Splunk Search

Splunk Search
Community Activity
Whiteboardsarer
Hello Splunk Community,I hope this message finds you well. I'm currently working on enhancing my workflow in the Sear...
by Whiteboardsarer New Member in Splunk Search 10-03-2023
0 0
0
0
darphboubou
Hi Actualy I trying to search data even the archived ones but as you can see in printscreen below I get only the 3 la...
by darphboubou Explorer in Splunk Search 10-03-2023
0 1
0
1
anissabnk
Hello,   I hope everything is okay.   I need your help.   I am using this spl request : "index="bloc1rg" AND libelle ...
by anissabnk Path Finder in Splunk Search 10-03-2023
0 2
0
2
Amit79
Hello All,I  am calculating burnrate in splunk,  and using addinfo for enrichment to display it on the dashboard.Burn...
by Amit79 Loves-to-Learn Everything in Splunk Search 10-02-2023
0 1
0
1
balcv
Is it possible to have the true and false parts of an if statement contain eval statements.  | eval pwdExpire=if(type...
by balcv Contributor in Splunk Search 10-02-2023
0 3
0
3
10061987
Hi all,I searched my issue on community. There are lots of threads but i couldn't find my issue. As i know i can not ...
by 10061987 Engager in Splunk Search 10-02-2023
0 1
0
1
Splunk235
I have error logs like the below. How can I write a Rex query to match both the logs and only extract the message aft...
by Splunk235 Engager in Splunk Search 10-02-2023
0 5
0
5
gauravu_14
I need to compare the values of 2 fields from the Splunk data with the field-values from the lookup and find the miss...
by gauravu_14 Explorer in Splunk Search 10-02-2023
0 3
0
3
PankajAgr
I have event Logs Similar to this. {Level: Information MessageTemplate: Received Post Method for activity: {Activity}...
by PankajAgr Loves-to-Learn in Splunk Search 09-30-2023
0 7
0
7
Utkc137
Greetings, I am struggling with creating a table in splunk which would do the following transformation:Find the discr...
by Utkc137 Explorer in Splunk Search 09-30-2023
0 11
0
11
SplunkySplunk
HelloI'm trying to count events by field called "UserAgent"If im searching for the events without any calculated fiel...
by SplunkySplunk Explorer in Splunk Search 09-30-2023
0 3
0
3
Thulasinathan_M
Hi Splunk Experts,The timewrap command is using d(24 hr) format, but I'm wondering is it possible to make it Today fo...
by Thulasinathan_M Contributor in Splunk Search 09-29-2023
0 2
0
2
danielbb
We ran into this known issue with the AD servers having indexing delays of a couple of days when enabling evt_resolve...
by danielbb Motivator in Splunk Search 09-29-2023
0 0
0
0
Krish14
Query to output missing data in lookup file.I have a lookup file with below datacountry_name--------------------Brazi...
by Krish14 Explorer in Splunk Search 09-29-2023
0 5
0
5
jbrenner
I'm using the rex command to parse a value out of the results of a transaction command. Is there an easy way to restr...
by jbrenner Path Finder in Splunk Search 09-29-2023
0 2
0
2
jackueline14
Hi,I have Error logs which is having more than 50 lines but requirement is to be displayed for 1st 10 lines instead m...
by jackueline14 New Member in Splunk Search 09-28-2023
0 1
0
1
rprior
Hello all,We have a Splunk alert that searches for high temperature events on Juniper routers, it's a very straight f...
by rprior Explorer in Splunk Search 09-28-2023
0 2
0
2
Bennette
In the documentation on dataset literals there is an example query: FROM [ { state: "Washington", abbreviation: "WA",...
by Bennette Explorer in Splunk Search 09-28-2023
0 9
0
9
noorani1980
whats the difference between :: and = in splunk search. what are the benefits vs drawbacks
by noorani1980 Engager in Splunk Search 09-28-2023
0 1
0
1
sandmountain
I have a dropdown with two values PROD and TEST. Based on my selection in my panels in the dashboard I have to choose...
by sandmountain Explorer in Splunk Search 09-28-2023
0 3
0
3
eranhauser
I  have events with the following keys: key1, key2 & key3. I would like to get the change events i.e. events that the...
by eranhauser Path Finder in Splunk Search 09-28-2023
0 5
0
5
jbrenner
What's the simplest regex that will match any character including newline? I want to be able to match all unknown con...
by jbrenner Path Finder in Splunk Search 09-28-2023
0 2
0
2
Splunk77
What is the fastest way to run a query to get an event count on a timechart per host? This is for windows events and ...
by Splunk77 Explorer in Splunk Search 09-28-2023
0 1
0
1
danielbb
In Step 2 "Add the Dataset" of "Create Anomaly Job" within the Splunk App for Anomaly Detection, when running the fol...
by danielbb Motivator in Splunk Search 09-28-2023
0 4
0
4
vishalduttauk
Hi there, I have a dashboard and I want to subtract the total number of events of 2 queries but not sure how to do it...
by vishalduttauk Communicator in Splunk Search 09-28-2023
0 6
0
6
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...