Splunk Search

Splunk Search
Community Activity
kteng2024
Hi There, Can i please know the ports to be opened for heavy forwarder , indexer , universal forwarder ?
by kteng2024 Path Finder in Splunk Search 07-31-2017
0 3
0
3
sylbaea
Hello, Does anybody see something wrong with this regex ? \w{3}S*ALTSIP*\d{1,2} When testing against my host lis...
by sylbaea Communicator in Splunk Search 07-31-2017
0 2
0
2
Lgo
I'm attempting to track a mule transaction where the correlation ID changes part way through the request, I would nor...
by Lgo Explorer in Splunk Search 07-31-2017
0 2
0
2
jcorkey
I have these three different searches: A search to display when users create a new user account A search to display ...
by jcorkey Explorer in Splunk Search 07-31-2017
0 2
0
2
bagir32
I want to search for a phone number among multiple indexes and I use append to combined the result together but what ...
by bagir32 Explorer in Splunk Search 07-31-2017
0 7
0
7
katzr
Hello, I am trying to filter on null values for the field called Device. None of the following searches below work- c...
by katzr Path Finder in Splunk Search 07-31-2017
1 3
1
3
nsriram
How to predict a 4th value based on 1,2,3 values in splunk machine learning tool kit i have been asked to give the 4t...
by nsriram New Member in Splunk Search 07-31-2017
0 1
0
1
Sarmbrister
I have been asked by Legal to get login logoff time for colleagues with in certain time frames usually very specific ...
by Sarmbrister Path Finder in Splunk Search 07-31-2017
0 4
0
4
harsush
Hi Team, Need Help on run search checking server live or not using lookup boxdata box_env box_live_state box_locat...
by harsush Path Finder in Splunk Search 07-31-2017
0 9
0
9
nyasharashad59
Hello, I want create a column chart with 2 y-axis variables (AP and FP). I want AP to be the number of bars on the X ...
by nyasharashad59 Explorer in Splunk Search 07-31-2017
0 4
0
4
ddrillic
How do I find whether the time stamp of an event covers a specific second within a day? So, we need to identify all t...
by ddrillic Ultra Champion in Splunk Search 07-31-2017
0 5
0
5
bic
I have a lookup file assignment_schedule containing below sample data assignment_group task_order schedule ...
by bic Explorer in Splunk Search 07-31-2017
0 4
0
4
aelliott
I have two tables The first table has a list of Categories. The Second table has a list of Offices. Such as Categ...
by aelliott Motivator in Splunk Search 07-31-2017
0 2
0
2
grannnt
I would like to compare two field values and return a new field with a percent match between the two. Current search...
by grannnt New Member in Splunk Search 07-31-2017
0 2
0
2
raghu0463
Hi, How to convert this SQL statement to SPL pls select DateDiff(day, ga.Initial_L1_Decision_Date, Close_date) as [...
by raghu0463 Explorer in Splunk Search 07-31-2017
0 4
0
4
pfabrizi
I have the following ldapsearch | ldapsearch domain="PROD" search="(&(objectClass=group)(cn=DSMS Operations))" | ta...
by pfabrizi Path Finder in Splunk Search 07-31-2017
0 6
0
6
Jason
Is it necessary to include an ORDER BY $rising_column$ in my database tail query? This can be very expensive on a lar...
by Jason Motivator in Splunk Search 07-31-2017
2 14
2
14
kiran331
Hi, I see a lot of events in Windows logs with Process splunk-regmon, powershell etc. Is there a way to exclude the ...
by kiran331 Builder in Splunk Search 07-31-2017
0 6
0
6
himynamesdave
Hi all - I have a dataset that tracks server access. Every time a server makes a request an event is generated. A ve...
by himynamesdave Contributor in Splunk Search 07-31-2017
0 4
0
4
bugnet
The following search will give the count of attacks by attacker_IP and destination branch. index=waf Name=block | ...
by bugnet Path Finder in Splunk Search 07-31-2017
0 3
0
3
jonathan_yan5
how can i count "several" tickets as "OPEN" every month including when it was created(create_date, mmddyyyy) to the m...
by jonathan_yan5 Explorer in Splunk Search 07-30-2017
0 5
0
5
HattrickNZ
How do I replace the MB in each field name with GB ?? _time XXX-XX-MB XXX-XXX-MB XXXXXXMB_XX_XXX 1 2017-07-30...
by HattrickNZ Motivator in Splunk Search 07-30-2017
1 1
1
1
samlinsongguo
HI Everyone I have a query will return me a table shows top users that has logon fail detail as below query sourcet...
by samlinsongguo Communicator in Splunk Search 07-30-2017
0 5
0
5
nagarjuna280
| gentimes start=-1 | eval YourDate="3:21:34 AM 12/8/2014" | table YourDate | eval epoch1=strptime(YourDate,"%H:%M:...
by nagarjuna280 Communicator in Splunk Search 07-30-2017
0 1
0
1
danielwan
I have 2 separated all-in-one Splunk boxes running on the different sites for DR purpose. Is there any way to replic...
by danielwan Explorer in Splunk Search 07-30-2017
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...