Splunk Search

Splunk Search
Community Activity
skiller1234
So I am new to Splunk, but cannot seem to find the answer to this likely simple search question. So I need to search...
by skiller1234 Explorer in Splunk Search 08-05-2016
1 2
1
2
sloshburch
I was talking with someone who may have assets with the same IP across multiple data centers. In other words, the sam...
by sloshburch Ultra Champion in Splunk Search 08-05-2016
0 18
0
18
pmdba
I have a query like the following that I am using to trend the number of users active in an application during a give...
by pmdba Builder in Splunk Search 08-05-2016
1 2
1
2
Buscatrufas
Hi guys, I have 2 sources, historical and current, i need to catch the new events in my monitor, so i compare curren...
by Buscatrufas Path Finder in Splunk Search 08-05-2016
0 2
0
2
borshoff
Hello. I need to monitor events with EventCode="4656 on windows server. But only events with string "ObjectType: Fil...
by borshoff Explorer in Splunk Search 08-05-2016
0 1
0
1
lefelle
i have a file with filed date like 03/08/2016 09:25 GMT+02:00 My sourcetype doesn't work with %d/%m/%Y %H:%M %Z%z \...
by lefelle New Member in Splunk Search 08-05-2016
0 2
0
2
chandra61446
I have search below .. |inputlookup biweekly_backup | join type=outer max=0 host [search index=tsm sourcetype="tsm-c...
by chandra61446 New Member in Splunk Search 08-05-2016
0 4
0
4
jwertheim
I'm using the following regular expression: (?<timestamp>:"(\d{1,4}\-\d{1,2}\-\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2})"|(\d...
by jwertheim Explorer in Splunk Search 08-05-2016
0 9
0
9
atiruval
I have a table and one of the column is for URLs. I want to highlight the URLs in blue color. Please let me know how...
by atiruval New Member in Splunk Search 08-05-2016
0 2
0
2
gabriel_vasseur
With tstats, I can't seem to get access to the original events. Even in "verbose" mode, the "Events" tab contains onl...
by gabriel_vasseur Contributor in Splunk Search 08-05-2016
2 3
2
3
Sukisen1981
I have a timechart with 3 line series: A,B and C Now, I have used series colors in Simple XML to change the colors o...
by Sukisen1981 Champion in Splunk Search 08-04-2016
0 2
0
2
proylea
ok, here is my dilemma I have a lookup table like this: _raw,sourcetype,alertMessage,severity *Reloading repositor...
by proylea Contributor in Splunk Search 08-04-2016
0 7
0
7
ZacEsa
Hi, I'm doing two searches with custom rex extraction of fields. For both searches, I have named all the fields I ext...
by ZacEsa Communicator in Splunk Search 08-04-2016
0 3
0
3
information_sec
I'm trying to find the average time (in weeks) it takes to patch specific network vulnerabilities. I take in data fro...
by information_sec New Member in Splunk Search 08-04-2016
0 3
0
3
dpanych
I have an alert that runs every hour at the half hour mark. So at 1:30, 2:30, etc... When I run the timechart command...
by dpanych Communicator in Splunk Search 08-04-2016
0 1
0
1
ivonnepena
I am trying to create new fields to search across multiple sources. I have two problems: When searching for data of ...
by ivonnepena New Member in Splunk Search 08-04-2016
0 3
0
3
phudinhha
Dear Team, What i am trying to achieve is like this: I have a lookup table with many subnets. I am trying to match t...
by phudinhha Explorer in Splunk Search 08-04-2016
1 4
1
4
janderson19
Hello, I'm working on a search for blackboard that will return users who have failed to log in more than 3 times in ...
by janderson19 Path Finder in Splunk Search 08-04-2016
0 4
0
4
jph11
Currently working on an integration betweek Splunk and RSA Archer eGRC. We are working with the security operations m...
by jph11 New Member in Splunk Search 08-04-2016
0 1
0
1
iatwal
how do I change the colors of my bar chart to red, yellow, and green? Here is my query: index=xyxy env=PROD profile...
by iatwal Path Finder in Splunk Search 08-04-2016
0 1
0
1
dbcase
Hi, I have a table with 3 fields in it MSO (a name field) Trend (a Sparkline) Percentage (numeric) When a user cli...
by dbcase Motivator in Splunk Search 08-04-2016
0 2
0
2
ashishlal82
index=bigfix sourcetype=software | eval Hashes_allow_or_deny = if((sha256_allow_or_deny=="*deny*") OR (md5_allow_or_d...
by ashishlal82 Explorer in Splunk Search 08-04-2016
0 4
0
4
sjoerdcopier
I'm trying to use data from a search in a custom command. source | scrapy url=uri This gives me the following erro...
by sjoerdcopier Explorer in Splunk Search 08-04-2016
1 4
1
4
asarran
Hey Fellow Splunkers I have an issue when searching for similar events that are only unique by one character. Exam...
by asarran Path Finder in Splunk Search 08-04-2016
0 3
0
3
tungntran
Hello, I'm trying to change a value of a field using eval case then do a stats count based on that field. I'm getti...
by tungntran Explorer in Splunk Search 08-04-2016
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...