Splunk Search

Splunk Search
Community Activity
dkorlat
Hi I'm trying to perform a subsearch to get a list of users in a lookup table and map the mail field to recipients an...
by dkorlat Explorer in Splunk Search 08-11-2016
0 2
0
2
greeshmak
Example: application="example" index=web uri_path="/some/example/*" In my application, I have similar uri_paths. I...
by greeshmak Explorer in Splunk Search 08-11-2016
0 6
0
6
ashishlal82
I have a field name hosts which has values as: 10.128.193.39,10.128.193.52,10.128.193.47,10.128.193.55,10.128.193.40...
by ashishlal82 Explorer in Splunk Search 08-11-2016
0 1
0
1
anoopambli
Looking for some help with rex. The raw data looks like this, value= Name : SiteScope.exe MemGB : 6568 Name : powers...
by anoopambli Communicator in Splunk Search 08-11-2016
0 4
0
4
mcbradford
Not the best regex king, so I need some help please within the field "From" in my data there are emails. Within the...
by mcbradford Contributor in Splunk Search 08-11-2016
0 3
0
3
Hegemon76
Hello, Lets say I have a firewall and an IPS and I wanted to correlate based on source IP I'm trying to figure out t...
by Hegemon76 Communicator in Splunk Search 08-11-2016
0 11
0
11
pradjswl
How do I extract a substring from a field value, ignoring a word containing a particular character, let's say %2. Or...
by pradjswl Explorer in Splunk Search 08-11-2016
0 3
0
3
rajiv_abraham
Hi, Great documentation at: http://dev.splunk.com/view/python-sdk/SP-CAAAEE5#getcollparams I'd like to know what is...
by rajiv_abraham Explorer in Splunk Search 08-11-2016
0 3
0
3
daniel333
All, So I am playing with the netstat feature in Splunk for Unix. There does not seem to be field extractions for t...
by daniel333 Builder in Splunk Search 08-11-2016
0 3
0
3
chadman
I have a search that creates a time in HH:MM and looks like 04:34.000. How can I drop the .000 at the end of this? ...
by chadman Path Finder in Splunk Search 08-11-2016
0 7
0
7
najarvis
I am using the Splunk JavaScript API to create a dashboard to aggregate data. One of my searches that I want literall...
by najarvis Engager in Splunk Search 08-11-2016
0 1
0
1
chadman
I would like to show the HH:MM of my search as a field in a table. How can I set that up as a field?
by chadman Path Finder in Splunk Search 08-11-2016
1 6
1
6
mwdbhyat
Hi there, Can someone help me create my backfill script? I am creating a new summary index that runs every 10min wit...
by mwdbhyat Builder in Splunk Search 08-11-2016
0 4
0
4
SrinivasaC
Hi, We have 100 's of in our splunk system, what i need is, what are configured Forwarder Inputs in splunk system fo...
by SrinivasaC Path Finder in Splunk Search 08-11-2016
0 4
0
4
chapa
Currently Splunk puts the bar chart labels off to the left and truncates them which makes things really hard to read:...
by chapa Explorer in Splunk Search 08-11-2016
0 4
0
4
Vettori
Hello, I have a query like so: source=“some-source.log” MySearchQuery | stats count by user, host_name which produce...
by Vettori Engager in Splunk Search 08-11-2016
0 4
0
4
mansel_scheffel
Hi, I am trying to schedule 60 saved searches with summery indexing. There are for 5 different searches, each with 4...
by mansel_scheffel Explorer in Splunk Search 08-11-2016
0 5
0
5
karthiknzx
Hi there index=someIndex | stats = sum(fieldA) as one, sum(fieldB) as two I would like to display the result in the ...
by karthiknzx Engager in Splunk Search 08-10-2016
0 2
0
2
chvnc
We have a field with data 00 00:01:00.209 00 00:00:59.540 00 00:00:10.528 00 00:00:10.014 00 00:00:10.010 00 00:00:09...
by chvnc Explorer in Splunk Search 08-10-2016
0 6
0
6
unclethan
I have JSON events with a sub list and want to sum similarly named fields for each event. { "id": "theid", "subdata"...
by unclethan Path Finder in Splunk Search 08-10-2016
0 6
0
6
vstrash
My data displays in splunk and ![I was able to generate a correct table via running the command index=cmadam host=kot...
by vstrash New Member in Splunk Search 08-10-2016
0 2
0
2
dbray_sd
Here is the sample set of data, simplified: Aug 8 11:00:00 host=host1 status_code=UP Aug 8 12:20:00 host=host1 sta...
by dbray_sd Path Finder in Splunk Search 08-10-2016
0 2
0
2
Cuyose
Not sure why I cant find this, but the following is not working. |rex field=_raw "(?i)response=(?<responseXML>.+)$" ...
by Cuyose Builder in Splunk Search 08-10-2016
0 12
0
12
splunker9999
Hi , We have search that runs for every minute, and if in case it found any Service is down, it triggers an alert. H...
by splunker9999 Path Finder in Splunk Search 08-10-2016
0 6
0
6
sdettling
How can I make the results of a count on the user field case insensitive? index=winevents sourcetype="WinEventLog:Se...
by sdettling New Member in Splunk Search 08-10-2016
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...