Splunk Search

Splunk Search
Community Activity
smudge797
Im using this search for monitoring security events: source="WinEventLog:Security" EventCode=4624 OR EventCode=4634 ...
by smudge797 Path Finder in Splunk Search 03-16-2016
0 6
0
6
deepanram211219
I am creating a search that counts the daily unique category from a proxy log. I want to show the average number of ...
by deepanram211219 New Member in Splunk Search 03-16-2016
0 3
0
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the query below to extract a piece of data. i...
by IRHM73 Motivator in Splunk Search 03-16-2016
0 3
0
3
schose
Hi forum, I'm currently fighting with an installation of a Searchhead. When a Knowledge Object is created the config...
by schose Builder in Splunk Search 03-16-2016
0 4
0
4
splunkuser1982
Hello Everyone, Need help in writing a Splunk search that can help me measure the stats correctly. Please note the ...
by splunkuser1982 New Member in Splunk Search 03-16-2016
0 1
0
1
prategup1
I have two queries which are working fine independently but I want to join those two and get the result in one go. Ca...
by prategup1 New Member in Splunk Search 03-16-2016
0 2
0
2
loyslegrand
Hello I would like to get the average of a measure depending on the day of the week (monday, tuesday,...) and this ...
by loyslegrand Path Finder in Splunk Search 03-16-2016
0 11
0
11
scottclark360
When using Splunk's dashboard editor, shared timepicker is not an available option for dynamic searches on other inpu...
by scottclark360 Engager in Splunk Search 03-16-2016
3 2
3
2
kjiwatrakan
I am trying to search from source A that contains IP and trying to lookup IP location from source B where source B co...
by kjiwatrakan Explorer in Splunk Search 03-16-2016
1 8
1
8
amoldesai
Hi, The following query below returns the output as shown below : Query: index="79390-np" sourcetype=np-cache-v2 s...
by amoldesai Explorer in Splunk Search 03-16-2016
0 4
0
4
bbhandari012
How do i use the regex pattern to get only 13348864 for memory-free ? forwarder.memory.memory-cached 367001600 1458...
by bbhandari012 Explorer in Splunk Search 03-16-2016
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. Although I've been using Splunk for a few months now, I'...
by IRHM73 Motivator in Splunk Search 03-16-2016
2 2
2
2
praveenkpatidar
Hello, I have ticket data like below ID Open_date Close_date 1 01/01/2016 02/01/2016 2 01/01/2...
by praveenkpatidar Explorer in Splunk Search 03-16-2016
0 4
0
4
ayushchoudhary
I have a server of which logs are indexed on splunk. The server is universal forwarder and sends a log file continuou...
by ayushchoudhary Path Finder in Splunk Search 03-15-2016
0 2
0
2
vrmandadi
Hello Experts, How to calculate the count of the events based on the value of a particular field example: ...
by vrmandadi Builder in Splunk Search 03-15-2016
0 6
0
6
vinay4444
Hi i have a panel whose search i am trying to control from button which sets a token to true - $memory_chart$ i have...
by vinay4444 Explorer in Splunk Search 03-15-2016
0 1
0
1
spammenot66
Hi all, I'm trying to generate counts/hits based on client ip and create a map visualization similar to the one fou...
by spammenot66 Contributor in Splunk Search 03-15-2016
1 26
1
26
szelenka
This document details how to use the REST API to perform actions on a given sid: http://docs.splunk.com/Documentation...
by szelenka New Member in Splunk Search 03-15-2016
0 1
0
1
jhayIV
Using the table below I have the following query table Server_Name,Server_TotalPhysicalMemory,Server_Cores,Server_Num...
by jhayIV Engager in Splunk Search 03-15-2016
0 1
0
1
tmarlette
I am attempting to format my DNS data to a standard format. I'm thinking I can use REGEX / SED for the this formattin...
by tmarlette Motivator in Splunk Search 03-15-2016
0 2
0
2
renanprado96
how I do it? I want to see 30 days before and 30 days after a date. If I put "03/03/2016," the system will look for 3...
by renanprado96 Path Finder in Splunk Search 03-15-2016
0 9
0
9
jshultz
We are blocking a list of different known malicious IP ranges on our checkpoint firewalls. We do receive the syslog i...
by jshultz Explorer in Splunk Search 03-15-2016
0 3
0
3
nicklbailey
First, I am completely new to Splunk and the extent of my expertise with the query language is dumb wildcard matching...
by nicklbailey New Member in Splunk Search 03-15-2016
0 1
0
1
benjillaz
Hello Splunkers I just started to use splunk and you know how it is to learn something new, you punch the keyboard l...
by benjillaz Explorer in Splunk Search 03-15-2016
0 7
0
7
ArsenyKapralov
Hi I have the following problem. I have a set of events with field called "amount1". In this field I have a number w...
by ArsenyKapralov Path Finder in Splunk Search 03-15-2016
1 1
1
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...