Splunk Search

Splunk Search
Community Activity
sat94541
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by sat94541 Communicator in Splunk Search 02-09-2016
2 5
2
5
splunker9999
Hi, I have events with the below format: "phone":{"areaCode":"732","prefix":"986","lineNumber":"0245", Is there a...
by splunker9999 Path Finder in Splunk Search 02-09-2016
0 4
0
4
maclun
Hi, There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other eve...
by maclun New Member in Splunk Search 02-09-2016
0 1
0
1
chaseto
Hello Experts, I have 2 different sources source 1 has hostname, ip address source 2 has hostname, os, os version...
by chaseto Explorer in Splunk Search 02-09-2016
0 8
0
8
zabarai
Hi, I'm pretty new to spluk, I'm looking for some help with malware detection. What would the search expression l...
by zabarai Engager in Splunk Search 02-09-2016
2 1
2
1
mattholt
We need to find the most talkative indexers within Splunk for the last 24 hour period.
by mattholt New Member in Splunk Search 02-09-2016
0 1
0
1
lyndac
I am indexing JSON data. I need to be able to do stats based "by patches" and "by admin". I can't get spath or mv...
by lyndac Contributor in Splunk Search 02-09-2016
2 3
2
3
diliptmonson
Hi All, I am trying to link 2 indexes using join. I have tried the following code: index=index1| join Id[index=in...
by diliptmonson Explorer in Splunk Search 02-09-2016
0 3
0
3
jambajuice
I need to create an outputlookup file with more than 10,000 results. I've looked through the limits.conf examples an...
by jambajuice Communicator in Splunk Search 02-09-2016
3 5
3
5
SylviaB
Persistent queues are not available for splunktcp, I use several Forwarders on networks n, sending to a central forw...
by SylviaB New Member in Splunk Search 02-09-2016
0 2
0
2
taraksinha
Hi Guys, What is the difference between user and author fields along with the fields below as well? title, author, ...
by taraksinha New Member in Splunk Search 02-09-2016
0 1
0
1
anasar
Hi I have the below json file in Splunk. How do I extract based on api calls? Eg. apiname count20...
by anasar New Member in Splunk Search 02-09-2016
0 3
0
3
ststephe
I don't know if this has been answered in another question, but I'm trying to run a report for external IPs that have...
by ststephe Engager in Splunk Search 02-09-2016
0 6
0
6
Hindoo
Hello I enter in the search: index =main | timechart count by sourcetype And I "save as" a dashboard panel ... ...
by Hindoo Path Finder in Splunk Search 02-09-2016
1 11
1
11
vesug
I have a couple logins (user) and the ip addresses (c_ip) in a lookup table. As a true test to make a search to compa...
by vesug New Member in Splunk Search 02-09-2016
0 2
0
2
prakash007
I'm trying to calculate Total count and avg(count) of users on a specific file... I don't think it's the right way t...
by prakash007 Builder in Splunk Search 02-08-2016
0 5
0
5
ianformanek
When I issue 'splunk status' on Linux, the exit code is 0 even when splunk is not running. This makes it hard to use ...
by ianformanek Explorer in Splunk Search 02-08-2016
2 9
2
9
bowesmana
I have a log that records a transaction name, channel, and timing information, and need to calculate the maximum rate...
by SplunkTrust SplunkTrust in Splunk Search 02-08-2016
0 4
0
4
rgonzale6
We use inputlookup to run large numbers (thousands) of indicators against network traffic in our org. This has worke...
by rgonzale6 Path Finder in Splunk Search 02-08-2016
0 1
0
1
gregory_geller
I have defined a transaction based on a JobID and I want to list the last N transactions. How can I do this?? source...
by gregory_geller Engager in Splunk Search 02-08-2016
0 3
0
3
proletariat99
I run a scheduled search over 100 days that baselines some user behavior and then saves the results off to a lookup.c...
by proletariat99 Communicator in Splunk Search 02-08-2016
0 1
0
1
splunker9999
Hi, We have below search which would give us server uptime. We need to select ALL TIME or last time server recorder ...
by splunker9999 Path Finder in Splunk Search 02-08-2016
0 6
0
6
belesni
Hi! I need to extract part of a uri and store this string in a field to run statistics on it. http://www.something....
by belesni New Member in Splunk Search 02-08-2016
0 2
0
2
preotesoiu
Hello, In December 2015, Splunk issued a minor upgrade (6.3.2) which is fixing bugs. Currently we have Splunk 6.3.1 ...
by preotesoiu Path Finder in Splunk Search 02-08-2016
0 8
0
8
clarksinthehill
I'm sure this may have been asked before. When using transaction, I would like to format the duration into H:M:S, my ...
by clarksinthehill Explorer in Splunk Search 02-08-2016
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...