Splunk Search

Splunk Search
Community Activity
ravir_jbp
I am trying to remove T and Z from the output timestamp results. Can you please help me with the query to remove  and...
by ravir_jbp Explorer in Splunk Search 11-01-2023
0 4
0
4
smahoney
Haven't been able to find this, but I want to basically calculate up time percentage for a host based on 2 unique eve...
by smahoney Path Finder in Splunk Search 11-01-2023
0 7
0
7
Roy_9
Hello,I have a lookup where all the hostnames are available under the field called "title" with respect to teams.I wo...
by Roy_9 Motivator in Splunk Search 11-01-2023
0 9
0
9
duesser
Basically I have a search with a lot of fields, similar to this example:  | makeresults | eval aa1=1, aa2=2, aa1x=3, ...
by duesser Path Finder in Splunk Search 11-01-2023
0 3
0
3
jip31
hello   I have a admin role when I create a field alias, I can see it in the props.conf file but when I run the searc...
by jip31 Motivator in Splunk Search 11-01-2023
0 2
0
2
sigma
Hi all,I have a forwarder in my cluster and it sends events to the indexers. The events are json formatted and I want...
by sigma Path Finder in Splunk Search 11-01-2023
0 1
0
1
Komal0113
From splunk user we are receiving logs but when it comes to Splunk search head its splitting into different events Ex...
by Komal0113 Loves-to-Learn in Splunk Search 11-01-2023
0 3
0
3
leenaut
Hello,    I have a table with a column recording the ID, I want to make each ID in the table a Hyperlink and click on...
by leenaut Loves-to-Learn in Splunk Search 10-31-2023
0 0
0
0
VatsalJagani
Hello Splunkers,I’m looking for the best algorithm to search for events. with the below criteria.I have a lookup with...
by SplunkTrust SplunkTrust in Splunk Search 10-31-2023
0 2
0
2
sathiyasun
below is the sample json log content the main filelds are default extracts but the nested aren't. Please help to extr...
by sathiyasun Explorer in Splunk Search 10-31-2023
0 2
0
2
karu0711
my DN field value "cn=jsuwus, jkhzdhkjc,ou=sdsfefv accounts,ou=ffdsrew users,dc=hgsywy,dc=tre,dc=hyt,dc=kuhytr"I need...
by karu0711 Communicator in Splunk Search 10-31-2023
0 2
0
2
DanSec
I have a current search used in dashboards and alerts. It extracts fields from an existing field. I'm trying to edit ...
by DanSec Engager in Splunk Search 10-31-2023
0 2
0
2
riposans
I'm confused how to truncate from this log. how do I do it from props.conf or from the SPL command? Can anyone provid...
by riposans Explorer in Splunk Search 10-31-2023
0 2
0
2
jbanAtSplunk
Hi,How to create automatic tag if:eventtypes.conf[duo_authentication]search = sourcetype=json:duo type=authentication...
by jbanAtSplunk Communicator in Splunk Search 10-31-2023
0 1
0
1
av_
Is there any prebuilt search (like rest command) to find the number of triggered alerts for a particular dashboard? i...
by av_ Path Finder in Splunk Search 10-31-2023
0 1
0
1
Dustem
Hi guys, I want to detect a service ticket (TGS) request (Windows event code 4769) that is not preceded by one of the...
by Dustem Explorer in Splunk Search 10-30-2023
0 11
0
11
GaryZ
I am looking to create an acronym from a dynamic string, by capturing the first letter of each broken substringHow do...
by GaryZ Path Finder in Splunk Search 10-30-2023
0 2
0
2
avi7326
I am having two counts in the dashboard one is the total count and other is error count to get the success count I wa...
by avi7326 Path Finder in Splunk Search 10-30-2023
0 12
0
12
the_dude
I have three indexes I am trying to join that have at least three similar columns each. I want to table the results i...
by the_dude Engager in Splunk Search 10-30-2023
0 2
0
2
lukasmecir
Hello,by default, DMA summaries are not replicated between nodes in indexer cluster (for warm and cold buckets). I wo...
by lukasmecir Path Finder in Splunk Search 10-30-2023
0 0
0
0
raghul725
Hello,Currently my search looks for the list of containers which includes initialised successfully message and lists ...
by raghul725 Explorer in Splunk Search 10-30-2023
0 7
0
7
LearningGuy
Hello,Does stats values command combine unique values?For example:companyipcompanyAcompanyA1.1.1.1companyBcompanyBcom...
by LearningGuy Motivator in Splunk Search 10-30-2023
0 9
0
9
Splunkie1
I have a field called position that contains integers and a token called position_select that is either a floating po...
by Splunkie1 Loves-to-Learn Lots in Splunk Search 10-30-2023
0 3
0
3
aohls
I have a lookup table with a list of dates which I want to use in my alerts. If the alert triggers I want a where cla...
by aohls Contributor in Splunk Search 10-30-2023
0 6
0
6
johnward4
How do you calculate the totals of each single row of a table and display that value in a new fields, much like addco...
by johnward4 Communicator in Splunk Search 10-30-2023
0 3
0
3
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors