Splunk Search

Splunk Search
Community Activity
kiran331
Hi I have the DNS debug logs enabled, is there a way to index only failures ignoring the successful one's? I have m...
by kiran331 Builder in Splunk Search 06-15-2017
0 2
0
2
jrnastase
Hello all! I'm trying to find the number of days that the daily count of my event exceeds the daily mean + standard ...
by jrnastase Explorer in Splunk Search 06-15-2017
0 3
0
3
mihall
I am trying to display results that simply report if a certain field contains information or not. My search is as f...
by mihall Path Finder in Splunk Search 06-15-2017
0 1
0
1
rmuraly
Hi, I have a string 'ABC_GFD_NOCS_RPT_HIST_2017-05-12_5min.csv' How do I extract '2017-05-12' from 'ABC_GFD_NOCS_R...
by rmuraly Explorer in Splunk Search 06-15-2017
0 5
0
5
MastaMia
need a search for creation of admin accounts. For both Windows and Linux. Domain-level accounts. Thanks
by MastaMia New Member in Splunk Search 06-15-2017
0 3
0
3
phillipmadm
We are logging information from a network security device that has multiple fields of interest. LOGIN, LOGOUT, START,...
by phillipmadm Explorer in Splunk Search 06-15-2017
0 4
0
4
shinde0509
2017-04-02 so-splunky.local 22:45:19.023 -0600 sshd[68061]: Accepted keyboard-interactive/pam for sowings from xx.xx....
by shinde0509 Explorer in Splunk Search 06-15-2017
0 1
0
1
architkhanna
Do we have any functionality in splunk to make panels populate data once post processing of queries is done.?
by architkhanna Path Finder in Splunk Search 06-15-2017
0 2
0
2
jsven7
index=myindex server="server1234" OR "server1235" OR "server1236" OR "server1237" OR "server1238" | stats count(_raw)...
by jsven7 Communicator in Splunk Search 06-15-2017
0 6
0
6
codebased
Hi Guys, I have been trying to extract the number at the end of EVENT_MESSAGE field. Text sample: SERVER=SERVERNA...
by codebased Explorer in Splunk Search 06-15-2017
0 9
0
9
newbie2tech
Hi All, Need help with regex for extracting desired output from below patterns. I have ecommerce site where we want...
by newbie2tech Communicator in Splunk Search 06-15-2017
0 8
0
8
fli
There is default license alert when license usage is greater 80%, then you will get email notification. The alert is...
by fli Explorer in Splunk Search 06-15-2017
0 3
0
3
scc00
I am trying to map a users activity once they've logged into a vdi session to when they log into a specific applicati...
by scc00 Contributor in Splunk Search 06-15-2017
0 7
0
7
deepak_dhankhar
index=XXXX eventtype=XXXXX | iplocation src_ip | geostats globallimit=0 count by src_ip its not working Field...
by deepak_dhankhar Explorer in Splunk Search 06-15-2017
0 1
0
1
sujith_usha_kum
Hi All, I have a saved search, which executes for every 5 minutes. Sometimes it fails because it was running for mo...
by sujith_usha_kum Explorer in Splunk Search 06-14-2017
0 9
0
9
Svill321
Good day everyone, I have an idea I'd like to try to monitor actions taken by root users or sudo. Say that I have l...
by Svill321 Path Finder in Splunk Search 06-14-2017
0 4
0
4
sweenj
I am attempting to have splunk forward a script of comma separated values. The values are coming into search as one ...
by sweenj Explorer in Splunk Search 06-14-2017
1 7
1
7
essklau
Folks, I don't understand why this is killing me, but it is. In short, I want to, at index time, 1) ignore first li...
by essklau Path Finder in Splunk Search 06-14-2017
1 10
1
10
rkaakaty
Hi, I am trying to count how many certain TYPES there are in the data I am using. For example, there are three type...
by rkaakaty Path Finder in Splunk Search 06-14-2017
0 1
0
1
jefflambert
We are needing to do a search on "Text 1", then we take a dynamic value that's displayed there and do another search ...
by jefflambert New Member in Splunk Search 06-14-2017
0 1
0
1
dgoldin
I am using this search to produce a monthly report ranking top pages in a section of a site. My date range always st...
by dgoldin New Member in Splunk Search 06-14-2017
0 11
0
11
splunkit2010
Hello. What is the best way to trend login failures. Would like to create a baseline of processing normalcy over a tw...
by splunkit2010 Explorer in Splunk Search 06-14-2017
0 2
0
2
splunklakshman
Dear All, I have a column named called id in file1.csv and id1 in file2.csv . File1.csv: File2.csv ID: ...
by splunklakshman Explorer in Splunk Search 06-14-2017
0 5
0
5
sreejith2k2
After running a search, under the Inspect job, I am able to view the searchTotalBucketCount. I need to find, how lon...
by sreejith2k2 Explorer in Splunk Search 06-14-2017
0 3
0
3
halkelley
can I chart data by day of the week, but have it come out chronologically instead of alphabetically?.. i.e. I want Su...
by halkelley Path Finder in Splunk Search 06-14-2017
1 12
1
12
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...