Splunk Search

Splunk Search
Community Activity
jhochstetler
I have a process that experiences about 8640 events per day, or what I would expect to be an average of 0.1 events pe...
by jhochstetler New Member in Splunk Search 08-07-2017
0 4
0
4
jcorkey
I am trying to set a token to have the following regex value rex "by (?<SU>[^(]+)". This regex is part of a larger se...
by jcorkey Explorer in Splunk Search 08-07-2017
0 6
0
6
NicolayCSPI
Hello everybody, I am in the process of building a use case, which consists of 5 real-time alerts. In order to make ...
by NicolayCSPI Engager in Splunk Search 08-07-2017
0 3
0
3
LauraBre
Hello, I want to know if it's possible to create a chart where there are two periods of time. For example, I want to...
by LauraBre Communicator in Splunk Search 08-07-2017
1 8
1
8
splunkrocks2014
I set up a savedsearch to monitor the status from some critical reports (from a "critical_reports.csv" lookup) within...
by splunkrocks2014 Communicator in Splunk Search 08-07-2017
0 1
0
1
AHEARNJ
I am trying to extract a filed using. | rex field=_raw I used regexr to create a regular expression with an exclude ...
by AHEARNJ Explorer in Splunk Search 08-07-2017
0 1
0
1
vshakur
I have a field called suite_name that consists of several suites, each of which has many events. I would like to com...
by vshakur Path Finder in Splunk Search 08-07-2017
0 4
0
4
FeatureCreeep
This is driving me nuts because I use strptime all the time and have many of my own working examples to reference. I...
by FeatureCreeep Path Finder in Splunk Search 08-07-2017
0 6
0
6
isha_rastogi
I have a table that counts different versions of products and a second table that has the system type, like Laptop, V...
by isha_rastogi Path Finder in Splunk Search 08-07-2017
0 2
0
2
apantoja
We are running some automated reports that give us information on accounts created in the last 24 hours. index=win...
by apantoja New Member in Splunk Search 08-07-2017
0 1
0
1
sangs8788
I have an error event in this format indexed in Splunk. Error for batch element #1: One or more values in the INSERT...
by sangs8788 Communicator in Splunk Search 08-07-2017
0 2
0
2
tlmayes
I've seen many fine examples on how to present stats results even if a zero output, but for some reason I cannot get ...
by tlmayes Contributor in Splunk Search 08-07-2017
0 2
0
2
pfabrizi
I have multiple look up tables built from ldapsearches, these tables hold different user that might have access. I ne...
by pfabrizi Path Finder in Splunk Search 08-07-2017
0 4
0
4
splunkreal
Hello, is it possible to set 'smart mode' search for all users in a search head cluster, if yes, how? Thanks.
by splunkreal Influencer in Splunk Search 08-07-2017
0 1
0
1
jaango123
Hi, I am new to Splunk and I managed to construct the below query to generate statistics with the help of the answer...
by jaango123 Engager in Splunk Search 08-07-2017
0 10
0
10
Rocky31
I am typing all command like splunk start, splunk help, nothing is working, i don't know what to do, every time comma...
by Rocky31 Path Finder in Splunk Search 08-06-2017
0 9
0
9
wifemin
tl;dr how does renaming a field to "search" help? how to make a map visualization with the lookup table/codes shown...
by wifemin Engager in Splunk Search 08-06-2017
0 4
0
4
splunkerkanaka
Is there a specific command that we use to take away a field from the results displayed?
by splunkerkanaka New Member in Splunk Search 08-06-2017
0 2
0
2
chinchin96
When you run a standard search query (say, in verbose mode), it auto-extracts fields and displays them on the left. W...
by chinchin96 New Member in Splunk Search 08-06-2017
0 2
0
2
matansocher
Hi, I have created a chart to show the accumulated number of open and closed ticket: My code: sourcetype=snow:in...
by matansocher Contributor in Splunk Search 08-06-2017
0 1
0
1
colinmchugo
Hi all, I am trying to discover the standard deviation from one set of data to another in a percentage to see if the...
by colinmchugo Explorer in Splunk Search 08-04-2017
0 6
0
6
rwardwell
Hello, We currently have a use case to examine the permissions/access associated with a users Office365 or SharePoint...
by rwardwell Explorer in Splunk Search 08-04-2017
0 1
0
1
kteng2024
When I give admin_all_objects to a role, that role can also edit the permissions of the dashboards, but when I remove...
by kteng2024 Path Finder in Splunk Search 08-04-2017
0 2
0
2
raghu0463
Hi, Here I want to assign Initial_L1_Decision_Date dates to Queue_to_Initial_L1_Days. There are some dates for Initi...
by raghu0463 Explorer in Splunk Search 08-04-2017
0 4
0
4
deadbits
I am looking to create a way to track multiple types of events across different sources. For example, where 'web' is ...
by deadbits Explorer in Splunk Search 08-04-2017
1 4
1
4
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...