Splunk Search

Splunk Search
Community Activity
tankhanandita
The Splunk documentation says that we use pipe character when we need to club two or more commands, but in some cases...
by tankhanandita Explorer in Splunk Search 06-22-2016
0 4
0
4
clarksinthehill
I have a set of data that I would like to exclude the second search result set from. First search: Gets me all the e...
by clarksinthehill Explorer in Splunk Search 06-22-2016
0 2
0
2
splunker1981
Hello all, Trying to figure out how to search or filter based on the matches in my case statement. I guess also wan...
by splunker1981 Path Finder in Splunk Search 06-22-2016
0 7
0
7
bspier1
In one event, I see that a search results with this following line: "SERIES". That line tells me that the user select...
by bspier1 New Member in Splunk Search 06-22-2016
0 4
0
4
splunkrocks2014
Hi. How do I filter my results from an extracted field and where-clause? I have a user lookup table which contain...
by splunkrocks2014 Communicator in Splunk Search 06-22-2016
0 6
0
6
JSkier
I'd like to sanitize host names during search time in Splunk (IDS alerts), so users don't receive a hyperlink to the ...
by JSkier Communicator in Splunk Search 06-22-2016
0 4
0
4
alan20854
Hi, I am creating a dashboard with 2 drop-downs, one for Services and the other for Methods, and I want the search ...
by alan20854 Path Finder in Splunk Search 06-22-2016
0 4
0
4
KSKandala
Hi, Currently I am consolidating data from different indexes. index=application1 ID=$id$ | rename application1_id ...
by KSKandala New Member in Splunk Search 06-22-2016
0 1
0
1
chvnc
I want to make a new field with extracted values like Header.txt, LogMessage.xml , JSON_HEADER.json (it's from the se...
by chvnc Explorer in Splunk Search 06-22-2016
0 1
0
1
voninski
Not sure how to accomplish this and need some advice from the experts here. I am working with data from a torque too...
by voninski New Member in Splunk Search 06-22-2016
0 4
0
4
DF10569
Search I am trying to use: index="wineventlog" (EventCode=4656 Accesses=DELETE) OR EventCode=1102 OR EventCode=4670...
by DF10569 New Member in Splunk Search 06-22-2016
0 2
0
2
kiran331
Hi How can I extract the "TCP_MISS/200" and "TCP_MISS_SSL/200" or similar from the event below? 1466609862.644 109...
by kiran331 Builder in Splunk Search 06-22-2016
0 1
0
1
zeophlite
I have a field in my events that is a string (but does not translate to a number directly) Is there a way to convert...
by zeophlite New Member in Splunk Search 06-22-2016
0 4
0
4
szabados
I created a datamodel from a source, which had spaces in the field names, but field were automatically created with t...
by szabados Communicator in Splunk Search 06-22-2016
3 2
3
2
daniel_augustyn
I am not sure how to fix the date extraction from a raw log which is done by default by Splunk. Splunk extracts date ...
by daniel_augustyn Contributor in Splunk Search 06-21-2016
0 4
0
4
sanchitguptaiit
I have a requirement where I need to search all logs to match a set of patterns and extract some values. Is there som...
by sanchitguptaiit Explorer in Splunk Search 06-21-2016
0 1
0
1
goodsellt
My problem stems from how the last value functions, where it pulls the last value from the previous event. While I wa...
by goodsellt Contributor in Splunk Search 06-21-2016
0 1
0
1
haziqwebs
I want to rename CPU001 to CPU1, CPU_ALL to CPUALL, is it possible?
by haziqwebs New Member in Splunk Search 06-21-2016
0 3
0
3
prakash007
Need help with regex...should start with " end with space or ? Need entire string in a field starting with " and end...
by prakash007 Builder in Splunk Search 06-21-2016
0 3
0
3
fredclown
I know that I ca get the event time using "_time". Does Splunk keep track of the time the event was loaded into Splun...
by fredclown Builder in Splunk Search 06-21-2016
1 6
1
6
bgdatasar
How do I fix this Regex syntax error in subpattern name missing terminator? Error in 'rex' command: Encountered the ...
by bgdatasar New Member in Splunk Search 06-21-2016
0 1
0
1
bsellapi
Hi I am getting below error when I use the metadata command. Could someone explain to me in detail what this is all ...
by bsellapi New Member in Splunk Search 06-21-2016
0 5
0
5
annalisefolsen
I have an app for a custom command called disabler and I am trying to call the command by: ... | disabler | ... Bu...
by annalisefolsen Explorer in Splunk Search 06-21-2016
0 1
0
1
benjaminw
My curl searches result in the output Unparsable URI-encoded request data I see that many of the curl searches on...
by benjaminw New Member in Splunk Search 06-21-2016
0 3
0
3
i111040d
For example: |stats count by src_ip src_ip count 1.1.1.1 100 2.2.2.2 200 3.3.3.3 300 |stats count by dst_ip dst...
by i111040d New Member in Splunk Search 06-21-2016
0 2
0
2
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors