Splunk Search

Splunk Search
Community Activity
nittalasub
how to extract only decimal values in splunk ? ..example (7 divided by 2 ) = 3.5 , I need to get only 0.5 here ...wi...
by nittalasub Explorer in Splunk Search 08-13-2017
0 9
0
9
sangs8788
I have a lookup file with dates. how do i use it to set earliest and latest inorder to search for events, For exampl...
by sangs8788 Communicator in Splunk Search 08-13-2017
0 3
0
3
coenvandijk
Hello I have a string of all uppercase letters (no digits) I need a regex to insert a ":" after every second charact...
by coenvandijk Observer in Splunk Search 08-13-2017
0 8
0
8
auaave
Hi, I have the below statement with the correct statistics output. However my visualization is empty. But when I use...
by auaave Communicator in Splunk Search 08-13-2017
0 2
0
2
prashanthberam
Hi All, I want to compare result column Names which is displaying 3 kind of messages. Normal, Elevated, C...
by prashanthberam Explorer in Splunk Search 08-12-2017
0 6
0
6
jsuryaprakash
index=main (sourcetype=bb OR sourcetype=cc) type=DELETE | transaction info.agentId startswith=COMPLETED endswith=DE...
by jsuryaprakash Path Finder in Splunk Search 08-12-2017
0 1
0
1
kteng2024
Hi, For example, we have 2 universal forwarders UF1 = web01abc23 UF2 = web01cde21 Both are having same inputs.con...
by kteng2024 Path Finder in Splunk Search 08-11-2017
0 1
0
1
medveleyenet
I migrated the database "splunk/var/lib/splunk" but when I copy my configuration files, the fields and alerts disapp...
by medveleyenet New Member in Splunk Search 08-11-2017
0 1
0
1
patilsh
Hello Guys, I have a column _time Ex Values (Suppose the search has 4 events here): 2017-08-11 12:06:51 2017-08-11...
by patilsh Explorer in Splunk Search 08-11-2017
0 2
0
2
rgarbac1
I am looking for help with a case statement that looks for a field full load with a value of "running CDC only in fre...
by rgarbac1 New Member in Splunk Search 08-11-2017
0 1
0
1
kiran331
Hello, How to use Regex in props.conf to extract the fields in the below sample event with source type "syslog". 08...
by kiran331 Builder in Splunk Search 08-11-2017
0 3
0
3
pavanae
For yesterday's results we give the earliest and latest as below earliest=-1d@d latest=@d Simillarly, what could b...
by pavanae Builder in Splunk Search 08-11-2017
0 3
0
3
ibob0304
I have events which are in this format, where the time in the event is the _time. 8/11/2017 1:26:17 PM|Thread Id: 4...
by ibob0304 Communicator in Splunk Search 08-11-2017
0 3
0
3
SplunkLunk
Greetings, I'm trying to find when a user logs (or tries to log) into six different workstations over the course of ...
by SplunkLunk Path Finder in Splunk Search 08-11-2017
0 2
0
2
Sarmbrister
I am currently working on a Splunk query to look at Windows Defender data that has been allowed in the environment. ...
by Sarmbrister Path Finder in Splunk Search 08-11-2017
0 4
0
4
Charlotte94
Hello everyone, I'm just beginning to use Splunk and iIwant to do this : I already tried this : index="****...
by Charlotte94 New Member in Splunk Search 08-11-2017
0 3
0
3
griffinpair
Below is the current search I have put together to extract a couple fields. The extraction of the ClientID from the s...
by griffinpair Path Finder in Splunk Search 08-11-2017
0 5
0
5
pushpender07
Hi, I have a search - index=ABC sourcetype=XYZ | stats values(user), dc(user) as usercount by region | e...
by pushpender07 Explorer in Splunk Search 08-11-2017
1 9
1
9
thambisetty
Hi Splunkers, I have tried stats dc(sourcetype) as count by commonfield | where count > 1. I assume this search is f...
by SplunkTrust SplunkTrust in Splunk Search 08-11-2017
0 9
0
9
vaibhavagg2006
Hi Experts What is the best way to get first and last event by _indextime. I want to group by events based on transac...
by vaibhavagg2006 Communicator in Splunk Search 08-11-2017
0 6
0
6
ankurborah
I have to use a date filed fields.updated to filter records the I have to filter based on matching Year-Month as belo...
by ankurborah Path Finder in Splunk Search 08-11-2017
0 1
0
1
bab4684
Here are the Fields & possible values. pc_id {1234,5678,9012, etc.....}pc_connection {lan, wifi, mo...
by bab4684 New Member in Splunk Search 08-11-2017
0 3
0
3
YTKme
I was wondering if is possible to group / filter based on a single field. Below is a field called user_agent for brow...
by YTKme Engager in Splunk Search 08-11-2017
0 6
0
6
m7787580
These are some below mentioned details which is present in splunk in exactly same format:- New Core 12 Month CTE (201...
by m7787580 Explorer in Splunk Search 08-11-2017
0 5
0
5
karthi2809
|| vasb05 | PROD | Availit | | 2017-08-11 08:54:01,420 | ERROR | http--10.100.108.48-8080-13 | com.amerigroup.utilit...
by karthi2809 Builder in Splunk Search 08-11-2017
0 2
0
2
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors