Splunk Search

Splunk Search
Community Activity
sajumulakkal
field1,field2,field3 1, a, b 1, b, c 1, c, d 2, r, s 2, s, k 2, k, l 2, l, m field 1 is the key based on above dat...
by sajumulakkal New Member in Splunk Search 09-07-2015
0 3
0
3
hkhat5
Sample data set user, pc, logon, logoff, durationOfLogon User11, HNA1E8I, 01-06-15 13:49:09, 01-06-15 13:49:11, 0:00...
by hkhat5 New Member in Splunk Search 09-07-2015
0 2
0
2
Masa
How can I keep only first 6k bytes of single line event. I have syslog type of data. They are single line and someti...
by Masa Splunk Employee Splunk Employee in Splunk Search 09-07-2015
0 7
0
7
arungeorge09
I have a splunk join between a synchornous event and an asynchornous event. The only join condition between these are...
by arungeorge09 Path Finder in Splunk Search 09-07-2015
0 1
0
1
Madhan45
We can use \ as an escape sequence for special characters ",",(,),[,] and so on. How to use for * character?
by Madhan45 Path Finder in Splunk Search 09-07-2015
0 3
0
3
isedrof
Hi everybody, I need your help please, i want to convert a numeric field to a date. Ex: "20150223" >> "2015-02-23" ...
by isedrof Engager in Splunk Search 09-07-2015
0 3
0
3
raindrop18
I have this string and I want the output for this result to be combined on one line and also sum the results index="...
by raindrop18 Communicator in Splunk Search 09-06-2015
0 2
0
2
HattrickNZ
I want to just look at 1 hour for yesterday, but I want it to be relative to today so no matter when I look at it in ...
by HattrickNZ Motivator in Splunk Search 09-05-2015
0 4
0
4
pdoconnell
I am building an alert based on file accesses to certain files. This is what I have so far: index=wineventlog source...
by pdoconnell Path Finder in Splunk Search 09-05-2015
0 1
0
1
subtrakt
Hi, Anyone know what's the best way to count by minute the error exists, and not by the count of the number of erro...
by subtrakt Contributor in Splunk Search 09-05-2015
0 1
0
1
subtrakt
Hi, I have a search w/ a stats function that illustrates multiple individual errors. Once that search completes, I ...
by subtrakt Contributor in Splunk Search 09-05-2015
0 6
0
6
dimitryz
Hi all, I'm tying to use D3 donut chart with splunk real-time search. I've defined SearchManager this way : var searc...
by dimitryz Path Finder in Splunk Search 09-04-2015
0 1
0
1
ryanprice22
I wrote this Splunk search that gives me the lat and lon for both the destination IP address and source IP address ba...
by ryanprice22 New Member in Splunk Search 09-04-2015
0 3
0
3
idab
Hi everyone, Need help with my XML below. I need to create a drop-down to display certain data based on the host and...
by idab Path Finder in Splunk Search 09-04-2015
0 3
0
3
guimilare
Hi all. I'm having a hard time trying to make a subtraction.. This is my entry csv: Date,category,amount,person 01...
by guimilare Communicator in Splunk Search 09-04-2015
0 5
0
5
Runals
As a spin on the rabbit/coyote population cycle I've come up with one for humans vs zombies (somewhat at boss' reques...
by Runals Motivator in Splunk Search 09-04-2015
12 8
12
8
JohnWright8
I'm processing some IIS log files with a search: stats count max(time_taken) avg(time_taken) as avgTT by cs_uri_stem ...
by JohnWright8 Path Finder in Splunk Search 09-04-2015
2 2
2
2
coshea
Using Splunk 6.2, I have a few regex commands that return drastically different results when they are set up using f...
by coshea Engager in Splunk Search 09-04-2015
0 3
0
3
nilotpaldutta
Hi, I have a column in my source with different severity levels, for example - Severity 1 - High 2 - Medium 3 - Mo...
by nilotpaldutta Explorer in Splunk Search 09-04-2015
0 1
0
1
kierencrossland
I am in the process of writing a custom command using the Python SDK. It is a generating command. I would like the ...
by kierencrossland Path Finder in Splunk Search 09-03-2015
0 1
0
1
raby1996
Hi all, So I have a search that currently is giving me a stats table where one of the fields is "Bundle", and what ...
by raby1996 Path Finder in Splunk Search 09-03-2015
0 3
0
3
bwindham
I have an instance using ServiceNow data where I want to dedup the data based on sys_updated_on to get the last updat...
by bwindham Path Finder in Splunk Search 09-03-2015
0 2
0
2
andrewjgriffin
I have message data similar to as follows, which is the count of active user processes on a host: host=hostA user1:0...
by andrewjgriffin Engager in Splunk Search 09-03-2015
0 4
0
4
ahattrell_splun
When adding an _meta entry into inputs.conf such as: [monitor:///tmp/fwdtest] sourcetype = sun_jvm _meta env::prd W...
by ahattrell_splun Splunk Employee Splunk Employee in Splunk Search 09-03-2015
0 4
0
4
zackh123
I have a saved search in splunk which has a default start time of 7 days. I have a curl command that works perfectly ...
by zackh123 Path Finder in Splunk Search 09-03-2015
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors