Splunk Search

Splunk Search
Community Activity
jlvix1
Hi all, I have tried everything... In props.conf SEDCMD-replacespaces = s/\s/_/g and also SEDCMD-replacespace...
by jlvix1 Communicator in Splunk Search 08-23-2016
0 14
0
14
jacomharada
パケットキャプチャデータをCSVに変換した後Splunkにコマンドラインにてoneshotでデータを入力するとデータが欠損したようになります。 取り込んだデータ配下のようになっており、★が付いている箇所について取り込むとデータがサーチ...
by jacomharada Explorer in Splunk Search 08-22-2016
0 4
0
4
swannie
Hi all, I'm trying to extract key/value data from SNMP trap data logged to my splunk server. I have snmptrapd runni...
by swannie New Member in Splunk Search 08-22-2016
0 7
0
7
daishih
When I run the following transaction search from the dashboard I created it only displays "host=.... source=.... sour...
by daishih Path Finder in Splunk Search 08-22-2016
0 5
0
5
syed_star357
Hi Team, How to search which are the hosts and Sources not sending logs to Splunk? The below metadata search shows o...
by syed_star357 New Member in Splunk Search 08-22-2016
0 6
0
6
samdavies
I have events with this structure: { id, version, event_type }. The id field corresponds to a device ID. I'm trying t...
by samdavies Engager in Splunk Search 08-22-2016
0 17
0
17
chanduira
Hi Experts, I am getting data from 10 sources, I want to send 3 source data to nullque. I tried with below props.co...
by chanduira Explorer in Splunk Search 08-22-2016
0 2
0
2
Marwalg
my regex expression works properly but I since I'am newbie in splunk I didn't know how to get the rex expression. I w...
by Marwalg New Member in Splunk Search 08-21-2016
0 2
0
2
friscos
Hi, I would like to extract the XML field value from an XML string from the log and include it in the search. What i...
by friscos Explorer in Splunk Search 08-21-2016
0 13
0
13
miraclen
リストボックストークン:トークン名=D01 、選択肢:XYZ ※Field-AにXYZが代入されているとみなす。 入力ログ:index=IDX1 ルックアップ定義:|lookup Looktest Field-A OUTPUT Fie...
by miraclen New Member in Splunk Search 08-21-2016
0 1
0
1
rmearkle
I am trying to update a table when an item in my javascript chart is clicked. Previously, this worked fine: JavaScrip...
by rmearkle Explorer in Splunk Search 08-21-2016
0 4
0
4
AravindSridhara
I have multiple Queues and I have created a field X_Queuename, and in the message management logs, I get a number of ...
by AravindSridhara New Member in Splunk Search 08-21-2016
0 4
0
4
ashutoshsharma1
How to convert the output of a search with stats command that's generating a table as output to events? Thus send Ev...
by ashutoshsharma1 Path Finder in Splunk Search 08-21-2016
0 10
0
10
splunker9999
Hi, We are looking for a search which would give availability for the last 3 months. We came come up with the sear...
by splunker9999 Path Finder in Splunk Search 08-21-2016
0 2
0
2
syed_star357
Hi Team, How can I write search for the below use case? We have a Financial Audit Department. If any one accesses Fi...
by syed_star357 New Member in Splunk Search 08-21-2016
0 1
0
1
zqmirza
I am using the search below to get two different averages from two different indexes: index=a| bucket _time span=4h ...
by zqmirza New Member in Splunk Search 08-20-2016
0 2
0
2
bmo017
Hello, I am looking for information on how I would go about monitoring firewall logs with excessive accepts to the s...
by bmo017 Path Finder in Splunk Search 08-20-2016
0 2
0
2
karthikbits
Single log line: {kpiMuleMS=12, kpiSecurityCheckMS=230, kpiGetQuoteMS=56, kpiGetLegalEntityMS=0, kpiOIILookupPersona...
by karthikbits New Member in Splunk Search 08-19-2016
0 2
0
2
dbcase
Hi, First time trying to use pardelim and kvdelim and having no luck. The data looks like this ####<Aug 19, 201...
by dbcase Motivator in Splunk Search 08-19-2016
0 11
0
11
lmtaylor
We are having an issues getting results back from scheduled searches. When I open the instance of a report I get eith...
by lmtaylor Engager in Splunk Search 08-19-2016
0 1
0
1
riotto
When I run the below command, it returns some of the grouped events, but not all of them. It will not return the most...
by riotto Path Finder in Splunk Search 08-19-2016
0 3
0
3
mcy
I have a search that tracks VPN logins for known/unknown users that works fine. I am trying to filter for only login...
by mcy Engager in Splunk Search 08-19-2016
0 3
0
3
dbcase
Hi, I have the following search: host="*beta*" index=wls OR index=main sourcetype=wls_managedserver OR source="/etc...
by dbcase Motivator in Splunk Search 08-19-2016
0 12
0
12
omgwut56k
My data for field entity contains either a username or an ip address. How can make a new field for either user or sr...
by omgwut56k Path Finder in Splunk Search 08-19-2016
0 6
0
6
mwdbhyat
Hi, I need to automate the backfill script for about 60 searches.. Is there a way to put all 60 searches in a single...
by mwdbhyat Builder in Splunk Search 08-19-2016
0 11
0
11
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors