Splunk Search

Splunk Search
Community Activity
kranthi851
Hi all, How to extract the fields UDP_PORT and TCP_PORT from this result? FIXED_SEVERITY_3=10, FIXED_SEVERITY_2=14...
by kranthi851 New Member in Splunk Search 06-06-2016
0 2
0
2
packet_hunter
Scenario: Ultimately, I would like to create an alert for an event in index A. Then I would like the alert to kicko...
by packet_hunter Contributor in Splunk Search 06-06-2016
0 26
0
26
hokieb
**Problem #1** ** I am struggling to avoid the 10k limit on subsearches within Splunk. I have two data sources and...
by hokieb New Member in Splunk Search 06-06-2016
0 5
0
5
jbsplunk
I have access to Splunk.com without issue. However when I try to install any app such as SoS and Sideview Utils, fr...
by jbsplunk Splunk Employee Splunk Employee in Splunk Search 06-06-2016
6 3
6
3
kiran331
Hi all, From a scan report of Qualys, I will get IP and its PORT, TCP_PORT, UDP_PORT. Now when the scan is done afte...
by kiran331 Builder in Splunk Search 06-06-2016
0 3
0
3
thilleso
Hi, Do someone have experience using the Splunk Add-on for Azure app, and retrieving Azure Table storage data? Th...
by thilleso Path Finder in Splunk Search 06-06-2016
0 3
0
3
krasay
Here is the regex that I have: ^\(\d+\)\s+\d+/\d+/\d+\s+\d+:\d+:\d+\s+\w+\s+\-\s+\(\w+\s+\w+\s+\w+\)\s+\(\d+\.\d+\.\...
by krasay New Member in Splunk Search 06-06-2016
0 2
0
2
aaron_harris
When running a search in splunk such as 'index=syslog date_hour=12' we get the below error to do with memory configur...
by aaron_harris Engager in Splunk Search 06-06-2016
0 2
0
2
harry_hodge
I have tried multiple time ranges. no luck. Cisco app shows data coming in. License section of Splunk Utilization Mon...
by harry_hodge Explorer in Splunk Search 06-06-2016
0 4
0
4
phoenixdigital
OK one of our devs discovered a weird bug where if a lookup is being performed on a CSV where the field to match cont...
by phoenixdigital Builder in Splunk Search 06-05-2016
0 6
0
6
prakash007
Can anyone explain the time commands in Splunk with a use case? I see few of these searches in Splunk Answers, but I ...
by prakash007 Builder in Splunk Search 06-05-2016
0 1
0
1
maximus_reborn
I am getting the below error while running Splunk integration spring adapter. org.xml.sax.SAXParseException; lineNum...
by maximus_reborn Path Finder in Splunk Search 06-05-2016
0 2
0
2
splaccount123
Hi! Is it possible to create a correlation of fields over several different events? For example, I have to find all...
by splaccount123 New Member in Splunk Search 06-05-2016
0 5
0
5
farismitri
To put it as simply as possible: Imagine 8 log entries with only two fields per log, t = time & ID = Identifier Lo...
by farismitri Explorer in Splunk Search 06-04-2016
0 7
0
7
satishsdange
Has anyone faced this problem - root@ip-172-31-19-68:/home/ubuntu# tail /opt/splunkforwarder/var/log/splunk/streamfw...
by satishsdange Builder in Splunk Search 06-04-2016
0 1
0
1
packet_hunter
Scenario: I need to extract the User out of the following field msg using rex. So, I need abcdefg Group <XGroupPoli...
by packet_hunter Contributor in Splunk Search 06-03-2016
0 12
0
12
jkalra
I have the following search and takes a lot of time to output data. Is there a way to optimize the search? eventtype...
by jkalra Explorer in Splunk Search 06-03-2016
0 8
0
8
diliptmonson
Hi , I am trying to update a multivalued field in a KV store. So let's say there are 3 values in the field: A,B,A. ...
by diliptmonson Explorer in Splunk Search 06-03-2016
0 2
0
2
tinhuty
I am using appendcols to put two timecharts in one graph to show the correlation, however, the values are off in diff...
by tinhuty Engager in Splunk Search 06-03-2016
0 11
0
11
MidGe
This morning after rebooting my computer with splunk on it, Splunk refuses to start. Trying to investigate the probl...
by MidGe Explorer in Splunk Search 06-03-2016
1 15
1
15
jcouture
For Example: Suppose you have 3 numbers from search results: 1,000 2,000 and 3,000. I want to be able to display...
by jcouture Explorer in Splunk Search 06-03-2016
0 6
0
6
DanielFordWA
I have the following search index=iis | eval WebShellActive=if(match($Webshell$,"true"),"Yes",WebShellActive) | eva...
by DanielFordWA Contributor in Splunk Search 06-03-2016
0 2
0
2
faabiojr
I am running a querie to calculate the upperperc95 and avg for the number of conections in my firewalls, but some tim...
by faabiojr New Member in Splunk Search 06-03-2016
0 2
0
2
Madhan45
The event had indexed at 10:00 AM, but when I search for the same data at 10:15, I just got "No results found". Howev...
by Madhan45 Path Finder in Splunk Search 06-03-2016
0 1
0
1
undercoverbroth
Hello I want to Display the CPU used from a Server depending on the users are working on that Server for several Serv...
by undercoverbroth New Member in Splunk Search 06-03-2016
0 7
0
7
Get Updates on the Splunk Community!

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...