Splunk Search

Splunk Search
Community Activity
ayousseff
Hi, i have the below json object that is being returned when applying my search: index="devops" sourcetype="_json"...
by ayousseff New Member in Splunk Search 06-07-2017
0 2
0
2
dave4988
I have a simple-xml Splunk dashboard with a base query, and two post-processing queries inheriting from the base. How...
by dave4988 Engager in Splunk Search 06-07-2017
0 2
0
2
snipedown21
I have a table which consists of user names, events triggered by the user and the timestamps when the events were tri...
by snipedown21 Path Finder in Splunk Search 06-06-2017
0 3
0
3
yutaka1005
"$ SPLUNK_HOME / var / run" in my Splunk environment gradually increased from 15:00 PM on 2017/6/5 to 2017/6/6 09: 00...
by yutaka1005 Builder in Splunk Search 06-06-2017
0 4
0
4
ppanchal
Below is my log Database-Error(3100)\nCONF-01083 - Count of positive/negative confirmations do not match the service...
by ppanchal Path Finder in Splunk Search 06-06-2017
0 3
0
3
dsiob
I have three colums Track, Flow and Job. I want to plot 'Track+Flow' vs 'Job' as 'Track+Flow' giving uniqueness. Eg:...
by dsiob Communicator in Splunk Search 06-06-2017
0 15
0
15
ykobak
I am trying to display a table of users usage for each individual computer that they have used. I can get the result ...
by ykobak New Member in Splunk Search 06-06-2017
0 6
0
6
james_gall
If you have a sample search such as the below sourcetype=HOSTS | stats values(user) as USERS_OF_COMPUTER dc(user) as...
by james_gall New Member in Splunk Search 06-06-2017
0 1
0
1
ewise1
Hi, I am trying to use rex function to extract "/" from my data which lookslike: Database User [1] : "/" how sho...
by ewise1 New Member in Splunk Search 06-06-2017
0 1
0
1
ferdbiffle
I have been modifying searches to accommodate Windows data in the CIS Top 20 Critical Controls app. The following sea...
by ferdbiffle Explorer in Splunk Search 06-06-2017
0 4
0
4
eyaluodba
I have a dashboard that lists/groups recently updated dashboards and I just wanted to know if there was a way to also...
by eyaluodba Path Finder in Splunk Search 06-06-2017
0 6
0
6
gforster
2017-06-06 08:30:56,761 [ajp-127.0.0.4-8009-44] INFO Weblogger - 3B08FDCAF216658E81536A07B9D5772E: cdbarnes: reset ...
by gforster New Member in Splunk Search 06-06-2017
0 2
0
2
bharadwaja30
In our environment we have syslog sources that forward data to HFs via load balancer. I would like to get the report ...
by bharadwaja30 Path Finder in Splunk Search 06-06-2017
0 5
0
5
lacrosse1991
Hello, I'm trying to set up my Splunk instance so that it filters out some lines and then leaves everything else. Th...
by lacrosse1991 Explorer in Splunk Search 06-06-2017
0 8
0
8
mszopa
Hello everyone! I have a field called word_score_cat1 that looks like this: word_score_cat1=7.12500 1.5171 2.1923 1.6...
by mszopa Explorer in Splunk Search 06-06-2017
0 4
0
4
smruti13
I have a table which has fields defects and summary that gives me the summary of the defects. I want to extract som...
by smruti13 Observer in Splunk Search 06-06-2017
0 5
0
5
dsiob
I need to set my custom time as default time, in time picker. So that in bar chart it will only show the data for tha...
by dsiob Communicator in Splunk Search 06-05-2017
0 5
0
5
dragut
My scenario is thus: The main search searches for a pattern in a sourcefile: source="/apps.log" index=idx "abc" | xm...
by dragut New Member in Splunk Search 06-05-2017
0 7
0
7
sillingworth
Using the docs here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Propsconf, specifically this section: *...
by sillingworth Path Finder in Splunk Search 06-05-2017
0 8
0
8
lids4dt
If I have a lookup containing a list of different regular expressions in a column, is there a way I can input the loo...
by lids4dt Engager in Splunk Search 06-05-2017
1 3
1
3
ppanchal
Splunk time and the event time does not match. There is a 5 hour difference. How to get both the timestamps under the...
by ppanchal Path Finder in Splunk Search 06-05-2017
0 6
0
6
igordon
My current search is: index=ad memberOf=role1 OR memberOf=role2 NOT memberOf=role3 | stats count as "User Group A" |...
by igordon New Member in Splunk Search 06-05-2017
0 3
0
3
jcouture
Hello, I'm joining two tables in splunk and their only common attribute is time. This works well 99% of the time. B...
by jcouture Explorer in Splunk Search 06-05-2017
0 6
0
6
simpkins1958
Using this SPL: index=main sourcetype=conn_activeifc d_name="JimSimpkins-Surface3" | transaction mvlist=t maxevents=...
by simpkins1958 Contributor in Splunk Search 06-05-2017
1 4
1
4
robdanl
I'm looking at firewall logs which typically have (among other details) a source address and a destination address. I...
by robdanl Explorer in Splunk Search 06-05-2017
0 12
0
12
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...