Splunk Search

Splunk Search
Community Activity
SirHill17
Hi, I would like to anonymize data (data is file system path) using REGEX. I succesfully managed to hide data like I...
by SirHill17 Communicator in Splunk Search 02-29-2016
0 17
0
17
Sr59
Hi! I'm indexing XML data containing free memory values and get a nice stats table, but not be able to show that as ...
by Sr59 Explorer in Splunk Search 02-29-2016
1 12
1
12
koshyk
hi We have a situation whereby we have to run an app (a script within an app) individually on each Servers of Search ...
by koshyk Super Champion in Splunk Search 02-29-2016
0 5
0
5
alisterwhipp
I have a user group that I'm trying to assign access to a specific subnet of firewall traffic. Their network travers...
by alisterwhipp Path Finder in Splunk Search 02-29-2016
0 2
0
2
saurabhkunte
HI All , I hope someone can help me out with a problem I currently see in a query. I have a Splunk DB Connect quer...
by saurabhkunte Path Finder in Splunk Search 02-29-2016
0 1
0
1
MB2016
I'd like to place a solid border around a chart panel in XML - I'm struggling to comprehend how this is done within X...
by MB2016 New Member in Splunk Search 02-29-2016
0 3
0
3
abhayneilam
Hi, I have a lookup table in which I have area code and longtitue and latitude and other details, at the other end ...
by abhayneilam Contributor in Splunk Search 02-28-2016
0 2
0
2
danielphome
I've been looking at sizing a Splunk instance based on https://splunk-sizing.appspot.com/#v=10 and it mentions hot, c...
by danielphome Engager in Splunk Search 02-28-2016
0 3
0
3
daniel333
Is there a better way to do an OR in Splunk? Example: api_domain="purchase" OR api_domain="user" OR api_domain="tes...
by daniel333 Builder in Splunk Search 02-28-2016
0 2
0
2
gsrikanth87
I am getting below output when i am searching in syslog. I want to filter only Error Log messages given below. searc...
by gsrikanth87 Path Finder in Splunk Search 02-28-2016
0 4
0
4
jwalzerpitt
Having an issue searching Cisco ISE logs in Hunk where values I know exist in the events/logs (independently verified...
by jwalzerpitt Influencer in Splunk Search 02-27-2016
0 3
0
3
gdavid
Is there any easy way for an alert to trigger another search? my use case is for an account lockout to trigger a se...
by gdavid Path Finder in Splunk Search 02-27-2016
0 4
0
4
thunder_wu
In stats, I want something equal to (latest - earliest) / earliest for certain field. How I can achieve that?
by thunder_wu Path Finder in Splunk Search 02-27-2016
0 2
0
2
avisram
Hi There, I have 158 events with three fields - latitude, longitude, and an integer value representing the total num...
by avisram Path Finder in Splunk Search 02-26-2016
0 2
0
2
babcolee
I have the following REGEX to pickup the bytes out, ^(?:[^,\n]*,){31}(?P\d+). I need to know the REGEX to filter out ...
by babcolee Path Finder in Splunk Search 02-26-2016
0 5
0
5
j8lp
I'm writing a custom search command to convert all the full path xml names to just local names. I'm also making the f...
by j8lp Explorer in Splunk Search 02-26-2016
0 1
0
1
calebking3
Hi Folks, I am attempting to look at some Splunk logs and within the JSON, I only care about 3 fields: cmd, vax, opc...
by calebking3 New Member in Splunk Search 02-26-2016
0 1
0
1
moe44688
Hi guys, I am monitoring suspicious user activity using the transaction command. For example, if EventCodes X, Y, an...
by moe44688 New Member in Splunk Search 02-26-2016
0 2
0
2
P_A_WORKS
Hi, After I run a SearchManager in dashboard, the number of result events I see is 165, however, when I use the foll...
by P_A_WORKS New Member in Splunk Search 02-26-2016
0 6
0
6
ceng
Hi, How can I create this kind of table? MissingA : 0 MissingB : 100 MissingC : 200 I'd...
by ceng New Member in Splunk Search 02-26-2016
0 4
0
4
sistemistiposta
Hello, I have this raw line: 2016-02-25T15:48:09.762479+01:00 03ucas amavis[1369]: (01369-16) run_av (ClamAV-clamd-...
by sistemistiposta Path Finder in Splunk Search 02-26-2016
1 3
1
3
dsollen
Assuming I'm not completely incorrect, I don't believe there is a way to store a field as a boolean value. There are...
by dsollen Explorer in Splunk Search 02-26-2016
1 4
1
4
floppymoose
I'm using Splunk Enterprise. I have a search that looks like: index=foo sourcetype=yapache_access host=bar | field...
by floppymoose Engager in Splunk Search 02-26-2016
0 4
0
4
fmpa_isaac
Can anyone help me get the count for Top 5 plus an Others count for the following please? Thank you sourcetype="cisc...
by fmpa_isaac Path Finder in Splunk Search 02-26-2016
0 3
0
3
johnraftery
Hi, I'm using a time picker which gives you a start and end token as time modifiers (eg "-2d@d - now" for the last tw...
by johnraftery Communicator in Splunk Search 02-26-2016
0 4
0
4
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...