Splunk Search

Splunk Search
Community Activity
danielbb
We ran into this known issue with the AD servers having indexing delays of a couple of days when enabling evt_resolve...
by danielbb Motivator in Splunk Search 09-29-2023
0 0
0
0
Krish14
Query to output missing data in lookup file.I have a lookup file with below datacountry_name--------------------Brazi...
by Krish14 Explorer in Splunk Search 09-29-2023
0 5
0
5
jbrenner
I'm using the rex command to parse a value out of the results of a transaction command. Is there an easy way to restr...
by jbrenner Path Finder in Splunk Search 09-29-2023
0 2
0
2
jackueline14
Hi,I have Error logs which is having more than 50 lines but requirement is to be displayed for 1st 10 lines instead m...
by jackueline14 New Member in Splunk Search 09-28-2023
0 1
0
1
rprior
Hello all,We have a Splunk alert that searches for high temperature events on Juniper routers, it's a very straight f...
by rprior Explorer in Splunk Search 09-28-2023
0 2
0
2
Bennette
In the documentation on dataset literals there is an example query: FROM [ { state: "Washington", abbreviation: "WA",...
by Bennette Explorer in Splunk Search 09-28-2023
0 9
0
9
noorani1980
whats the difference between :: and = in splunk search. what are the benefits vs drawbacks
by noorani1980 Engager in Splunk Search 09-28-2023
0 1
0
1
sandmountain
I have a dropdown with two values PROD and TEST. Based on my selection in my panels in the dashboard I have to choose...
by sandmountain Explorer in Splunk Search 09-28-2023
0 3
0
3
eranhauser
I  have events with the following keys: key1, key2 & key3. I would like to get the change events i.e. events that the...
by eranhauser Path Finder in Splunk Search 09-28-2023
0 5
0
5
jbrenner
What's the simplest regex that will match any character including newline? I want to be able to match all unknown con...
by jbrenner Path Finder in Splunk Search 09-28-2023
0 2
0
2
Splunk77
What is the fastest way to run a query to get an event count on a timechart per host? This is for windows events and ...
by Splunk77 Explorer in Splunk Search 09-28-2023
0 1
0
1
danielbb
In Step 2 "Add the Dataset" of "Create Anomaly Job" within the Splunk App for Anomaly Detection, when running the fol...
by danielbb Motivator in Splunk Search 09-28-2023
0 4
0
4
vishalduttauk
Hi there, I have a dashboard and I want to subtract the total number of events of 2 queries but not sure how to do it...
by vishalduttauk Communicator in Splunk Search 09-28-2023
0 6
0
6
sandmountain
I have the following Query:index=obh_prod sourcetype=obh:edge:api proxy!="ow*" |lookup blink_six_providers ProviderId...
by sandmountain Explorer in Splunk Search 09-28-2023
0 1
0
1
swejoos
can't figure out how to indexing my data from zigbee2mgtt.  The logs are exported from Home assistance via syslog, as...
by swejoos Observer in Splunk Search 09-28-2023
0 4
0
4
loganramirez
Greetings. I'm trying to count all calls in this:index="my_data" resourceId="sip*" "CONNECTED"Where not in this:index...
by loganramirez Path Finder in Splunk Search 09-27-2023
0 3
0
3
LearningGuy
Is it possible to run different filter in an index search based on a condition in dropdown below?The second filter wo...
by LearningGuy Motivator in Splunk Search 09-27-2023
0 10
0
10
NanSplk01
I have the following script, but it keeps erroring out.def connect_to_splunk(username,password,host='http://xxxxxxxx....
by NanSplk01 Communicator in Splunk Search 09-27-2023
0 4
0
4
eregon
Hello fellow Splunkthiasts!I need some insights to understand how comparison functions in mstats could be used. Consi...
by eregon Path Finder in Splunk Search 09-27-2023
0 0
0
0
nihvk
How do we capture multiple URLs in a single event?Log1:type=EXECVE msg=audit(1695798790.101:25214323): argc=17 a1="ht...
by nihvk Explorer in Splunk Search 09-27-2023
0 4
0
4
Runals
I've done a little looking and poking around but haven't seen an answer to this - hopefully I haven't overlooked some...
by Runals Motivator in Splunk Search 09-26-2023
0 12
0
12
itsahmedshaikh1
index=botsv1 sourcetype="stream:http" | timechart max(date_year)
by itsahmedshaikh1 Observer in Splunk Search 09-26-2023
0 1
0
1
siva_1
Hi All,I have two csv files. File1.csv -> id, operation_name, session_idFile2.csv -> id, error, operation_nameI want ...
by siva_1 New Member in Splunk Search 09-26-2023
0 3
0
3
hrawat
Blocked auditqueue can cause random skipped searches, scheduler slowness on SH/SHC and slow UI.
by hrawat Splunk Employee Splunk Employee in Splunk Search 09-26-2023
0 1
0
1
rfiscus
I have several events with similar to this raw data field that I would like to break down into a new event for each I...
by rfiscus Path Finder in Splunk Search 09-26-2023
0 13
0
13
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors