Splunk Search

Splunk Search
Community Activity
mikeyty07
I 've  two fields one is _time and another one is received_time.  I want to get the time differences between these tw...
by mikeyty07 Communicator in Splunk Search 07-28-2023
0 7
0
7
deepaksn1214
I m having a hard time trying to extract a string from a field from a splunk search using splunk regex , can someone ...
by deepaksn1214 Engager in Splunk Search 07-28-2023
0 1
0
1
eholz1
Hello Members, I have seen and used the accum command, but it does not quite give me what I want. I have this search ...
by eholz1 Builder in Splunk Search 07-28-2023
0 4
0
4
treven
I am attempting to extract attachment fields from our email logs using regex. Attachments like .jpg, .png, pdf, etc. ...
by treven Explorer in Splunk Search 07-28-2023
0 8
0
8
sh254087
I'm facing a weird issue. I'm not able to calculate percentage value when I use two variables/fields.I have a lookup ...
by sh254087 Communicator in Splunk Search 07-28-2023
0 2
0
2
Satheesh_red
Hi, Alert Query to monitor CPU usage every 5 minutes and send an email if it matches 5 of 6 bad samples (i.e., if my ...
by Satheesh_red Path Finder in Splunk Search 07-28-2023
0 9
0
9
jip31
HiI use a | stats min(_time) as time_min stats max(_time) as time_max command in my searchThe time is displayed in Un...
by jip31 Motivator in Splunk Search 07-28-2023
0 4
0
4
RemyaT
I have a Splunk query that helps me to visualize different APIs vs Time as below. Using this query I could see each l...
by RemyaT Explorer in Splunk Search 07-28-2023
0 2
0
2
Satheesh_red
Hi,I'm attempting to calculate the average of the last six CPU event values. If the average of those six events is gr...
by Satheesh_red Path Finder in Splunk Search 07-27-2023
0 1
0
1
BinaryAddict
I'm wanting to avoid using saved searches and lookup tables as much if possible so it's easily maintainable by anyone...
by BinaryAddict Engager in Splunk Search 07-27-2023
0 2
0
2
Steve_A200
I am still trying to get my head around regular expressions in splunk, and would like to use regex that could parse t...
by Steve_A200 Path Finder in Splunk Search 07-27-2023
0 3
0
3
Altexec
Hello,I have an index with a field that record how long a computer has been running. Basically, when I display the in...
by Altexec New Member in Splunk Search 07-27-2023
0 1
0
1
DanAlexander
Hi All,Can anyone help me create a regex to extract the bolded parts from the following _raw log, please?meta sequenc...
by DanAlexander Communicator in Splunk Search 07-27-2023
0 7
0
7
GregSmith
I have a savedsearch running on a 5 minute cron schedule iteratively working through a list of previously saved searc...
by GregSmith Explorer in Splunk Search 07-27-2023
0 2
0
2
Ramana246
0
2
pierre_weg
Hi guys!I have a static snapshot lookup that stores a lot of information about vulnerabilities actives on my hosts in...
by pierre_weg Path Finder in Splunk Search 07-27-2023
0 2
0
2
mk00928640
Hello everyonePlease assist me in solving the problem below.I'm attempting to determine how to track it in Splunk if ...
by mk00928640 New Member in Splunk Search 07-27-2023
0 6
0
6
ykmohank
Hi, I want to do a search having multiple strings. Example: Consider,I am looking for SearchKey1 and SerachKey2 I...
by ykmohank New Member in Splunk Search 07-27-2023
0 3
0
3
leonuz01
Hi, I need help! I have this query. Ticket_Encryption_Type=0x17 Account_Domain="ad.contoso.com" but I need, pull all ...
by leonuz01 Engager in Splunk Search 07-26-2023
0 1
0
1
Teemanny
I have the code below and I need to get the statuses yesterday and today with respect to API value.My current search ...
by Teemanny Engager in Splunk Search 07-26-2023
0 7
0
7
Neel881
Hello everyone, I am trying to SUM the columns.  index="nzc-neel-uttar" source="http:kyhkp" | timechart span=1d count...
by Neel881 Path Finder in Splunk Search 07-26-2023
0 3
0
3
Naji
When I ran the following query:     index="myindex" sourcetype="hamlet" environment=staging | top limit=10 client | e...
by Naji Explorer in Splunk Search 07-26-2023
0 4
0
4
mahesh27
my query: index=abd ("start app" AND "app listed") |rex field=_raw "APP:\s+(<application1>\S+)" |rex field=_raw ...
by mahesh27 Communicator in Splunk Search 07-26-2023
0 4
0
4
Vig95
Hi,I am new to splunk, could you please help me with below SPL, I am trying to use stats and table commandWe have 4 e...
by Vig95 Engager in Splunk Search 07-26-2023
0 3
0
3
john_c_calhoun
I'm trying to create something that displays long term outages: any index that hasn't had traffic in the last hour.I'...
by john_c_calhoun Explorer in Splunk Search 07-26-2023
0 1
0
1
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...