Splunk Search

Splunk Search
Community Activity
aracer
Here's what I have below. I'm trying to do unit conversion and the unit trails in the string (ex. 127 KiB). Any ideas...
by aracer Engager in Splunk Search 07-27-2017
0 9
0
9
pushpender07
I need to create a panel in dashboard which gives me list of activities till 23rd July 2017. Now, I don't want the st...
by pushpender07 Explorer in Splunk Search 07-27-2017
0 8
0
8
ajdyer2000
Event_Reported_Time Comment_Date Diff 7/21/2016 7/22/2016 1 7/24/2016 ...
by ajdyer2000 Path Finder in Splunk Search 07-27-2017
0 2
0
2
jcorkey
I have the follow search query: sourcetype=linux_secure source="/var/log/*" "su: (" | eval Date=strftime(_time, "%Y...
by jcorkey Explorer in Splunk Search 07-27-2017
0 7
0
7
kteng2024
For example , i have a sourcetype=abc and data in splunk started missing for this sourcetype from past week . Can i p...
by kteng2024 Path Finder in Splunk Search 07-27-2017
0 1
0
1
ronekarleone
I have search results like this: Host---------------Description------------ EventSize 127.0.0.1----------Prod DB----...
by ronekarleone Explorer in Splunk Search 07-27-2017
0 10
0
10
mjmayer
I have two firewall devices that log their activities in different formats. I'm trying to create CIM compliant logs. ...
by mjmayer Explorer in Splunk Search 07-27-2017
0 3
0
3
goyals05
I have two different searches and i want to run those searches based on the token. if any value is set for that toke...
by goyals05 Explorer in Splunk Search 07-27-2017
2 3
2
3
kiran331
HI How to extract the field with space using regex? name: T11345DDF ERROR T11345SSDF Volume C values: 123455-253355...
by kiran331 Builder in Splunk Search 07-27-2017
0 3
0
3
tlmayes
We have an environment that indexes approximately 600GB / day. I have been tasked with creating queries that correl...
by tlmayes Contributor in Splunk Search 07-27-2017
0 3
0
3
obiloki
While researching exchanging licenses between servers I came across "Historical Data." What is historical Data?
by obiloki New Member in Splunk Search 07-27-2017
0 1
0
1
simpkins1958
Trying to figure out if can rename field names using lookup and CSV file. Something like this: index=main d_name="*"...
by simpkins1958 Contributor in Splunk Search 07-27-2017
0 6
0
6
abhayneilam
Hi, I have a file coming from the source ( UF ) in which I am getting two fields ( IP and PORT ) , Now I have a loo...
by abhayneilam Contributor in Splunk Search 07-27-2017
0 3
0
3
wkassel
Hi - I need to extract two multivalue fields from each event. Let's say the strings are "AAA-" and "BBB-". Each strin...
by wkassel New Member in Splunk Search 07-27-2017
0 3
0
3
robertlynch2020
I am using a join, but is there a better way to replace values? I have the following table. (NICKNAME + Human_Name_N...
by robertlynch2020 Influencer in Splunk Search 07-27-2017
0 4
0
4
tareddy
My search operation consists of two parts Part 1: This job runs every 6 hours and keeps appending to the results obt...
by tareddy Explorer in Splunk Search 07-27-2017
0 4
0
4
Taner
I would like to create a new panel in my Dashboard and I am using the following search string: index=$index$ eventId...
by Taner Engager in Splunk Search 07-27-2017
0 5
0
5
riyaz551
Hi I need to segregate the logs which we imported splunk. Ex:- I want to extract the logs by using the word error a...
by riyaz551 New Member in Splunk Search 07-26-2017
0 4
0
4
hcannon
Splunk is automatically (and correctly) extracting a user field/value in a particular set of logs, I'm looking for a ...
by hcannon Path Finder in Splunk Search 07-26-2017
0 4
0
4
ahallak2016
I am trying to do a timechart on the number of rows on a particular location as shown below. Pivot Query | search l...
by ahallak2016 Explorer in Splunk Search 07-26-2017
0 4
0
4
wvalente
Hi, I'm trying to run a search that alerts me when 40 accounts is created within 1 minute. I'm talking about linux u...
by wvalente Explorer in Splunk Search 07-26-2017
0 2
0
2
kulo
I now have two index needs related inquiries, which indexB the B field is a subset of A field of indexA, how do I cha...
by kulo Engager in Splunk Search 07-26-2017
0 13
0
13
raghu0463
Hi, i was using data from 2 different sources, and joining with join key word, my question is when i want to display...
by raghu0463 Explorer in Splunk Search 07-26-2017
0 2
0
2
sohaibomar
I have JSON formatted data in event as below: { "stats": [ {"name":"Facebook", "count":50}, {"name":"yahoo", "count"...
by sohaibomar Explorer in Splunk Search 07-26-2017
0 1
0
1
AKG1_old1
Hi, I am injesting some data to splunk and in my data there is no unique field to sperate different rows. So I am th...
by AKG1_old1 Builder in Splunk Search 07-26-2017
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...