DrRich
Hi, I've written a query (see original query below) which joins 3 different event types to display A_events started...
by DrRich Explorer in Splunk Search 08-15-2017
0 6
0
6
drizzo
We're combining many types of searches into one tabled alert. We create our own variables with an eval statement and ...
by drizzo Path Finder in Splunk Search 08-15-2017
0 4
0
4
michaelrosello
Is there a way to customize the column charts label, or the y-axis? What I want to do is create a column with the co...
by michaelrosello Path Finder in Splunk Search 08-14-2017
0 4
0
4
jwalzerpitt
I have the following search in which I'm trying to sort first alphabetically and then by total, but the Processes fie...
by jwalzerpitt Influencer in Splunk Search 08-14-2017
0 7
0
7
viggor
I have a simple question: I have two variables foo and bar, each containing a set of strings, and I would like to c...
by viggor Path Finder in Splunk Search 08-14-2017
0 3
0
3
DEAD_BEEF
I have a query that shows observed category of domains (search engines, social media, streaming, etc.). I'd like to ...
by DEAD_BEEF Builder in Splunk Search 08-14-2017
0 4
0
4
gb0143
I have a log as follows 14AUG2017_12:54:44.903 3418:13 INFO filename.cpp:200 ID:abc123 contextInfo: [ peer_service...
by gb0143 New Member in Splunk Search 08-14-2017
0 1
0
1
splunk_anoosheh
When I use this command ( table ) it runs at a slow speed .... please help me. Thank you for your answer.
by splunk_anoosheh New Member in Splunk Search 08-14-2017
0 2
0
2
rens78
My search so far: index=notimportant EventID=4624 [ inputlookup users.csv | fields TargetUserName ] | chart eval(la...
by rens78 New Member in Splunk Search 08-14-2017
0 2
0
2
ejeny
Hello everyone, So what I'm trying to do with this is print out a value into a Single Value Panel (42). Depending on...
by ejeny Explorer in Splunk Search 08-14-2017
0 9
0
9
nittalasub
how to extract only decimal values in splunk ? ..example (7 divided by 2 ) = 3.5 , I need to get only 0.5 here ...wi...
by nittalasub Explorer in Splunk Search 08-13-2017
0 9
0
9
sangs8788
I have a lookup file with dates. how do i use it to set earliest and latest inorder to search for events, For exampl...
by sangs8788 Communicator in Splunk Search 08-13-2017
0 3
0
3
coenvandijk
Hello I have a string of all uppercase letters (no digits) I need a regex to insert a ":" after every second charact...
by coenvandijk Observer in Splunk Search 08-13-2017
0 8
0
8
auaave
Hi, I have the below statement with the correct statistics output. However my visualization is empty. But when I use...
by auaave Communicator in Splunk Search 08-13-2017
0 2
0
2
prashanthberam
Hi All, I want to compare result column Names which is displaying 3 kind of messages. Normal, Elevated, C...
by prashanthberam Explorer in Splunk Search 08-12-2017
0 6
0
6
jsuryaprakash
index=main (sourcetype=bb OR sourcetype=cc) type=DELETE | transaction info.agentId startswith=COMPLETED endswith=DE...
by jsuryaprakash Path Finder in Splunk Search 08-12-2017
0 1
0
1
kteng2024
Hi, For example, we have 2 universal forwarders UF1 = web01abc23 UF2 = web01cde21 Both are having same inputs.con...
by kteng2024 Path Finder in Splunk Search 08-11-2017
0 1
0
1
medveleyenet
I migrated the database "splunk/var/lib/splunk" but when I copy my configuration files, the fields and alerts disapp...
by medveleyenet New Member in Splunk Search 08-11-2017
0 1
0
1
patilsh
Hello Guys, I have a column _time Ex Values (Suppose the search has 4 events here): 2017-08-11 12:06:51 2017-08-11...
by patilsh Explorer in Splunk Search 08-11-2017
0 2
0
2
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...