Splunk Search

Splunk Search
Community Activity
daniel333
Is there a better way to do an OR in Splunk? Example: api_domain="purchase" OR api_domain="user" OR api_domain="tes...
by daniel333 Builder in Splunk Search 02-28-2016
0 2
0
2
gsrikanth87
I am getting below output when i am searching in syslog. I want to filter only Error Log messages given below. searc...
by gsrikanth87 Path Finder in Splunk Search 02-28-2016
0 4
0
4
jwalzerpitt
Having an issue searching Cisco ISE logs in Hunk where values I know exist in the events/logs (independently verified...
by jwalzerpitt Influencer in Splunk Search 02-27-2016
0 3
0
3
gdavid
Is there any easy way for an alert to trigger another search? my use case is for an account lockout to trigger a se...
by gdavid Path Finder in Splunk Search 02-27-2016
0 4
0
4
thunder_wu
In stats, I want something equal to (latest - earliest) / earliest for certain field. How I can achieve that?
by thunder_wu Path Finder in Splunk Search 02-27-2016
0 2
0
2
avisram
Hi There, I have 158 events with three fields - latitude, longitude, and an integer value representing the total num...
by avisram Path Finder in Splunk Search 02-26-2016
0 2
0
2
babcolee
I have the following REGEX to pickup the bytes out, ^(?:[^,\n]*,){31}(?P\d+). I need to know the REGEX to filter out ...
by babcolee Path Finder in Splunk Search 02-26-2016
0 5
0
5
j8lp
I'm writing a custom search command to convert all the full path xml names to just local names. I'm also making the f...
by j8lp Explorer in Splunk Search 02-26-2016
0 1
0
1
calebking3
Hi Folks, I am attempting to look at some Splunk logs and within the JSON, I only care about 3 fields: cmd, vax, opc...
by calebking3 New Member in Splunk Search 02-26-2016
0 1
0
1
moe44688
Hi guys, I am monitoring suspicious user activity using the transaction command. For example, if EventCodes X, Y, an...
by moe44688 New Member in Splunk Search 02-26-2016
0 2
0
2
P_A_WORKS
Hi, After I run a SearchManager in dashboard, the number of result events I see is 165, however, when I use the foll...
by P_A_WORKS New Member in Splunk Search 02-26-2016
0 6
0
6
ceng
Hi, How can I create this kind of table? MissingA : 0 MissingB : 100 MissingC : 200 I'd...
by ceng New Member in Splunk Search 02-26-2016
0 4
0
4
sistemistiposta
Hello, I have this raw line: 2016-02-25T15:48:09.762479+01:00 03ucas amavis[1369]: (01369-16) run_av (ClamAV-clamd-...
by sistemistiposta Path Finder in Splunk Search 02-26-2016
1 3
1
3
dsollen
Assuming I'm not completely incorrect, I don't believe there is a way to store a field as a boolean value. There are...
by dsollen Explorer in Splunk Search 02-26-2016
1 4
1
4
floppymoose
I'm using Splunk Enterprise. I have a search that looks like: index=foo sourcetype=yapache_access host=bar | field...
by floppymoose Engager in Splunk Search 02-26-2016
0 4
0
4
fmpa_isaac
Can anyone help me get the count for Top 5 plus an Others count for the following please? Thank you sourcetype="cisc...
by fmpa_isaac Path Finder in Splunk Search 02-26-2016
0 3
0
3
johnraftery
Hi, I'm using a time picker which gives you a start and end token as time modifiers (eg "-2d@d - now" for the last tw...
by johnraftery Communicator in Splunk Search 02-26-2016
0 4
0
4
IRHM73
Hi, I wonder whether someone may be able to help me please. The search I'm using correctly extract the information I...
by IRHM73 Motivator in Splunk Search 02-26-2016
0 5
0
5
mgpspr
Hello, I'm trying to match a bearer token. How can I match the token after Bearer that is found in a log? Bearer edd...
by mgpspr New Member in Splunk Search 02-26-2016
0 3
0
3
HattrickNZ
I am trying to recreate the below graph from excel...it is created using pivot in excel and i use the option select d...
by HattrickNZ Motivator in Splunk Search 02-26-2016
0 6
0
6
nikkkc
I do not know how to change count values to a percentage value and I couldn't find an answer by searching this forum,...
by nikkkc Path Finder in Splunk Search 02-26-2016
0 4
0
4
vw5qb73
Hi - I am indexing a JMX GC log in splunk. It has following entries 29800.962: [Full GC 29800.962: [CMS29805.756: [C...
by vw5qb73 Explorer in Splunk Search 02-26-2016
0 10
0
10
changux
Hi all. I have a sourcetype with a lot of events. I want to prepare a timechart that present the total events per ho...
by changux Builder in Splunk Search 02-26-2016
0 5
0
5
thunder_wu
I have logs of following pattern, and want a time chart to track the per project field delta trend. As the change is ...
by thunder_wu Path Finder in Splunk Search 02-25-2016
1 1
1
1
johnchamp
Hi, I have a lookup file in which one of the field values is a formula. test.csv (lookup file) name,value first,cou...
by johnchamp Explorer in Splunk Search 02-25-2016
2 8
2
8
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...