Splunk Search

Splunk Search
Community Activity
dstaulcu
It appears that the where clause is sensitive to the case of field values when invoked as part of an inputlookup comm...
by dstaulcu Builder in Splunk Search 07-09-2016
0 2
0
2
mjones414
sourcetype=pbs:rg OR (sourcetype=pbs:status state!=free AND state!=job-* tag=sasl0002) | foreach resources_available...
by mjones414 Contributor in Splunk Search 07-09-2016
1 1
1
1
mprreddy51
Hi All, Here is my requirement: I have 100 values (abc1,def1,....etc) in lookup1 and 100 values in lookup2 (ABC1,DE...
by mprreddy51 Explorer in Splunk Search 07-08-2016
0 8
0
8
brianlee12
Hi guys, So I have an input field where the user inputs text in the format %y%m%d%H%M, for example 1607061700, whic...
by brianlee12 Engager in Splunk Search 07-08-2016
0 16
0
16
JoshuaJohn
Hi I'm new to the community and to Splunk. I am trying to combine the 4 columns my search creates into one total co...
by JoshuaJohn Contributor in Splunk Search 07-08-2016
0 5
0
5
Hazel
Hello, I am trying to use the external_lookup.py feature to pass in IP addresses and return the hostname. I tried c...
by Hazel Communicator in Splunk Search 07-08-2016
3 9
3
9
pdumblet
I have the following results from my search. I am trying to extract the Application Name from the raw log using the f...
by pdumblet Explorer in Splunk Search 07-08-2016
0 2
0
2
mjones414
Sample data: I have several field values in one sourcetype that are variable limits that can change week by week. Th...
by mjones414 Contributor in Splunk Search 07-08-2016
0 5
0
5
adamblock2
The following search returns results when I run it as a search, but not when it is used as a dashboard panel. The das...
by adamblock2 Path Finder in Splunk Search 07-08-2016
0 1
0
1
adamblock2
I am interested in identifying when a field contains 2 specific field values appear within 5 minutes of each other. ...
by adamblock2 Path Finder in Splunk Search 07-08-2016
0 5
0
5
moaf13
I have multiple CSV lookup files and I want to use a variable to determine which lookup table to choose in my search....
by moaf13 Path Finder in Splunk Search 07-08-2016
0 2
0
2
Sravan_C
Hi All, I am writing various Splunk searches to get result set from iis logs. For each search, I have different wher...
by Sravan_C New Member in Splunk Search 07-08-2016
0 9
0
9
PRIYANKA_1993
I'm fetching the data from a CSV file, but the issue with my data is that some of the values are in PDT and some are ...
by PRIYANKA_1993 New Member in Splunk Search 07-08-2016
0 7
0
7
yzimmer
Hi everybody! In a Splunk Dashboard, I created a Bar Panel with this: * | stats count(U*) as U* | transpose | renam...
by yzimmer New Member in Splunk Search 07-08-2016
0 4
0
4
Urias
Hello! I've been told to use stats values() instead of transaction for performance issues. However, with long log fi...
by Urias Engager in Splunk Search 07-08-2016
0 6
0
6
rashid47010
HI everyone, I am trying to figure out about Unauthorised Vulnerability Scan - External.. we detected an external ho...
by rashid47010 Communicator in Splunk Search 07-08-2016
0 8
0
8
tdewitt_atl_rea
I have 2 logs: an error log and a success log. When an item fails (error log), it is retried. I would like to filter ...
by tdewitt_atl_rea New Member in Splunk Search 07-07-2016
0 4
0
4
khubyarb
I am trying to validate whether data from two separate sources is the same. I have indexed two csv files of 450,000+ ...
by khubyarb Path Finder in Splunk Search 07-07-2016
0 3
0
3
raby1996
Null
by raby1996 Path Finder in Splunk Search 07-07-2016
0 10
0
10
zsizemore
Hi, I have a query showing the amount of distinct logins by IP address based on the "term" i've created in the query...
by zsizemore Path Finder in Splunk Search 07-07-2016
0 5
0
5
iKate
Hi! Is it possible to pass into lookup's name created by outputlookup command a token or a search value? Smth like ...
by iKate Builder in Splunk Search 07-07-2016
1 2
1
2
jtuni
I have log data that doesn't always contain a user ID, but I would like to fill the user ID field with the last known...
by jtuni Engager in Splunk Search 07-07-2016
0 4
0
4
daniel333
alt text I want an alert if an application pool drops more than 99% of logging. (We have an issue where before a JVM ...
by daniel333 Builder in Splunk Search 07-07-2016
0 2
0
2
mgrimes
So I've posted a question a week ago regarding finding the max EPS for a timespan of a day. The query that I am using...
by mgrimes New Member in Splunk Search 07-07-2016
0 8
0
8
arrowecssupport
So I've got 2 different values I'm trying to use; letters & numbers. I want to be able to say If letters = a b or c...
by arrowecssupport Communicator in Splunk Search 07-07-2016
0 1
0
1
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...