Splunk Search

Splunk Search
Community Activity
hwakonwalk
The data from multiple sensors comes into SPlunk though a single DB connection as: SensorId ParamA ParamB ParamC 1 ...
by hwakonwalk Path Finder in Splunk Search 02-16-2017
0 3
0
3
varad_joshi
I saw some answers already however did not find anything concrete so asking a new question. I have a field where va...
by varad_joshi Communicator in Splunk Search 02-16-2017
0 2
0
2
hwakonwalk
I have a dashboard with an input variable that displays data in an a table with row extension functionality using JS....
by hwakonwalk Path Finder in Splunk Search 02-16-2017
0 2
0
2
att35
Hi, From our IDS logs, we have a field named "blocked" where value is 0 for allowed and 1 for blocked. How can I cre...
by att35 Builder in Splunk Search 02-16-2017
0 6
0
6
deodion
I have Regex with tens of thousand characters (approx 21k), Its for event filtering, with config model like below: P...
by deodion Path Finder in Splunk Search 02-16-2017
0 6
0
6
TiagoTLD1
Hello I have a UF that will send the data to another UF. I want to send the data uncooked to the second UF, and only...
by TiagoTLD1 Communicator in Splunk Search 02-15-2017
0 2
0
2
ringbbg
can [if , then ] only be used inside of a search string (w/eval) ? im asking coz i have a dual drop down setup. The...
by ringbbg Engager in Splunk Search 02-15-2017
0 2
0
2
AkritiParida
I need to predict/forecast the actual cost which will be incurred in the future sprints depending upon the hourly cha...
by AkritiParida Engager in Splunk Search 02-15-2017
0 1
0
1
harsush
host=aa* | search env=CERT (job=AJOB OR job= BJOB OR job= CJOB ) | eval desired_time=strftime(_time, "%d/%m/%Y %I:%M:...
by harsush Path Finder in Splunk Search 02-15-2017
0 6
0
6
pradyprakhar
For example: action actual_action process user hostname Time Event 1: allowed Left alone ...
by pradyprakhar New Member in Splunk Search 02-15-2017
0 2
0
2
mcronkrite
Why do some splunk users say that the | pivot command isn't for ninjas? Which is better then, pivot, datamodel, tstat...
by mcronkrite Splunk Employee Splunk Employee in Splunk Search 02-15-2017
2 4
2
4
rhfiberlight
I have a search that works correctly when specific field values are entered but would like to create a report for the...
by rhfiberlight Engager in Splunk Search 02-15-2017
0 3
0
3
justinfranks
Hello Peoples.. I have this issue with a search, here is the search that I am performing. source="*playbackinit.log...
by justinfranks Path Finder in Splunk Search 02-15-2017
0 11
0
11
spammenot66
In Splunk, is there a way to format data that normally contains user, month-year, hits, clicks to display multiple v...
by spammenot66 Contributor in Splunk Search 02-15-2017
0 2
0
2
rodiers01
Good afternoon all I'm just looking for a search that will search for anyone that has logged in to a web site, from ...
by rodiers01 New Member in Splunk Search 02-15-2017
0 6
0
6
bcusick
Hi, I'm thinking this has a simple solution..Is there anyway to show a table in descending order by count? Currentl...
by bcusick Communicator in Splunk Search 02-15-2017
0 5
0
5
sravankaripe
Help me with Rex "keys":"values" "SSOUSERDATA":"INDV=12345678|ONE|testd44|ABCD,ABCD_ABCDABCD" "X-comGlobalSessionI...
by sravankaripe Communicator in Splunk Search 02-15-2017
0 5
0
5
aselios
Hello everyone!!! This is a search that I was used to setting up a report with acceleration. But in the Report Accel...
by aselios Engager in Splunk Search 02-15-2017
0 2
0
2
rbal_splunk
I am trying to figure out if the Splunk is sending Search Bundles very often and if these are full or delta?
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 02-15-2017
1 1
1
1
dbcase
Hi, I have the below log data. It appears to be all one line. What I'd like to do is: Have a separate event every...
by dbcase Motivator in Splunk Search 02-15-2017
0 4
0
4
dfenko
I have a data set that gives me an entry for each time a company runs a report in my system. I can easily put togethe...
by dfenko Explorer in Splunk Search 02-15-2017
0 2
0
2
kteng2024
Hi, How to calculate the truncate value ? is it calculated based on the log size and max_events ? if yes , can anyo...
by kteng2024 Path Finder in Splunk Search 02-15-2017
0 1
0
1
ajdyer2000
Hi I have a search that returns a field called "Administrators" Administrators \DomainAdmins \Backup Group \Eventl...
by ajdyer2000 Path Finder in Splunk Search 02-15-2017
0 8
0
8
rbal_splunk
My searches are failing with the following errors in splunkd.log. I have one Search Head and 26 indexers. In the Sear...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 02-15-2017
13 5
13
5
sravankaripe
i have two indexes i have Sid common in both i want to display Sid and Did in a table. Please help me with join con...
by sravankaripe Communicator in Splunk Search 02-15-2017
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...