Splunk Search

Splunk Search
Community Activity
JoshuaJohn
I want to create a conditional that is based on date, so for example I have a table that will show you the last time ...
by JoshuaJohn Contributor in Splunk Search 04-24-2017
0 1
0
1
jacqu3sy
struggling with the following IF statement.... I have a table, and want to create a new field called 'finalclosedtim...
by jacqu3sy Path Finder in Splunk Search 04-24-2017
0 6
0
6
lasonyadj
I am working on a search that returns counts by the hour but when the event has not occur, I would still like to fill...
by lasonyadj New Member in Splunk Search 04-24-2017
0 11
0
11
HeinzWaescher
Hi, let's say I want to create a 5 step-funnel for customers depending on their max step. My first approach would b...
by HeinzWaescher Motivator in Splunk Search 04-24-2017
0 6
0
6
lakromani
I have data in the form like this: 21:00 Pos=A Strength=45 21:00 Pos=B Strength=60 21:00 Pos=C Strength=32 22:00 Pos...
by lakromani Builder in Splunk Search 04-24-2017
0 5
0
5
ErikaE
I am using a search of real-time data and a lookup to check whether certain problems exist based on the data. For e...
by ErikaE Communicator in Splunk Search 04-24-2017
0 6
0
6
Abarny
Hi guys, I have a problem on my request because when i use a short time like 7 days ou 15 days it is right but when ...
by Abarny Path Finder in Splunk Search 04-24-2017
0 5
0
5
santosh_hb
Hi All, I need help in creating time chart for the following request: I have a field by name field.status that will ...
by santosh_hb Explorer in Splunk Search 04-24-2017
0 9
0
9
ewanbrown
Hi I have a query to look at the number of times a user does an event, and then get different percentiles of these. ...
by ewanbrown Path Finder in Splunk Search 04-24-2017
0 6
0
6
HeinzWaescher
Hi, Is it possible to write a search that shows all saved searches, reports & lookup tables that are shared globally...
by HeinzWaescher Motivator in Splunk Search 04-24-2017
0 3
0
3
sumangala
Hi, Is there any way that we can create lookup table for specific user? As I checked outputlookup command and it doe...
by sumangala Path Finder in Splunk Search 04-24-2017
1 9
1
9
superhm
I want to find the host IPs for three consecutive days of antivirus detection. Please help me. ex) - sourcetype: viru...
by superhm Explorer in Splunk Search 04-24-2017
0 2
0
2
xsstest
I am a splunk novice. Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html URL o...
by xsstest Communicator in Splunk Search 04-23-2017
0 4
0
4
abonuccelli_spl
I am grouping time buckets using 'span' and I'd like to trim partial time buckets at the beginning and end of the sea...
by abonuccelli_spl Splunk Employee Splunk Employee in Splunk Search 04-22-2017
2 3
2
3
macadminrohit
Hi, Below is the search I am running on a set of servers in the lookup file , I don't want to run the search on all ...
by macadminrohit Contributor in Splunk Search 04-22-2017
0 7
0
7
sideview
The fieldformat command ( http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Fieldformat ) offers a ...
by SplunkTrust SplunkTrust in Splunk Search 04-22-2017
1 5
1
5
robertlynch2020
Is it possible to remove all non alpha-numeric when taking in data in the props.conf? I have tried wiht regex but i ...
by robertlynch2020 Influencer in Splunk Search 04-22-2017
0 13
0
13
happysplunkyay
I have hundreds of .tmp files that begin with evb* and exist within the "File Name" field. All I want to do is change...
by happysplunkyay New Member in Splunk Search 04-21-2017
0 8
0
8
yoho
Just wanted to share with the community the plugin and syntax highlighter I've made for VIM. To enable syntax highli...
by yoho Contributor in Splunk Search 04-21-2017
14 10
14
10
sravankaripe
Is there any option other than transaction command to measure the time between events? because i am already using tra...
by sravankaripe Communicator in Splunk Search 04-21-2017
0 1
0
1
ON34C02151009
I was asked to provide active users since December 2016. With the logs we're working with, there's really no way to ...
by ON34C02151009 Explorer in Splunk Search 04-21-2017
0 12
0
12
jhayIV
Is there a way to write an eval to pull back host name Server1 from Server1.12.city.net
by jhayIV Engager in Splunk Search 04-21-2017
0 2
0
2
joesrepsol
Looking to build a report to list all the indexes/sourcetypes in use. And be able to monitor event counts as they go ...
by joesrepsol Path Finder in Splunk Search 04-21-2017
0 8
0
8
nagarjuna280
I have some data, if the message contains a word which is in a csv file, then results should show in a table. How sho...
by nagarjuna280 Communicator in Splunk Search 04-21-2017
0 3
0
3
jian
A search for "ip=100.2.2.2" userid=foobar (identifying information has been changed) produces 5 results. However, whe...
by jian Explorer in Splunk Search 04-21-2017
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors