Splunk Search

Splunk Search
Community Activity
MayraEllen
Desired Outcome: Shows only the top 5% of people who have spent more than 10000 Table Output - Just the User ID and t...
by MayraEllen New Member in Splunk Search 07-14-2016
0 2
0
2
halr9000
Banging my head on this one for too long, could use some help. Take a sample doc such as the below, where you have a...
by halr9000 Motivator in Splunk Search 07-14-2016
2 11
2
11
tmontney
I have a subsearch that I only want to look for the last 15 minutes. All I find are examples of days. Can someone giv...
by tmontney Builder in Splunk Search 07-14-2016
0 8
0
8
Stevelim
Not exactly sure how to phrase this, but how can I remodel my data input via Splunk? For example, my raw data looks...
by Stevelim Communicator in Splunk Search 07-14-2016
0 2
0
2
mcgi906
I have been beating my head against a wall trying to figure this out and have not been having much luck, Ive tried ev...
by mcgi906 Explorer in Splunk Search 07-14-2016
0 8
0
8
sarahalhawi
Hello, I am having some issues with using multiple field exclusions as not all results are being returned (only the ...
by sarahalhawi Explorer in Splunk Search 07-14-2016
0 16
0
16
sathishsathiyam
Below is my applogs data: {"name":"blink-api-manager","submodule":"perfLogger","level":30,"req":{"url":"/api/account...
by sathishsathiyam New Member in Splunk Search 07-13-2016
0 5
0
5
arulbalans
Splunk Query: 2016-06-12 00:48:29,834 INFO [MainThread][PID:3143] item: AR001SJFBS valid_audio_path: /PROXY_AUDIO/2...
by arulbalans Engager in Splunk Search 07-13-2016
0 2
0
2
ZacEsa
Hi all, I'm trying to create a guide for my colleagues regarding the raw logs on Splunk, but I'm stuck as I'm not su...
by ZacEsa Communicator in Splunk Search 07-13-2016
0 7
0
7
Dark_Ichigo
Is it possible to create a dotted Line Chart in splunk using Advanced XML?
by Dark_Ichigo Builder in Splunk Search 07-13-2016
2 7
2
7
mcgi906
index=a | eval SPLITid=[search index=b | eval tempid= substr(SPLITLOTID,2,8) | return $tempid ] | table SPLITid Whe...
by mcgi906 Explorer in Splunk Search 07-13-2016
0 2
0
2
chillsgrove
I want to create an alert that triggers when a src_ip OR dest_ip exists in a lookup table (e.g. threat_ip_list.csv). ...
by chillsgrove Explorer in Splunk Search 07-13-2016
0 3
0
3
amandaxtru
<title>Routers</title> | dbquery "routerdb" "SELECT DEVICE_LOC FROM routerdb.LKP_LOCATION_EDITED WHERE METRO_CITY L...
by amandaxtru Engager in Splunk Search 07-13-2016
0 1
0
1
p_gurav
Hi All, I have the following JVM logs: May 8, 2016 1:26:26 AM IST Warning Socket BEA-000449 Closing socket as no da...
by p_gurav Champion in Splunk Search 07-13-2016
4 3
4
3
babcolee
After upgrading to 6.4.1 I am seeing a message that says "A new major or minor version is available for upgrade" and ...
by babcolee Path Finder in Splunk Search 07-13-2016
0 5
0
5
sreynolds30
On event actions under show source my users are getting the following error: Streamed search execute failed because:...
by sreynolds30 Explorer in Splunk Search 07-13-2016
0 3
0
3
chadman
I'm trying to create a new field for some null values. I tried this, but it still shows the null value. eval Reboot...
by chadman Path Finder in Splunk Search 07-13-2016
0 16
0
16
brent_weaver
Hello. I am on my Enterprise Security Search head and this is the output from the subject command (Minus the Checking...
by brent_weaver Builder in Splunk Search 07-13-2016
0 1
0
1
tkwaller
Hello I have a field extraction to extract email address from a wso2 log and rename it as user. So this log: 2016...
by tkwaller Builder in Splunk Search 07-13-2016
0 16
0
16
Makinde
Hello, I have this search string to identify hosts that have stopped sending logs to Splunk, however the search stri...
by Makinde New Member in Splunk Search 07-13-2016
0 5
0
5
Makinde
I have vulnerability detection in Splunk where there is the possibility of duplicate QID, IP and PORT, so I run a sea...
by Makinde New Member in Splunk Search 07-13-2016
0 3
0
3
michael_sleep
Hey there, I've been learning how to use the search features in Splunk and trying to find a way to get some user-age...
by michael_sleep Communicator in Splunk Search 07-13-2016
0 7
0
7
akashjohn
Hi Team, I am looking for a Splunk search to get a statistics table output I am looking for is the SSH user account...
by akashjohn Explorer in Splunk Search 07-13-2016
0 4
0
4
Shark2112
Hey guys. I have events like this "ip delay|" every second: 10.161.30.19 0.290|10.2.10.151 0.793|10.2.10.152 0.596|1...
by Shark2112 Communicator in Splunk Search 07-13-2016
0 11
0
11
splunkids75
Hi everybody! My database has to many properties, but important properties to set in my Dashboard starting with "U" ...
by splunkids75 New Member in Splunk Search 07-13-2016
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...