Splunk Search

Splunk Search
Community Activity
dragut
My scenario is thus: The main search searches for a pattern in a sourcefile: source="/apps.log" index=idx "abc" | xm...
by dragut New Member in Splunk Search 06-05-2017
0 7
0
7
sillingworth
Using the docs here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Propsconf, specifically this section: *...
by sillingworth Path Finder in Splunk Search 06-05-2017
0 8
0
8
lids4dt
If I have a lookup containing a list of different regular expressions in a column, is there a way I can input the loo...
by lids4dt Engager in Splunk Search 06-05-2017
1 3
1
3
ppanchal
Splunk time and the event time does not match. There is a 5 hour difference. How to get both the timestamps under the...
by ppanchal Path Finder in Splunk Search 06-05-2017
0 6
0
6
igordon
My current search is: index=ad memberOf=role1 OR memberOf=role2 NOT memberOf=role3 | stats count as "User Group A" |...
by igordon New Member in Splunk Search 06-05-2017
0 3
0
3
jcouture
Hello, I'm joining two tables in splunk and their only common attribute is time. This works well 99% of the time. B...
by jcouture Explorer in Splunk Search 06-05-2017
0 6
0
6
simpkins1958
Using this SPL: index=main sourcetype=conn_activeifc d_name="JimSimpkins-Surface3" | transaction mvlist=t maxevents=...
by simpkins1958 Contributor in Splunk Search 06-05-2017
1 4
1
4
robdanl
I'm looking at firewall logs which typically have (among other details) a source address and a destination address. I...
by robdanl Explorer in Splunk Search 06-05-2017
0 12
0
12
snreichel
I've concluded that I absolutely need to use mapping, as I need to run the same (large) search query for each Iterati...
by snreichel Engager in Splunk Search 06-05-2017
0 3
0
3
shrutigupta
So, basically I've a query which ends something like this: | eval uf = if(like(one_reason, "%unknown_failure%"), uf....
by shrutigupta New Member in Splunk Search 06-05-2017
0 2
0
2
gvnd
Hi, I want to extract particular fields from single event based on fields position. Sample Data: event1: aaa|bbb|c...
by gvnd Path Finder in Splunk Search 06-05-2017
0 2
0
2
t_splunk_d
I am trying to write a query to show number of open and closed incidents in a month. When I try the following in the...
by t_splunk_d Path Finder in Splunk Search 06-04-2017
0 34
0
34
amanavohra
I have xml logs as below where I am trying to write a Splunk search to do a search where entry=01 and result = Done...
by amanavohra New Member in Splunk Search 06-04-2017
0 3
0
3
bowesmana
I have a CSV containing wine names, vintages and prices, e.g. Description,Vintage,Price A,2012,100 A,2013, B,2014, B...
by SplunkTrust SplunkTrust in Splunk Search 06-03-2017
0 5
0
5
ankithreddy777
Hi , I have a scenario. where my _time is chicago time(CST/CDT) . But I need to convert it to London time and do stat...
by ankithreddy777 Contributor in Splunk Search 06-03-2017
0 3
0
3
johnmvang
Hello Everyone, I'm having an issue where I cannot use EVAL in search or in the props.conf for a field that has been...
by johnmvang Path Finder in Splunk Search 06-03-2017
0 12
0
12
rvencu
I have a lookup table of IDs like this: (id)uuid - (myid)numeric id (id)uuid - (myid)email (id)email - (myid)numeric ...
by rvencu Path Finder in Splunk Search 06-03-2017
0 1
0
1
sandyIscream
Basically my search looks like this index=something | rex "(?), " | rex "(?\d+)" | eval _time=strftime(_time, "%d ...
by sandyIscream Communicator in Splunk Search 06-03-2017
0 2
0
2
surajgupta
Hi, We have a requirement where client wants to see only events which satisfied the below condition. Any events whi...
by surajgupta New Member in Splunk Search 06-02-2017
0 4
0
4
testadrianbelen
This docs (https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Runshellscript) says $8 argument i...
by testadrianbelen New Member in Splunk Search 06-02-2017
0 5
0
5
kylbarne
Hello! As the title states, my dashboard fails to load a panel that performs a search. If I click "Open in search...
by kylbarne New Member in Splunk Search 06-02-2017
0 16
0
16
matthijsk
The documentation on user-prefs.conf is incomplete. I cannot find an explanation for the following settings: appOrde...
by matthijsk Explorer in Splunk Search 06-02-2017
0 2
0
2
rdownie
When running this search (the return value is hard coded, it is coming from an external command). I just pasted the r...
by rdownie Communicator in Splunk Search 06-02-2017
0 2
0
2
richgalloway
I'm having problems with what should be a very simple query. I'm trying to get a count of events in an "unavailable"...
by SplunkTrust SplunkTrust in Splunk Search 06-02-2017
0 5
0
5
stefan1988
I'm monitoring Sysmon events from my laptop, but if I temporarily lose network connection Splunk stops logging comple...
by stefan1988 Path Finder in Splunk Search 06-02-2017
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...