Splunk Search

Splunk Search
Community Activity
emottola
When comparing multivalue fields, there are a number of relationships one might be interested in.Equality is easy to ...
by emottola Explorer in Splunk Search 08-07-2023
0 2
0
2
sathiyasun
Please let me know the Splunk SaaS cloud licensing usage over time per index.
by sathiyasun Explorer in Splunk Search 08-07-2023
0 1
0
1
MGlass
How would you extract fields from this Data, I would like to extract the panel ID, watts, grid Hz, grid voltage and t...
by MGlass Explorer in Splunk Search 08-07-2023
0 3
0
3
kc_prane
 My base search  PAGE_ID=*| where PAGE_ID=DGEFH  OR  PAGE_ID =RGHJH  NOT NUM_OF_MONTHS_RUN>=6 AND NOTNUM_OF_INDIVIDUA...
by kc_prane Communicator in Splunk Search 08-07-2023
0 3
0
3
danielbb
I'm trying to run -      | tstats count where index=wineventlog* TERM(EventID=4688) by _time span=1m     It returns n...
by danielbb Motivator in Splunk Search 08-07-2023
0 6
0
6
evallja
Hello, I have a table with the following fields from an email security system that are duplicated within a time range...
by evallja Path Finder in Splunk Search 08-07-2023
0 1
0
1
fishmong3r0
Guys, I have a very simple output that looks like: weekcartotalbroken31Volvo1002031Hyundai1301031Ford2404432Volvo9815...
by fishmong3r0 Loves-to-Learn Lots in Splunk Search 08-07-2023
0 1
0
1
venky1544
Hi i have a table where i obtained the values after sorting PCT_FREE in ascending order now i want to plot a timechar...
by venky1544 Builder in Splunk Search 08-06-2023
0 4
0
4
apietersen
Hi I am struggling with an issue for days now but keep running in circles, any help is much appreciated.Below you fin...
by apietersen Contributor in Splunk Search 08-06-2023
0 6
0
6
sarit_s
Hello what is the capability so the user will be able to upload file with "add data" option ?
by sarit_s Communicator in Splunk Search 08-05-2023
0 2
0
2
Thulasinathan_M
Hi Splunk Experts, I want to search for a word and then print the current matching line & the immediate next line. Ki...
by Thulasinathan_M Contributor in Splunk Search 08-05-2023
0 19
0
19
Niro
Hello, I'm trying to figure out the best way to report/alert on active directory change events. I have admon/event fo...
by Niro Explorer in Splunk Search 08-05-2023
0 1
0
1
Niro
Hello, I have an alert that sends an email when there are x authentication failures , this works fine and returns use...
by Niro Explorer in Splunk Search 08-04-2023
0 6
0
6
isxtn
So, this PCRE regex works in testers, but not on Splunk.    ^((http[s]?):\/)?\/?([^:\/\s]+)((\w+)*\/){2})   Should re...
by isxtn Explorer in Splunk Search 08-04-2023
0 2
0
2
t-
Needing some help building a dashboard that will display the Dat Set Version of all Linux machines on the network. An...
by t- New Member in Splunk Search 08-04-2023
0 2
0
2
lemospt
Hi, i have the following case,An operation has multiple events and every event of an operation is related by field Pu...
by lemospt Explorer in Splunk Search 08-04-2023
0 2
0
2
jhilton90
I am ingesting advanced hunting logs and I have a main dashboard where I present the number of events per Event Categ...
by jhilton90 Path Finder in Splunk Search 08-04-2023
0 7
0
7
eholz1
Hello All,I would like some suggestions. I am trying to search the Cisco ASA sourcetype in Splunk for the current use...
by eholz1 Builder in Splunk Search 08-04-2023
0 2
0
2
robertgiffin
I have a set of data that I upload into Splunk every morning as a .csv file because the tool doesn't feed the particu...
by robertgiffin Explorer in Splunk Search 08-04-2023
0 4
0
4
Talking_Master
Hi Iam looking to create an if statement:  if value  contains part of another value  it changes it too another value....
by Talking_Master Explorer in Splunk Search 08-04-2023
0 3
0
3
Questioner
I want to rename row value by data case. (It is line chart)The line chart row name changed  by token $value$if value ...
by Questioner Path Finder in Splunk Search 08-04-2023
0 6
0
6
stwong
Hello,We've an application with logs looks like following.  See below for some sample cases of single connection.With...
by stwong Communicator in Splunk Search 08-04-2023
0 3
0
3
scumbum
My event data contains the following:target: [      {        alternateId: application1       detailEntry: {        } ...
by scumbum New Member in Splunk Search 08-04-2023
0 1
0
1
kevin_larsson
I have need of creating a dashboard that will compare 2 sets of data from different times. Thus, I need to bypass the...
by kevin_larsson New Member in Splunk Search 08-04-2023
0 1
0
1
RubenElias
Hii all... Hope you can help me with two questions 1)Trying to create a query to find if the target user that set to ...
by RubenElias Loves-to-Learn Everything in Splunk Search 08-04-2023
0 1
0
1
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors