Splunk Search

Splunk Search
Community Activity
prashanthberam
i have values with seconds so i need to convert those into days, hours, minutes, seconds, and milliseconds. i am usin...
by prashanthberam Explorer in Splunk Search 03-21-2017
0 4
0
4
SamChang
Dear Sir When I run a long search. The Splunk always reponsd this message. [subsearch]: Search auto-finalized after...
by SamChang Path Finder in Splunk Search 03-21-2017
2 12
2
12
showard22
I want to use Splunk to match on a field name for accounts with exactly 4 characters, all numbers and letters. I kee...
by showard22 New Member in Splunk Search 03-21-2017
0 4
0
4
shreyans
Hi, I have parent child relation data in splunk (based on dbid field) Example 1.Parent Event <parent> <dbid>10</dbid...
by shreyans Path Finder in Splunk Search 03-21-2017
0 4
0
4
dhsetty
event_start=1 event_stop=500 search_parms = {'date_from': '1/10/2016:05:00', 'start': event_start, 'stop': event_sto...
by dhsetty Explorer in Splunk Search 03-21-2017
0 2
0
2
pakerwe
Hi, i've this table R VIP state R1 1.1.1.1 Master R2 1.1.1.1 Backup I want t...
by pakerwe New Member in Splunk Search 03-21-2017
0 10
0
10
tkwaller
Hello I am trying to extract the username from windows security event logs. It seems that there are 2 account name f...
by tkwaller Builder in Splunk Search 03-21-2017
0 17
0
17
sassens1
Hi I'm struggling to find out how to add an overlay or something that will display the daily license usage for speci...
by sassens1 Path Finder in Splunk Search 03-21-2017
1 2
1
2
raghu0463
How can i use Common Table Expressions? i need to store my result in temporary table and use that result later on in...
by raghu0463 Explorer in Splunk Search 03-20-2017
0 3
0
3
yarafatin2
I need to get the count of requests per IP per 30 minutes. The stats column headers should be clientip and all the 3...
by yarafatin2 New Member in Splunk Search 03-20-2017
0 1
0
1
saqibhome
I have a search as follows: (Referrer!="*bing*" AND Referrer!="*google*") Note: Referrer is the http_referrer fiel...
by saqibhome Explorer in Splunk Search 03-20-2017
0 3
0
3
Blu3fish
I'm trying to create a search that'll visualize when a network scan is being run against a particular target. To do t...
by Blu3fish Path Finder in Splunk Search 03-20-2017
0 1
0
1
FeatureCreeep
I have transaction records that are pretty clear. OperationType=singon Client=abc IsSuccess=1 OperationType=changePa...
by FeatureCreeep Path Finder in Splunk Search 03-20-2017
1 6
1
6
sylim_splunk
Our search heads syntax highlighting does not function for any of search commands. This is with search_syntax_highlig...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 03-20-2017
0 1
0
1
Lucas_Henry_
Is there a way to search for a list of strings, and for each match, put that string as the value of the same field? ...
by Lucas_Henry_ New Member in Splunk Search 03-20-2017
0 24
0
24
moesaidi
I have a set of Apache access_logs where a URL is something similar to: http://mydomain.com/user.php?userid=123 I'm ...
by moesaidi Path Finder in Splunk Search 03-20-2017
0 4
0
4
jatin_patel
If you have input type text and searchWhenChanged="true" then i would think that once a user types and hits enter, th...
by jatin_patel Path Finder in Splunk Search 03-20-2017
0 4
0
4
matansocher
I need to create a chart, looking like the example I added. the chart needs to show the cumulative number of tasks op...
by matansocher Contributor in Splunk Search 03-20-2017
0 10
0
10
mistydennis
A few years ago, I was given a search string to filter web crawlers/bots from showing up in our download reports. I'm...
by mistydennis Communicator in Splunk Search 03-20-2017
0 7
0
7
jcspigler2010
Is there a way to do a real time search with a static start time? For example... Select start time of march 19 @ 9:...
by jcspigler2010 Path Finder in Splunk Search 03-20-2017
0 3
0
3
Bags
Hello. I have two queries that will run and write to two files. Then my third query will read from the two files. Is...
by Bags Explorer in Splunk Search 03-20-2017
0 2
0
2
sreejith2k2
HI I am using following regular expression for the index time extraction in the props.conf. For some reason, it is no...
by sreejith2k2 Explorer in Splunk Search 03-20-2017
0 4
0
4
peterh26
I am looking at 10,000 devices and want to look at the last ten files each one has produced. Some will create 100 fil...
by peterh26 New Member in Splunk Search 03-19-2017
0 4
0
4
deodion
Is there any regex limit on Splunk? Where can I configure its limit? I have very specific regex formula and it conta...
by deodion Path Finder in Splunk Search 03-19-2017
0 3
0
3
kiran331
Hi, I have a field EMP, I need to remove the 0000 present before the field, is this do able? like, I'm using Rex and...
by kiran331 Builder in Splunk Search 03-19-2017
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors