Splunk Search

Splunk Search
Community Activity
markuxProof
Greetings, I'm trying to make a regular expression to filter the IIS logs. I want Splunk to index only logs whose sc...
by markuxProof Path Finder in Splunk Search 02-22-2017
0 6
0
6
erwan_raulet
I use SplunkIcons glyphs to display some states with search command "rangemap". I would like to see the icons are ava...
by erwan_raulet Explorer in Splunk Search 02-22-2017
2 7
2
7
smcdonald20
I need to be able to find the difference between two "Count" values; the count for today, and the count yesterday. M...
by smcdonald20 Path Finder in Splunk Search 02-22-2017
0 9
0
9
santorof
I have Active Directory logs that do not have many fields associated with them. Each log is over 100 lines and I wish...
by santorof Communicator in Splunk Search 02-22-2017
0 2
0
2
sravankaripe
"sessionID":"123456567" "sessionID":"ABCnsh8ah" Please help me with Rex to pick 123456567 ABCnsh8ah from above _ra...
by sravankaripe Communicator in Splunk Search 02-22-2017
0 3
0
3
cdcproject
We are using Splunk version 6.3 and facing an issue with a lookup table. While running the search, it returns below e...
by cdcproject New Member in Splunk Search 02-22-2017
0 1
0
1
20065945
hi, I am writing the following search query in the dashboard panel sourcetype=xml22 |where $field1$ = 7|search Tex...
by 20065945 Explorer in Splunk Search 02-22-2017
0 3
0
3
srinivasup
Hi, I want to figure out, how long an employee inside office. Once employee enters into office he will do card swipe...
by srinivasup Explorer in Splunk Search 02-22-2017
0 8
0
8
himynamesdave
I have a saved search that generates a table of users each day: search "my users" | table username, id I want to tu...
by himynamesdave Contributor in Splunk Search 02-22-2017
0 3
0
3
reach2tushar
I used following syntax to monitor a file input in windows [monitor://D:\app*\logs\a*.log] The above stanza is not in...
by reach2tushar Explorer in Splunk Search 02-21-2017
0 6
0
6
rarbabi
I have a simple search with stats count eval (u_id is a numeric field): index=myindex base search | stats count(eval...
by rarbabi New Member in Splunk Search 02-21-2017
0 1
0
1
the_wolverine
I have a need to stats count by a list of variable fields that I don't know the names of. (stats count by * doesn't...
by the_wolverine Champion in Splunk Search 02-21-2017
0 2
0
2
huligesh
Hi, I have Siebel logs like below: event 1: MessageFlow MsgFlowDetail 4 00005609588f0d40:0 2017-01-30 09:38:48 ...
by huligesh Engager in Splunk Search 02-21-2017
0 4
0
4
krishnacasso
Hi Ninja I've done a field extraction for apache access log like Referer. Referer= http(s)://FQDN/Abc/dasd/sadfasf/...
by krishnacasso Path Finder in Splunk Search 02-21-2017
0 2
0
2
ICAP_RND
I have a lookup called FailuresList It contains the following fields: date, site, text, excluded I would like to modi...
by ICAP_RND Engager in Splunk Search 02-21-2017
0 6
0
6
oliverj
I have a regular expression that works on part of my data. Given the log entry: pam_vas: Authentication <succeeded> ...
by oliverj Communicator in Splunk Search 02-21-2017
0 16
0
16
krishnacasso
We have 2 different csv files under the same index and sourcetype. csv1.csv-Fields[uniquenumber Name status] csv2.c...
by krishnacasso Path Finder in Splunk Search 02-21-2017
0 3
0
3
avaishsplunk
In my search query, I have 2 searches 1. This gives stats for today 2. This gives stats for the period entered as...
by avaishsplunk Path Finder in Splunk Search 02-21-2017
0 3
0
3
ephemeric
Greetz, For security purposes we wish to do a search from an untrusted host (could be compromised) and therefore can...
by ephemeric Contributor in Splunk Search 02-21-2017
0 3
0
3
rajgowd1
Hi, i would like to display column chart based on events count and display events size in bytes,KB,MB and GB if even...
by rajgowd1 Communicator in Splunk Search 02-21-2017
0 5
0
5
Mkaz
I have a log that a software package provides which creates a standard record for each event. The standard format ...
by Mkaz New Member in Splunk Search 02-21-2017
0 3
0
3
jacqu3sy
If I run the following search from 'incident_review' I can establish certain fields, but I need to try and calculate ...
by jacqu3sy Path Finder in Splunk Search 02-21-2017
0 9
0
9
repo12
I have two fields, cid Status and delivery_date. How could I get the total unique count of cids which has Status as D...
by repo12 New Member in Splunk Search 02-21-2017
0 4
0
4
hankmath
Hi, I have two tables: table1: share, cost, time A , 10 , 2017-02-20 A , 14 , 2017-02-21 B , ...
by hankmath Observer in Splunk Search 02-21-2017
0 1
0
1
leonjxtan
Hi my use case is to search for only email chains that are replied (attended) by Support team. I have managed to extr...
by leonjxtan Path Finder in Splunk Search 02-21-2017
0 5
0
5
Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors