Splunk Search

Splunk Search
Community Activity
sandmountain
I have a dropdown with two values PROD and TEST. Based on my selection in my panels in the dashboard I have to choose...
by sandmountain Explorer in Splunk Search 09-28-2023
0 3
0
3
eranhauser
I  have events with the following keys: key1, key2 & key3. I would like to get the change events i.e. events that the...
by eranhauser Path Finder in Splunk Search 09-28-2023
0 5
0
5
jbrenner
What's the simplest regex that will match any character including newline? I want to be able to match all unknown con...
by jbrenner Path Finder in Splunk Search 09-28-2023
0 2
0
2
Splunk77
What is the fastest way to run a query to get an event count on a timechart per host? This is for windows events and ...
by Splunk77 Explorer in Splunk Search 09-28-2023
0 1
0
1
danielbb
In Step 2 "Add the Dataset" of "Create Anomaly Job" within the Splunk App for Anomaly Detection, when running the fol...
by danielbb Motivator in Splunk Search 09-28-2023
0 4
0
4
vishalduttauk
Hi there, I have a dashboard and I want to subtract the total number of events of 2 queries but not sure how to do it...
by vishalduttauk Communicator in Splunk Search 09-28-2023
0 6
0
6
sandmountain
I have the following Query:index=obh_prod sourcetype=obh:edge:api proxy!="ow*" |lookup blink_six_providers ProviderId...
by sandmountain Explorer in Splunk Search 09-28-2023
0 1
0
1
swejoos
can't figure out how to indexing my data from zigbee2mgtt.  The logs are exported from Home assistance via syslog, as...
by swejoos Observer in Splunk Search 09-28-2023
0 4
0
4
loganramirez
Greetings. I'm trying to count all calls in this:index="my_data" resourceId="sip*" "CONNECTED"Where not in this:index...
by loganramirez Path Finder in Splunk Search 09-27-2023
0 3
0
3
LearningGuy
Is it possible to run different filter in an index search based on a condition in dropdown below?The second filter wo...
by LearningGuy Motivator in Splunk Search 09-27-2023
0 10
0
10
NanSplk01
I have the following script, but it keeps erroring out.def connect_to_splunk(username,password,host='http://xxxxxxxx....
by NanSplk01 Communicator in Splunk Search 09-27-2023
0 4
0
4
eregon
Hello fellow Splunkthiasts!I need some insights to understand how comparison functions in mstats could be used. Consi...
by eregon Path Finder in Splunk Search 09-27-2023
0 0
0
0
nihvk
How do we capture multiple URLs in a single event?Log1:type=EXECVE msg=audit(1695798790.101:25214323): argc=17 a1="ht...
by nihvk Explorer in Splunk Search 09-27-2023
0 4
0
4
Runals
I've done a little looking and poking around but haven't seen an answer to this - hopefully I haven't overlooked some...
by Runals Motivator in Splunk Search 09-26-2023
0 12
0
12
itsahmedshaikh1
index=botsv1 sourcetype="stream:http" | timechart max(date_year)
by itsahmedshaikh1 Observer in Splunk Search 09-26-2023
0 1
0
1
siva_1
Hi All,I have two csv files. File1.csv -> id, operation_name, session_idFile2.csv -> id, error, operation_nameI want ...
by siva_1 New Member in Splunk Search 09-26-2023
0 3
0
3
hrawat
Blocked auditqueue can cause random skipped searches, scheduler slowness on SH/SHC and slow UI.
by hrawat Splunk Employee Splunk Employee in Splunk Search 09-26-2023
0 1
0
1
rfiscus
I have several events with similar to this raw data field that I would like to break down into a new event for each I...
by rfiscus Path Finder in Splunk Search 09-26-2023
0 13
0
13
jnames10
I have been trying to get nmap output into Splunk. I thought the xml output would be nice and straightforward!Whilst ...
by jnames10 Explorer in Splunk Search 09-26-2023
1 11
1
11
mohsplunking
Hello Splunker, I'm trying to  join two fields values in stats command using Eval , looks like I'm doing it wrong, Pl...
by mohsplunking Path Finder in Splunk Search 09-26-2023
0 8
0
8
Sekhar
Event and Report extract rulesUse the payment business events to identify Transactions which have ACCP clearing statu...
by Sekhar Explorer in Splunk Search 09-26-2023
0 1
0
1
alexspunkshell
In my search results, I am getting IP and user details. I want to filter my search results if the same IP has been us...
by alexspunkshell Contributor in Splunk Search 09-25-2023
0 8
0
8
bluewizard
I have a query below that looked for an index and output to a csv file however. the size of the csv keep growing and ...
by bluewizard Explorer in Splunk Search 09-25-2023
0 2
0
2
gsmith93
I am trying to create a Dashboard that hold multiple table of WebSphere App Server configuration data.  The data I ha...
by gsmith93 Engager in Splunk Search 09-25-2023
0 8
0
8
arist0telis
I'm working with a table of conversation data, all conversations start out as a bot chat and can be escalated to a hu...
by arist0telis Explorer in Splunk Search 09-25-2023
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...