Splunk Search

Splunk Search
Community Activity
scout29
Looking to create a search / report showing the ingest by source ingestion method in the last 24hours. I am looking f...
by scout29 Path Finder in Splunk Search 10-03-2023
0 2
0
2
yohhpark
trying to set a token where system_id shows ABC1, ABC1-a, ABC10, ABC10-a and so on. when I set the token for that sys...
by yohhpark Path Finder in Splunk Search 10-03-2023
0 2
0
2
El_Franco
Hopefully this will set the issue out clearly. I have two sources, Transaction and Request.The Transaction holds the ...
by El_Franco Explorer in Splunk Search 10-03-2023
0 1
0
1
Geep
Is it possible to modify the value of a token obtained from a dashboard input prior to it being used in a panel? In t...
by Geep Engager in Splunk Search 10-03-2023
0 2
0
2
TheMorf
I am trying to extract the difference of time(duration) of 2 events in days. I have 2 saperate event for the same ID....
by TheMorf New Member in Splunk Search 10-03-2023
0 1
0
1
JohnEGones
Hi Fellow Splunkers,Have a hopefully quick question:Want to pull out the source and host from the Windows _internal s...
by JohnEGones Communicator in Splunk Search 10-03-2023
0 2
0
2
AL3Z
Hi,Can anyone pls figure out from these  list of apps which of these apps from web logs are not required for investig...
by AL3Z Builder in Splunk Search 10-03-2023
0 1
0
1
Whiteboardsarer
Hello Splunk Community,I hope this message finds you well. I'm currently working on enhancing my workflow in the Sear...
by Whiteboardsarer New Member in Splunk Search 10-03-2023
0 0
0
0
darphboubou
Hi Actualy I trying to search data even the archived ones but as you can see in printscreen below I get only the 3 la...
by darphboubou Explorer in Splunk Search 10-03-2023
0 1
0
1
anissabnk
Hello,   I hope everything is okay.   I need your help.   I am using this spl request : "index="bloc1rg" AND libelle ...
by anissabnk Path Finder in Splunk Search 10-03-2023
0 2
0
2
Amit79
Hello All,I  am calculating burnrate in splunk,  and using addinfo for enrichment to display it on the dashboard.Burn...
by Amit79 Loves-to-Learn Everything in Splunk Search 10-02-2023
0 1
0
1
balcv
Is it possible to have the true and false parts of an if statement contain eval statements.  | eval pwdExpire=if(type...
by balcv Contributor in Splunk Search 10-02-2023
0 3
0
3
10061987
Hi all,I searched my issue on community. There are lots of threads but i couldn't find my issue. As i know i can not ...
by 10061987 Engager in Splunk Search 10-02-2023
0 1
0
1
Splunk235
I have error logs like the below. How can I write a Rex query to match both the logs and only extract the message aft...
by Splunk235 Engager in Splunk Search 10-02-2023
0 5
0
5
gauravu_14
I need to compare the values of 2 fields from the Splunk data with the field-values from the lookup and find the miss...
by gauravu_14 Explorer in Splunk Search 10-02-2023
0 3
0
3
PankajAgr
I have event Logs Similar to this. {Level: Information MessageTemplate: Received Post Method for activity: {Activity}...
by PankajAgr Loves-to-Learn in Splunk Search 09-30-2023
0 7
0
7
Utkc137
Greetings, I am struggling with creating a table in splunk which would do the following transformation:Find the discr...
by Utkc137 Explorer in Splunk Search 09-30-2023
0 11
0
11
SplunkySplunk
HelloI'm trying to count events by field called "UserAgent"If im searching for the events without any calculated fiel...
by SplunkySplunk Explorer in Splunk Search 09-30-2023
0 3
0
3
Thulasinathan_M
Hi Splunk Experts,The timewrap command is using d(24 hr) format, but I'm wondering is it possible to make it Today fo...
by Thulasinathan_M Contributor in Splunk Search 09-29-2023
0 2
0
2
danielbb
We ran into this known issue with the AD servers having indexing delays of a couple of days when enabling evt_resolve...
by danielbb Motivator in Splunk Search 09-29-2023
0 0
0
0
Krish14
Query to output missing data in lookup file.I have a lookup file with below datacountry_name--------------------Brazi...
by Krish14 Explorer in Splunk Search 09-29-2023
0 5
0
5
jbrenner
I'm using the rex command to parse a value out of the results of a transaction command. Is there an easy way to restr...
by jbrenner Path Finder in Splunk Search 09-29-2023
0 2
0
2
jackueline14
Hi,I have Error logs which is having more than 50 lines but requirement is to be displayed for 1st 10 lines instead m...
by jackueline14 New Member in Splunk Search 09-28-2023
0 1
0
1
rprior
Hello all,We have a Splunk alert that searches for high temperature events on Juniper routers, it's a very straight f...
by rprior Explorer in Splunk Search 09-28-2023
0 2
0
2
Bennette
In the documentation on dataset literals there is an example query: FROM [ { state: "Washington", abbreviation: "WA",...
by Bennette Explorer in Splunk Search 09-28-2023
0 9
0
9
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...