Splunk Search

Splunk Search
Community Activity
gforster
2017-06-06 08:30:56,761 [ajp-127.0.0.4-8009-44] INFO Weblogger - 3B08FDCAF216658E81536A07B9D5772E: cdbarnes: reset ...
by gforster New Member in Splunk Search 06-06-2017
0 2
0
2
bharadwaja30
In our environment we have syslog sources that forward data to HFs via load balancer. I would like to get the report ...
by bharadwaja30 Path Finder in Splunk Search 06-06-2017
0 5
0
5
lacrosse1991
Hello, I'm trying to set up my Splunk instance so that it filters out some lines and then leaves everything else. Th...
by lacrosse1991 Explorer in Splunk Search 06-06-2017
0 8
0
8
mszopa
Hello everyone! I have a field called word_score_cat1 that looks like this: word_score_cat1=7.12500 1.5171 2.1923 1.6...
by mszopa Explorer in Splunk Search 06-06-2017
0 4
0
4
smruti13
I have a table which has fields defects and summary that gives me the summary of the defects. I want to extract som...
by smruti13 Observer in Splunk Search 06-06-2017
0 5
0
5
dsiob
I need to set my custom time as default time, in time picker. So that in bar chart it will only show the data for tha...
by dsiob Communicator in Splunk Search 06-05-2017
0 5
0
5
dragut
My scenario is thus: The main search searches for a pattern in a sourcefile: source="/apps.log" index=idx "abc" | xm...
by dragut New Member in Splunk Search 06-05-2017
0 7
0
7
sillingworth
Using the docs here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Propsconf, specifically this section: *...
by sillingworth Path Finder in Splunk Search 06-05-2017
0 8
0
8
lids4dt
If I have a lookup containing a list of different regular expressions in a column, is there a way I can input the loo...
by lids4dt Engager in Splunk Search 06-05-2017
1 3
1
3
ppanchal
Splunk time and the event time does not match. There is a 5 hour difference. How to get both the timestamps under the...
by ppanchal Path Finder in Splunk Search 06-05-2017
0 6
0
6
igordon
My current search is: index=ad memberOf=role1 OR memberOf=role2 NOT memberOf=role3 | stats count as "User Group A" |...
by igordon New Member in Splunk Search 06-05-2017
0 3
0
3
jcouture
Hello, I'm joining two tables in splunk and their only common attribute is time. This works well 99% of the time. B...
by jcouture Explorer in Splunk Search 06-05-2017
0 6
0
6
simpkins1958
Using this SPL: index=main sourcetype=conn_activeifc d_name="JimSimpkins-Surface3" | transaction mvlist=t maxevents=...
by simpkins1958 Contributor in Splunk Search 06-05-2017
1 4
1
4
robdanl
I'm looking at firewall logs which typically have (among other details) a source address and a destination address. I...
by robdanl Explorer in Splunk Search 06-05-2017
0 12
0
12
snreichel
I've concluded that I absolutely need to use mapping, as I need to run the same (large) search query for each Iterati...
by snreichel Engager in Splunk Search 06-05-2017
0 3
0
3
shrutigupta
So, basically I've a query which ends something like this: | eval uf = if(like(one_reason, "%unknown_failure%"), uf....
by shrutigupta New Member in Splunk Search 06-05-2017
0 2
0
2
gvnd
Hi, I want to extract particular fields from single event based on fields position. Sample Data: event1: aaa|bbb|c...
by gvnd Path Finder in Splunk Search 06-05-2017
0 2
0
2
t_splunk_d
I am trying to write a query to show number of open and closed incidents in a month. When I try the following in the...
by t_splunk_d Path Finder in Splunk Search 06-04-2017
0 34
0
34
amanavohra
I have xml logs as below where I am trying to write a Splunk search to do a search where entry=01 and result = Done...
by amanavohra New Member in Splunk Search 06-04-2017
0 3
0
3
bowesmana
I have a CSV containing wine names, vintages and prices, e.g. Description,Vintage,Price A,2012,100 A,2013, B,2014, B...
by SplunkTrust SplunkTrust in Splunk Search 06-03-2017
0 5
0
5
ankithreddy777
Hi , I have a scenario. where my _time is chicago time(CST/CDT) . But I need to convert it to London time and do stat...
by ankithreddy777 Contributor in Splunk Search 06-03-2017
0 3
0
3
johnmvang
Hello Everyone, I'm having an issue where I cannot use EVAL in search or in the props.conf for a field that has been...
by johnmvang Path Finder in Splunk Search 06-03-2017
0 12
0
12
rvencu
I have a lookup table of IDs like this: (id)uuid - (myid)numeric id (id)uuid - (myid)email (id)email - (myid)numeric ...
by rvencu Path Finder in Splunk Search 06-03-2017
0 1
0
1
sandyIscream
Basically my search looks like this index=something | rex "(?), " | rex "(?\d+)" | eval _time=strftime(_time, "%d ...
by sandyIscream Communicator in Splunk Search 06-03-2017
0 2
0
2
surajgupta
Hi, We have a requirement where client wants to see only events which satisfied the below condition. Any events whi...
by surajgupta New Member in Splunk Search 06-02-2017
0 4
0
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors