Splunk Search

Splunk Search
Community Activity
diliptmonson
I have 2 indexes: First index: index= abc with field1 having values like "\A,\B,\C" and "\A,\D" and so on Second ind...
by diliptmonson Explorer in Splunk Search 02-19-2016
0 3
0
3
jgc94131
I'm letting timechart choose the proper bucket size, but I want that size to be displayed somewhere. I'd like to be ...
by jgc94131 Explorer in Splunk Search 02-19-2016
0 1
0
1
darlas
Hi. I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns. When...
by darlas Communicator in Splunk Search 02-19-2016
0 3
0
3
timgirgis
I have a CSV import that has a date field in the format dd/mm/yyyy that I want to be able to chart chronologically on...
by timgirgis Explorer in Splunk Search 02-19-2016
0 4
0
4
kalianov
Hi I want to drop all Windows Security Events (4624, 4625, etc) with Logon Type:3 My first idea is to make filter o...
by kalianov Path Finder in Splunk Search 02-19-2016
0 1
0
1
jedatt01
I have a data source that is pipe delimited, but some of the fields contain no data or even a blank space. I've creat...
by jedatt01 Builder in Splunk Search 02-19-2016
0 4
0
4
aportela
At the indexer, we are trying to exclude event records from incoming windows logs that have Logon_Type=3. Below is...
by aportela New Member in Splunk Search 02-19-2016
0 4
0
4
IRHM73
Hi, I wonder whether someone may be able to help me please for which may seem a really dumb question. I'm using the ...
by IRHM73 Motivator in Splunk Search 02-19-2016
0 6
0
6
ma_anand1984
I have a url, by hitting which, i get some data. Is it possible in splunk to read that data and process it and displa...
by ma_anand1984 Contributor in Splunk Search 02-18-2016
0 2
0
2
rfiscus
This is my search: index="test" sourcetype="Cisco_Users" | rex field=_raw "(?<Host>\w+-\w+-\w+-\w+-?\d?\.\w+\.\w+)\...
by rfiscus Path Finder in Splunk Search 02-18-2016
0 1
0
1
JJ_of_c9
I have managed to get our linux hosts' lastlog data in our Splunk> (version 5.0.2, build 149561) easily enough, but w...
by JJ_of_c9 Engager in Splunk Search 02-18-2016
1 4
1
4
att35
Hi, We have few appliances spread across various data centers feeding logs into Splunk. Each Data center has 2 or mo...
by att35 Builder in Splunk Search 02-18-2016
0 3
0
3
dbcase
I have a json object (see below). I need to take the value of payload.chan (15 in this case) and using 15 select pay...
by dbcase Motivator in Splunk Search 02-18-2016
0 5
0
5
packet_hunter
Scenario: I am extracting sender domains with the following code: index=mail sourcetype=xemail [search index=m...
by packet_hunter Contributor in Splunk Search 02-18-2016
0 1
0
1
diliptmonson
Hi, I need to search for an element A present in one of the fields let's say field 1. Some of the values present fo...
by diliptmonson Explorer in Splunk Search 02-18-2016
0 2
0
2
splunker9999
Hi, Can someone please advise, how we can set different colors in a dashboard for each single row? Our data looks ...
by splunker9999 Path Finder in Splunk Search 02-18-2016
0 3
0
3
johnraftery
We have certain source types where there is only data from months ago. When putting this into a timechart, the chart ...
by johnraftery Communicator in Splunk Search 02-18-2016
0 4
0
4
timgirgis
I want to create a stacked bar graph showing 2 columns stacked by department: 1 column is the total time and the seco...
by timgirgis Explorer in Splunk Search 02-18-2016
1 2
1
2
andrei1bc
My search : index=test | where Value>=95 | stats count(Value) as Events by Host The result : if there are ...
by andrei1bc Communicator in Splunk Search 02-18-2016
0 4
0
4
nikkkc
In my search, I calculate some values, but if I reach the 10000 result limit, I get wrong results. I would like chang...
by nikkkc Path Finder in Splunk Search 02-18-2016
0 6
0
6
dwin02
Hi Splunk Support, I'm trying to create a table based on certain fields from the Output Results: Search String: ...
by dwin02 Explorer in Splunk Search 02-17-2016
0 13
0
13
nickleli
Hi Everyone, Our setup is a universal forwarder --> heavy forwarder --> indexer. I am looking to modify a universal...
by nickleli New Member in Splunk Search 02-17-2016
0 5
0
5
MichaelCohen829
Hello, Could someone please delineate the difference between these two earliest commands: earliest=-2d earliest=-2...
by MichaelCohen829 Explorer in Splunk Search 02-17-2016
0 8
0
8
athorat
Want to extract only /ubi-v2/api/scoresummary from the below mentioned event in a field. Rex used: `| rex "(?<remo...
by athorat Communicator in Splunk Search 02-17-2016
0 1
0
1
angelo_fazzina
This is my search so far. sourcetype="spam" |eventstats count as total|search block_code="*" |eventstats count as b...
by angelo_fazzina Engager in Splunk Search 02-17-2016
0 6
0
6
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors