Splunk Search

Splunk Search
Community Activity
rashid47010
I want to get all workstations/computers information from active directory and want to know how can I save it OR util...
by rashid47010 Communicator in Splunk Search 07-14-2016
0 2
0
2
wellhung
I don't need the entire tables, just the names of those processes will do so it would look like this: hosts d...
by wellhung Explorer in Splunk Search 07-14-2016
1 8
1
8
vrmandadi
Hello, I am finding it difficult to create a drilldown on bar chart which has: A B C with success and failures stac...
by vrmandadi Builder in Splunk Search 07-14-2016
0 4
0
4
daniel_augustyn
I've been trying to join two indexes: Windows Security index and a proxy one, but after running the search below, I o...
by daniel_augustyn Contributor in Splunk Search 07-14-2016
0 10
0
10
mprreddy51
Hi, why I am not able to extract date from _raw in MAP command(second part of query) Below is my query: index=abc ...
by mprreddy51 Explorer in Splunk Search 07-14-2016
0 3
0
3
jfeitosa
How to convert the search results in seconds to hours and minutes? This my search: index=pan* (type=TRAFFIC AND ven...
by jfeitosa Path Finder in Splunk Search 07-14-2016
0 3
0
3
splunker9999
Hi, Why we are not able to join my search? Can you please suggest how to edit this? index=idx* sourcetype=Uptime ho...
by splunker9999 Path Finder in Splunk Search 07-14-2016
0 3
0
3
MayraEllen
Desired Outcome: Shows only the top 5% of people who have spent more than 10000 Table Output - Just the User ID and t...
by MayraEllen New Member in Splunk Search 07-14-2016
0 2
0
2
halr9000
Banging my head on this one for too long, could use some help. Take a sample doc such as the below, where you have a...
by halr9000 Motivator in Splunk Search 07-14-2016
2 11
2
11
tmontney
I have a subsearch that I only want to look for the last 15 minutes. All I find are examples of days. Can someone giv...
by tmontney Builder in Splunk Search 07-14-2016
0 8
0
8
Stevelim
Not exactly sure how to phrase this, but how can I remodel my data input via Splunk? For example, my raw data looks...
by Stevelim Communicator in Splunk Search 07-14-2016
0 2
0
2
mcgi906
I have been beating my head against a wall trying to figure this out and have not been having much luck, Ive tried ev...
by mcgi906 Explorer in Splunk Search 07-14-2016
0 8
0
8
sarahalhawi
Hello, I am having some issues with using multiple field exclusions as not all results are being returned (only the ...
by sarahalhawi Explorer in Splunk Search 07-14-2016
0 16
0
16
sathishsathiyam
Below is my applogs data: {"name":"blink-api-manager","submodule":"perfLogger","level":30,"req":{"url":"/api/account...
by sathishsathiyam New Member in Splunk Search 07-13-2016
0 5
0
5
arulbalans
Splunk Query: 2016-06-12 00:48:29,834 INFO [MainThread][PID:3143] item: AR001SJFBS valid_audio_path: /PROXY_AUDIO/2...
by arulbalans Engager in Splunk Search 07-13-2016
0 2
0
2
ZacEsa
Hi all, I'm trying to create a guide for my colleagues regarding the raw logs on Splunk, but I'm stuck as I'm not su...
by ZacEsa Communicator in Splunk Search 07-13-2016
0 7
0
7
Dark_Ichigo
Is it possible to create a dotted Line Chart in splunk using Advanced XML?
by Dark_Ichigo Builder in Splunk Search 07-13-2016
2 7
2
7
mcgi906
index=a | eval SPLITid=[search index=b | eval tempid= substr(SPLITLOTID,2,8) | return $tempid ] | table SPLITid Whe...
by mcgi906 Explorer in Splunk Search 07-13-2016
0 2
0
2
chillsgrove
I want to create an alert that triggers when a src_ip OR dest_ip exists in a lookup table (e.g. threat_ip_list.csv). ...
by chillsgrove Explorer in Splunk Search 07-13-2016
0 3
0
3
amandaxtru
<title>Routers</title> | dbquery "routerdb" "SELECT DEVICE_LOC FROM routerdb.LKP_LOCATION_EDITED WHERE METRO_CITY L...
by amandaxtru Engager in Splunk Search 07-13-2016
0 1
0
1
p_gurav
Hi All, I have the following JVM logs: May 8, 2016 1:26:26 AM IST Warning Socket BEA-000449 Closing socket as no da...
by p_gurav Champion in Splunk Search 07-13-2016
4 3
4
3
babcolee
After upgrading to 6.4.1 I am seeing a message that says "A new major or minor version is available for upgrade" and ...
by babcolee Path Finder in Splunk Search 07-13-2016
0 5
0
5
sreynolds30
On event actions under show source my users are getting the following error: Streamed search execute failed because:...
by sreynolds30 Explorer in Splunk Search 07-13-2016
0 3
0
3
chadman
I'm trying to create a new field for some null values. I tried this, but it still shows the null value. eval Reboot...
by chadman Path Finder in Splunk Search 07-13-2016
0 16
0
16
brent_weaver
Hello. I am on my Enterprise Security Search head and this is the output from the subject command (Minus the Checking...
by brent_weaver Builder in Splunk Search 07-13-2016
0 1
0
1
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors