Splunk Search

Splunk Search
Community Activity
jnahuelperez35
Hi guys! i'm going crazy trying to find a way to solve this problem. I'm trying to find the percentage of Non Cleane...
by jnahuelperez35 Path Finder in Splunk Search 12-27-2016
0 5
0
5
jmaple
I'm trying to alert on a specific event code but there are certain combinations where these event codes are acceptabl...
by jmaple Communicator in Splunk Search 12-27-2016
0 3
0
3
splunker9999
Hi , we need to create an alert and trigger this to my team. Being that below is my search base query looks like ind...
by splunker9999 Path Finder in Splunk Search 12-27-2016
0 2
0
2
ankithreddy777
I used timechart command to display 1 hour intervals data. I am getting results starting from 00:00 with 1 hour inter...
by ankithreddy777 Contributor in Splunk Search 12-27-2016
0 1
0
1
papemalik
Hello, I would like the display by user, different count. For example: i have several rule such as M, N, O, P, Q . ...
by papemalik Explorer in Splunk Search 12-27-2016
0 3
0
3
MsherVin
Does anyone have an example of how to use: reset_after="(" < eval-expression > ")" and reset_before="(" < eval-e...
by MsherVin New Member in Splunk Search 12-26-2016
0 2
0
2
yashwanth_g_pra
Can someone help out with a search for the below context: 1) Need to get all the public IPs having blocked traffic (...
by yashwanth_g_pra Observer in Splunk Search 12-26-2016
0 2
0
2
vikas_gopal
Hi Experts, I know that we have Splunk App for Windows Infrastructure but I am not using this app. For CPU and Proce...
by vikas_gopal Builder in Splunk Search 12-26-2016
0 4
0
4
avaishsplunk
Unable to set value for earliest and latest, I am getting errors. Below is my search query. eval earliest=if(strftim...
by avaishsplunk Path Finder in Splunk Search 12-26-2016
0 6
0
6
twh1
I am getting the file path in my search result. When I am displaying it in dashboard with chart, I need to only extra...
by twh1 Communicator in Splunk Search 12-26-2016
0 2
0
2
aliroumani
dears i want to compare two indexes to find the values in index 1 and not in index 2 index 1 have field called accoun...
by aliroumani Explorer in Splunk Search 12-25-2016
0 2
0
2
ksing
Hi, I am running a search to find out the response time using the below query: mysearch | |eval diffResponse= ackTi...
by ksing New Member in Splunk Search 12-25-2016
0 8
0
8
TheGU
I have b/w data from multiple switch sourcetype=switch _time | sw | port1 | port2 | port3 | port4 00:01 | sw1 | ...
by TheGU Path Finder in Splunk Search 12-25-2016
0 4
0
4
sbenamro
Hi, I can see that there is a firewall that has started to send huge amount of traffic. how can I see which event typ...
by sbenamro New Member in Splunk Search 12-25-2016
0 2
0
2
bowa
I would like to combine the following two searches in one timechart: host="appserv" OAuth participants POST | regex ...
by bowa Path Finder in Splunk Search 12-24-2016
1 3
1
3
nsmouli
Hi - I have 2 drop-downs: Year lists down all the years, Month list down all the months. Now i would need to pass t...
by nsmouli New Member in Splunk Search 12-24-2016
0 2
0
2
kualo
Hi I want to show score distribution by column chart. The score ranges from 0 to 100 I have the below search and it ...
by kualo Explorer in Splunk Search 12-24-2016
0 2
0
2
heats
We're going to be migrating our Splunk to a central instance. I need to start pulling some information which I think ...
by heats Explorer in Splunk Search 12-23-2016
0 4
0
4
saransakthi83
I tried to use the value of main search regex in subsearch rex . Main search |rex "(?regular expression)"|append [s...
by saransakthi83 New Member in Splunk Search 12-23-2016
0 2
0
2
HCadmins
I have a linechart with values that increase each day. Is there a way to calculate and display the percentage of grow...
by HCadmins Communicator in Splunk Search 12-23-2016
0 4
0
4
twinspop
EDIT: It appears subsearch is what's broken, not appendcols. The follow fails on 5.0.2 search heads, but not 4.3.4 se...
by twinspop Influencer in Splunk Search 12-23-2016
0 1
0
1
dibrova911
I am new to Splunk I need to know how to create bar chart count only by certain tags For example event has tag=t1,t2...
by dibrova911 New Member in Splunk Search 12-23-2016
0 1
0
1
nivethainspire_
what is the rex command to extract the below highlighted field. 2015-12-22 22:40:13 ID="87602", Data_Name="sap01 "D...
by nivethainspire_ Explorer in Splunk Search 12-23-2016
0 1
0
1
mspoerr
Hello, I have Message-Tracking Logs from Exchange 2016 servers where the fields are comma separated, but in some lin...
by mspoerr Path Finder in Splunk Search 12-23-2016
0 4
0
4
kausar
I have multiple queries for same index and therefore trying to avoid subsearches. Looking for right syntax, trying to...
by kausar Path Finder in Splunk Search 12-22-2016
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...