Splunk Search

Splunk Search
Community Activity
MonkeyK
I have a lookup table with IP address indicators that I would like to be alerted on whether the IP address is the sou...
by MonkeyK Builder in Splunk Search 02-02-2017
1 8
1
8
maximusdm
hello, I need to extract the strings between both pipes " | | ", for instance, here are a few sample strings: (someti...
by maximusdm Communicator in Splunk Search 02-02-2017
0 10
0
10
ankithreddy777
Hi, below is the stanza in transforms.conf. [rfc5424_header] REGEX = <(\d+)>\d{1}\s{1}\S+\s{1}\S+\s{1}(\S+)\s{1}...
by ankithreddy777 Contributor in Splunk Search 02-02-2017
0 1
0
1
Jarohnimo
So I have mass copied the search app from Server A to Server B (Along with the users directory) to basically copy ove...
by Jarohnimo Builder in Splunk Search 02-02-2017
0 2
0
2
stephenmoorhous
hi i am trying to do something like index=uk search [subsearch] | fields a b | join a [index=uk search | table a b c...
by stephenmoorhous Path Finder in Splunk Search 02-02-2017
0 8
0
8
mvanberg
I've setup a field extractions with K=V; format and every field is working correctly except for the first field, "tim...
by mvanberg Explorer in Splunk Search 02-02-2017
0 7
0
7
thambisetty_bal
Hi Splunkers, I have been struggling to extract user name from below values of user. user -------- user1@sa.com sab...
by thambisetty_bal Path Finder in Splunk Search 02-02-2017
0 3
0
3
ErikaE
tl;dr : Need to manipulate rows / cols of a table in a specific way to avoid using subsearch, can't figure out how. S...
by ErikaE Communicator in Splunk Search 02-02-2017
0 2
0
2
pgreer_splunk
I have a field that has a pattern where there is a first portion of the string that I'd like to capture into one fiel...
by pgreer_splunk Splunk Employee Splunk Employee in Splunk Search 02-02-2017
0 2
0
2
jpringle03
In a past post someone helped me create the following search source=duo extracted_eventtype=authentication result="...
by jpringle03 Path Finder in Splunk Search 02-02-2017
1 8
1
8
landen99
I want to rename any number of fields/columns based on simple patterns. From: randomfields, a1.name1.stuff, a2.name2...
by landen99 Motivator in Splunk Search 02-02-2017
0 3
0
3
JDukeSplunk
I would like to enable to search assistant on my Search Head Cluster. The documentation recommends an edit to the fil...
by JDukeSplunk Builder in Splunk Search 02-02-2017
0 2
0
2
Dassari
HI I have two time stamps like "2017-01-30T19:22:39Z" "2017-01-29T19:17:33Z" From the above two timestamps I wan t...
by Dassari New Member in Splunk Search 02-02-2017
0 3
0
3
ASISH_9
I need a cron expression that would run a report on first two mondays of every month.What would be the expression?Tha...
by ASISH_9 Engager in Splunk Search 02-02-2017
0 7
0
7
mhornste
Hi, I'm running Splunk 6.4.0 with two customers. When using the fields - values search command, the dashboard is no...
by mhornste Path Finder in Splunk Search 02-01-2017
0 3
0
3
rleena
Hi, I have an EVAL statements in two add-ons. The field names are same and the add-on that comes later in alphabetic...
by rleena New Member in Splunk Search 02-01-2017
0 11
0
11
goji
Webアクセスのデータの中にURL Link情報(例えばreferer)データの中に、例えば、www.splunk.comという文字があったとします。 ダッシュボード内に、table refererというデータを表示することで、このU...
by goji Path Finder in Splunk Search 02-01-2017
0 1
0
1
rafiqul
Need help to extract fields between comma (,). The raw data below have two results, FAILURE and SUCCESS. I want to cr...
by rafiqul New Member in Splunk Search 02-01-2017
0 2
0
2
sai_john
index=test File="*.txt" | stats count by host | where count<1 -->with this I am getting NoResults found" but I need ...
by sai_john New Member in Splunk Search 02-01-2017
0 8
0
8
gwalford
One of my users has a lookup table that they have saved appropriately into their app. It was running just fine. Now,...
by gwalford Path Finder in Splunk Search 02-01-2017
1 6
1
6
ajdyer2000
Hi I have a search that returns the following . Adobe Acrobat XI Pro DSC .. Adobe Flash Player ActiveX DSC ... Ad...
by ajdyer2000 Path Finder in Splunk Search 02-01-2017
0 2
0
2
achetreanu
How can I change this query to count the SUM of my events/sec instead of the count of (X OR Y OR Z)/sec : host=myhos...
by achetreanu New Member in Splunk Search 02-01-2017
0 17
0
17
ayusuf
I don't understand how Splunk does regex! I have this search below: ... | spath output=test path=a.b.c | rex field=t...
by ayusuf Engager in Splunk Search 02-01-2017
0 4
0
4
imthesplunker
How to extract the nth letter from the host using regular expression? Sample hosts are :- host=abcdefpghijkl11 (pro...
by imthesplunker Path Finder in Splunk Search 02-01-2017
0 2
0
2
jsndvl11
I'm new to Splunk and need some help with a chart for disk space usage. I'm getting the data already in Splunk Light...
by jsndvl11 New Member in Splunk Search 02-01-2017
0 5
0
5
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...