Splunk Search

Splunk Search
Community Activity
ssyed2009
Base users are unable to get results of the search. As an Admin, I am able to view the data. Search is below. I can q...
by ssyed2009 New Member in Splunk Search 08-02-2017
0 5
0
5
saadmalik83
Hello All, I am having an issue after upgrading our ES app from 4.0.0 to 4.5.2. Currently i am not getting the event...
by saadmalik83 New Member in Splunk Search 08-02-2017
0 1
0
1
raghu0463
Do i need to create separate db input for each table we are loading data from sql server into splunk
by raghu0463 Explorer in Splunk Search 08-02-2017
0 3
0
3
patelaa
I have a lookup table with user data called id_lookup.csv username,hostname,ip user1,computer1,1.1.1.1 user2,compute...
by patelaa Explorer in Splunk Search 08-02-2017
0 3
0
3
kmaron
I keep going around in circles with this and I'm getting nowhere so I'm asking for help. My events look like this: ...
by kmaron Motivator in Splunk Search 08-02-2017
0 4
0
4
DEAD_BEEF
I apologize as I feel I am missing something very basic, but for the life of me I cannot get this query to work. I h...
by DEAD_BEEF Builder in Splunk Search 08-02-2017
0 3
0
3
puneethgowda
sourcetype=XyzProd blacklist = MethodExecutionInfo(\d{8})-(\d{2}).txt|DebugInfo(\d{8})-(\d{2}).txt|CacheRefreshInfo(...
by puneethgowda Communicator in Splunk Search 08-02-2017
0 1
0
1
jofermin
After I transpose my timechart, I'm getting 3 fields under my Column that I want to get rid of: _span, _spandays, and...
by jofermin Explorer in Splunk Search 08-02-2017
0 3
0
3
wvalente
Hi Guys, I need to create an alert that returns the creation time of an account and the first login. How can I run ...
by wvalente Explorer in Splunk Search 08-02-2017
0 2
0
2
vshakur
I have a query that ends with: | chart count by suite_name, status suite_name consists of many events with a sta...
by vshakur Path Finder in Splunk Search 08-02-2017
0 2
0
2
ananthan123
Hello, All of the sudden we have some uncertain usage and trying to under the usage, here are the same lines .... ...
by ananthan123 Explorer in Splunk Search 08-02-2017
0 1
0
1
smuderasi
host=dummy | eval Pattern='arb_usg_mps%06' | where like (source,'%Pattern%') doesnot work . can you help what's wro...
by smuderasi Explorer in Splunk Search 08-02-2017
0 2
0
2
jcorkey
I am receiving the audit.log data from a universal forwarder running on a Linux box Hello below is my search string ...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
jcorkey
trying to search for when sudo user1 adds user2 to a group and I want to extract the name of the user2 that was added...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
lim2
Want to label sc_status <= 304 as Ok and sc_status >= 400 as Error and get the Ok and Error counts and table the clie...
by lim2 Communicator in Splunk Search 08-02-2017
0 1
0
1
ringbbg
I have a simple search query to look for vpn alerts index=nm host = inyod1-jvpn1a-dmz8-lo0 syslog_message="*karachi*...
by ringbbg Engager in Splunk Search 08-02-2017
0 3
0
3
jerin1982
I am very new to regex and I need to extract anything that comes between "device_" and "_1_vol" as volume name. "de...
by jerin1982 New Member in Splunk Search 08-02-2017
0 4
0
4
sarahw3
I want to create a timechart based on 5 tags. I have tried | timechart count by tag |regex tag="Working|No_Images|Oth...
by sarahw3 Explorer in Splunk Search 08-02-2017
0 3
0
3
t_splunk_d
I trying figure out what is the best search query for reporting on the count of different unique status. Following i...
by t_splunk_d Path Finder in Splunk Search 08-02-2017
0 3
0
3
Aufex
Hi there, i try to buildup a firewall report: "sourcetype="firewall" action=blocked | table host src dest src_port ...
by Aufex Explorer in Splunk Search 08-01-2017
0 3
0
3
nkannan1984
I am using the following splunk query to combine the events in to one transaction based on the referenceid. It work...
by nkannan1984 Engager in Splunk Search 08-01-2017
0 3
0
3
tamakg
Hi, I'm trying to replace the host value using a field in the data. I tried to find any previous similar solution bu...
by tamakg Path Finder in Splunk Search 08-01-2017
0 4
0
4
rijinc
THis is my query i want to display a time chart where it should display the last 4week ( week by week) in a time char...
by rijinc Explorer in Splunk Search 08-01-2017
0 12
0
12
jcorkey
Below is my search string: index=* host=* sourcetype="*" "usermod" "add" "to shadow group" | rex "^(?:[^'\n]*'){3}(?...
by jcorkey Explorer in Splunk Search 08-01-2017
0 2
0
2
ankithreddy777
What is the difference between with or without using OUTPUT parameter in lookup command.
by ankithreddy777 Contributor in Splunk Search 08-01-2017
0 2
0
2
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...