Splunk Search

Splunk Search
Community Activity
sandyIscream
My customer has asked me to create a dashboard for the error in OS logs and as there are plenty he wants to make sure...
by sandyIscream Communicator in Splunk Search 06-14-2017
2 4
2
4
skelly99
Hi - I have a JSON formated log file which contains two EPOCH millisecond formatted timestamps One timestamp relates...
by skelly99 Explorer in Splunk Search 06-14-2017
0 1
0
1
Kieffer87
I have a single search that allows users to enter an IP address and return the workstation hostname that was associat...
by Kieffer87 Communicator in Splunk Search 06-14-2017
0 5
0
5
jwalzerpitt
I checked the Hunk documentation and it does not list 'tstats' as a command that's not supported, but when I try and ...
by jwalzerpitt Influencer in Splunk Search 06-14-2017
0 2
0
2
selsin
Search works correctly in Splunk Web: index=xxxx | rex field=_raw "InvalidLogin\|NotFound\|(?<client>\w+)" | stats c...
by selsin Engager in Splunk Search 06-14-2017
0 8
0
8
bewald_cfi
Good day, My first search pulls servername and owner from a sourcetype (database). I then need to take the servernam...
by bewald_cfi New Member in Splunk Search 06-14-2017
0 4
0
4
amir_thales
Hello, i'm a newbie in the world of splunk and i would know how i can add this word to make it a field My log is : ...
by amir_thales Path Finder in Splunk Search 06-14-2017
0 4
0
4
chrisschum
I have an index with data from two different sourcetypes. Each sourcetype has several different values which I have c...
by chrisschum Path Finder in Splunk Search 06-13-2017
0 9
0
9
Bassik
Hi All, I'm new to Splunk but have been working with it over a few months now. I'm trying to distinguish unique webs...
by Bassik Path Finder in Splunk Search 06-13-2017
0 1
0
1
exocore123
<fin:Data namespace=\"url1\" type=\"EData\">... Using basic search | rex "Data\snamespace=\"(?P<preName>[^\"]+)\"" ...
by exocore123 Path Finder in Splunk Search 06-13-2017
0 4
0
4
gagandeep_arora
How to search for all the sourcetypes, corresponding indexes, and their latest accessed time in a table format? My p...
by gagandeep_arora Path Finder in Splunk Search 06-13-2017
0 7
0
7
onkarkore1
II have a lookup table named transaction.csv contains one colunm, transaction_name. The goal is to have Splunk go thr...
by onkarkore1 Explorer in Splunk Search 06-13-2017
0 21
0
21
snehalk
Hello All, How can we get machine configuration from a Splunk search? I am trying the search below. Here we are able...
by snehalk Communicator in Splunk Search 06-13-2017
0 5
0
5
cdo_splunk
This search does not return the correct disk space for a server | rest splunk_server= /services/server/status/partit...
by cdo_splunk Splunk Employee Splunk Employee in Splunk Search 06-13-2017
0 1
0
1
premraj_vs
Hi All, I am a newbie and i am trying to extract fields from raw log. I followed the below steps. Using the link -h...
by premraj_vs Path Finder in Splunk Search 06-13-2017
0 9
0
9
wessam
Hello all , I need your help as i have list of tickets called "Tickets" and i would like to generate a graph where t...
by wessam Explorer in Splunk Search 06-13-2017
0 3
0
3
AshimaE
This question is slightly theoretical so kindly bear with me. I am trying to make a timechart for multiple hosts on a...
by AshimaE Explorer in Splunk Search 06-13-2017
0 3
0
3
shikhanshu
We feed JSON data into our Splunk index. It is not a flat JSON, but has a couple of levels of nested-ness. For instan...
by shikhanshu Path Finder in Splunk Search 06-13-2017
0 2
0
2
tejasbharadwaj
Hello, Please help me with the below:- 1) search command that will only display the list of last 15 days events. Ex...
by tejasbharadwaj New Member in Splunk Search 06-13-2017
0 1
0
1
lazysecurity
Hi, I'm still fairly new to Splunk (come from an ArcSight background) so apologies if this is a silly question. Bac...
by lazysecurity New Member in Splunk Search 06-13-2017
0 1
0
1
bagarwal
Hello Everyone, I am new to base search and need some help from you. With the help of base search, I want to pre...
by bagarwal Path Finder in Splunk Search 06-13-2017
0 5
0
5
kinkster
I am cannot quite get the regex working that I am looking for. I want to extract AcroRd32.exe Here is the sample tex...
by kinkster Explorer in Splunk Search 06-13-2017
0 9
0
9
ahallak2016
A single event has two dates. How do I count the number of days excluding weekends and holidays between these two dat...
by ahallak2016 Explorer in Splunk Search 06-13-2017
0 7
0
7
kiran331
How to extract the IP OR hostname from the field "source"? source=/opt/var/log/splunk/ciscoasa/11.12.22.345/2017_06_...
by kiran331 Builder in Splunk Search 06-13-2017
0 3
0
3
khanlarloo
hi i have problem in splunk.our company has firewall and the logs of firewall is sending to splunk,i want to change t...
by khanlarloo Explorer in Splunk Search 06-13-2017
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...
Top Solution Authors