Splunk Search

Splunk Search
Community Activity
almond14
I managed to create a table that somewhat looks like this: However, when I tried to append a new column with the di...
by almond14 Engager in Splunk Search 12-05-2015
0 2
0
2
the_wolverine
I have a need to accept data from multiple servers. WIll something like this work? [tcp://192.168.1.0\/24:9999] I...
by the_wolverine Champion in Splunk Search 12-05-2015
0 4
0
4
kkatzgraukeyw
I've got a query that will have a string passed into it. In this case, it's "2-Low". I need to parse out the number a...
by kkatzgraukeyw Explorer in Splunk Search 12-05-2015
0 5
0
5
rchan11
Hi, We've recently upgraded to a Splunk 6.2 indexer cluster, but we're finding that searches will hang and the syste...
by rchan11 Explorer in Splunk Search 12-05-2015
0 3
0
3
bradyguy
the following seach string basically pulls out the JSON puts it in a variable called data and then runs it through sp...
by bradyguy Engager in Splunk Search 12-04-2015
0 4
0
4
santorof
I am looking to create a unique alert that would look at virus activity. The idea is to get a real time alert in a 60...
by santorof Communicator in Splunk Search 12-04-2015
0 9
0
9
butzowj
Hi Splunkers! I am running the following search to try and apply a "low" rangemap value if a string matches "up", an...
by butzowj Path Finder in Splunk Search 12-04-2015
0 2
0
2
djmcint
Hello, I am trying to add my company Entitlement to my user ID in order to have the possibility to open Support Cas...
by djmcint Explorer in Splunk Search 12-04-2015
0 4
0
4
vinay4444
Tried using below search, but can't get result. I get null values in diff: XXX| eval indextime=strftime(_indextime,"...
by vinay4444 Explorer in Splunk Search 12-04-2015
0 5
0
5
ITSX
I've got an index full of events that have hostname, and some have macaddr. I'm trying to join it to another set of e...
by ITSX Explorer in Splunk Search 12-04-2015
0 3
0
3
nilotpaldutta
Hi, I have a search that gives me the following output: /u01/splunk/etc/apps/sampleApp/data/order-20151203120002.lo...
by nilotpaldutta Explorer in Splunk Search 12-03-2015
0 3
0
3
Shisa
tableコマンドで _timeフィールドを表示するとミリセカンドが表示されません。 ミリセカンドまで表示させるにはどうすればいいでしょうか?
by Shisa Explorer in Splunk Search 12-03-2015
0 1
0
1
harish_ka
Can someone please help me with a python script to display the values of search results. i have been trying but not a...
by harish_ka Communicator in Splunk Search 12-03-2015
0 7
0
7
s0rbeto
Hi everyone, I have these 3 searches, and they are all complicated as it looks. Any idea on how to combine them? I...
by s0rbeto Explorer in Splunk Search 12-03-2015
0 1
0
1
McJansen
Hi, I have a performance issue concerning multiple time ranges in 1 search. The search string is as follows: (index...
by McJansen Engager in Splunk Search 12-03-2015
0 3
0
3
bobbyfaber
Is there any way to 'force' delims/fields to honor a comma within quotes in a csv file? Is this a bug? Data is: > ...
by bobbyfaber Explorer in Splunk Search 12-03-2015
0 3
0
3
almond14
I have this list of events: 1. dir=up, time=60, speed=12, weight=92 2. dir=down, time=54, speed=16, weight=32 3. d...
by almond14 Engager in Splunk Search 12-03-2015
0 2
0
2
PrinceOfEval
I'm using Splunk 6.1.4, which is unable to accelerate multiple objects within a single data model. Because of this, ...
by PrinceOfEval Path Finder in Splunk Search 12-03-2015
3 5
3
5
ehaile039
Hi Splunkers, I have a CSV file that contains several different IOCs, such as domains, hashes, ip addresses, and ema...
by ehaile039 Engager in Splunk Search 12-03-2015
1 3
1
3
shariinPH
Hi Splukers, My problem here is that i have a search : index=myindexname sourcetype=mysourcetype |stats latest(fie...
by shariinPH Contributor in Splunk Search 12-03-2015
2 3
2
3
dstaulcu
I'd like to be able to enhance DB Connect results with details in a lookup table file. For some reason, the looku...
by dstaulcu Builder in Splunk Search 12-03-2015
0 4
0
4
the_wolverine
I'm using a CIDR lookup table against raw data (find a match in the entire event, any field.) It won't work, underst...
by the_wolverine Champion in Splunk Search 12-03-2015
0 3
0
3
konishi_taisuke
I'd like to copy Splunk configurations such as dashboards, searches, etc. on a Splunk server to another one. Is it p...
by konishi_taisuke New Member in Splunk Search 12-03-2015
0 2
0
2
LWilliamson1
When running the search: | eval startTime="1970-01-01"| eval dateadded_epoch = strptime(startTime, "%Y-%m-%d")| tab...
by LWilliamson1 Explorer in Splunk Search 12-03-2015
3 3
3
3
jsven7
Hi all. I'm trying to make a gauge that counts the amount of logged on users. Stuck on figuring out how to classify a...
by jsven7 Communicator in Splunk Search 12-03-2015
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...