Splunk Search

Splunk Search
Community Activity
tkwaller
I know this is fairly simple question. I am trying to do a couple evals on userAgent fields, as I am trying not to us...
by tkwaller Builder in Splunk Search 10-17-2016
0 5
0
5
Paul1896
Hello, I hope anyone can help me. My search eval epochtime=strptime(DATUM,"%d.%m.%Y") | eval datefield=strftime(ep...
by Paul1896 Path Finder in Splunk Search 10-17-2016
0 16
0
16
gcusello
Hi at all, I would extract a field as a part of source field and I know how to do this using rex command | rex field...
by SplunkTrust SplunkTrust in Splunk Search 10-17-2016
0 4
0
4
egreibl
Hi guys, hope you can help me. I want to have a statistic of my users. The most of the users access the search&repo...
by egreibl Engager in Splunk Search 10-17-2016
0 4
0
4
sumituv
Hi, I am configuring Field Extractor to extract fields from a single files directly from events>action>extract field...
by sumituv New Member in Splunk Search 10-16-2016
0 2
0
2
dbcase
Hi, I'm trying to pull the user ID from the below data? The userids are: mspeer2, ddaniel, mirella, jcrews I have...
by dbcase Motivator in Splunk Search 10-16-2016
0 7
0
7
brywilk_umich
Hello, I have the following search index=collaboration sourcetype="mail-2" Auth | geoip simta_client_ip | dedup simt...
by brywilk_umich Path Finder in Splunk Search 10-16-2016
0 2
0
2
mbintz
If I have a search that returns a table with multi-values in two different columns, how can I find the unique element...
by mbintz Explorer in Splunk Search 10-15-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the following subqueries: The first extracts ...
by IRHM73 Motivator in Splunk Search 10-15-2016
0 9
0
9
VidhyaR
We have different indexes with varied retention and volumes. We would like to be able to restrict some roles to searc...
by VidhyaR New Member in Splunk Search 10-14-2016
0 3
0
3
rajgowd1
How to display values in xyseries format? i have log like below tcp 0 0 12b8-splfwd02.nam.nsro:7171 poc-...
by rajgowd1 Communicator in Splunk Search 10-14-2016
0 15
0
15
rajgowd1
HI Experts, i am able to exact 4th and 5th fields from below log but i am able to exact get the value if the 4th or 5...
by rajgowd1 Communicator in Splunk Search 10-14-2016
0 8
0
8
landen99
Searching for events which match any of multiple values for the same field times several fields in a lookup using the...
by landen99 Motivator in Splunk Search 10-14-2016
0 1
0
1
viggor
I woudl like to know, per CountryId, what fraction of FooId equal to BarId In the follwoing log: MyEvent CountryId=...
by viggor Path Finder in Splunk Search 10-14-2016
0 1
0
1
larryleeroberts
I am trying to pull data from Splunk via a search and send it to Netcool OMNIbus. Right now I am just sending it via ...
by larryleeroberts Path Finder in Splunk Search 10-14-2016
0 7
0
7
justx001
I am having alot of trouble setting up rolling averages in Splunk. I would love to be able to overlay a 30, 60, 90 da...
by justx001 Explorer in Splunk Search 10-14-2016
1 4
1
4
DEAD_BEEF
I have some Windows event log data that shows the ID when a user logs in and logs out. In addition, it shows me the ...
by DEAD_BEEF Builder in Splunk Search 10-14-2016
0 4
0
4
tinylund
Fairly new to Splunk and I am trying to understand the reason for the difference in results and search time for the f...
by tinylund Explorer in Splunk Search 10-14-2016
0 1
0
1
accragv1
When Trying to run below query in Splunk search: | gentimes start=-1 | eval YourDate="3:21:34 PM 10/14/2016" | table...
by accragv1 Explorer in Splunk Search 10-14-2016
0 7
0
7
jwalzerpitt
I have three event types: eventtype="windows_login_failed" eventtype="duo_login_failed" eventtype="sremote_login_fai...
by jwalzerpitt Influencer in Splunk Search 10-14-2016
0 6
0
6
jbala1
example: If I have a list of user and I want to search and the users who only have a number in that field; John_doe...
by jbala1 Engager in Splunk Search 10-14-2016
0 3
0
3
patng323
In an running a command which uses the dedup command: index=myindex earliest=-5d@d latest=@d | bin _time span=1d | ...
by patng323 Explorer in Splunk Search 10-14-2016
0 13
0
13
brywilk_umich
Hello, I have a search (see below) that Im having a little trouble with. With it it returns the fields correctly, b...
by brywilk_umich Path Finder in Splunk Search 10-14-2016
0 4
0
4
pavanae
I have a search as follows field="abc"| eval b=len(_raw) | timechart span=1h sum(b) as b | eval mb=round(b/1024/1024...
by pavanae Builder in Splunk Search 10-14-2016
0 4
0
4
burras
I have a syslog feed coming in to our Splunk system that is essentially a CSV file. It's a conglomeration of the res...
by burras Communicator in Splunk Search 10-14-2016
0 9
0
9
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...