Splunk Search

Splunk Search
Community Activity
Splunk2016
I have gone over Splunk's tutorial to create Pivot tables. Now that I know the process, I would appreciate some dire...
by Splunk2016 Path Finder in Splunk Search 04-28-2015
0 2
0
2
sou128
hi, pretty new to splunk. I'm setting up a realtime search that will refresh every 30 sec. Here's my query on the ...
by sou128 Explorer in Splunk Search 04-28-2015
0 1
0
1
tb5821
How do I use the IFA or even better erex and specify mutiple values that contain a comma? I've tried putting them in ...
by tb5821 Communicator in Splunk Search 04-28-2015
0 3
0
3
garywiner
One of the fields in my data is the form "lastname,firstname". Splunk extracts the last name and moves on to the next...
by garywiner New Member in Splunk Search 04-28-2015
0 2
0
2
moiezuddin
I have a query index=casm_prod sourcetype=smtrace "Center realm" | rex "(?i) Realm\\]\\[\\]\\[\\]\\[\\]\\[\\]\\[\\]\...
by moiezuddin Explorer in Splunk Search 04-28-2015
0 20
0
20
singhbc
I have a few multivalue fields which I created using stats list(A) as A_list, list(B) as B_list, list(_time) as time_...
by singhbc Path Finder in Splunk Search 04-28-2015
2 7
2
7
rashokciet
… | where like(src, “10.9.165.%”) OR cidrmatch(“10.9.165.0/25”, dst) What will this search return as a result? An...
by rashokciet New Member in Splunk Search 04-28-2015
0 5
0
5
seam0n
I've got the start time for my events in a external xml-file. Is there a easy way to access this information in a sea...
by seam0n Explorer in Splunk Search 04-28-2015
0 5
0
5
blazergun
Hi All, I have Splunk running on my machine. I am using Nodejs (Javascript sdk) to search a query. I am using onesho...
by blazergun Engager in Splunk Search 04-27-2015
0 2
0
2
anhtrantech
Hello, I am basically stuck on this problem that I hope the Splunk community can help me with. I have 2 files. Tha...
by anhtrantech Engager in Splunk Search 04-27-2015
0 1
0
1
edrivera3
Hi I had a similar problem last month. I received a solution but now I encountered the same problem but the solution...
by edrivera3 Builder in Splunk Search 04-27-2015
0 6
0
6
krwinters11
I am trying to calculate a moving average and overlay those values on a bar chart of actual values. This is what I h...
by krwinters11 Path Finder in Splunk Search 04-27-2015
2 10
2
10
luckymaddy
Hi, Once we get data into splunk, what is the basic testing we have to do? What are the basic searches we need to ru...
by luckymaddy Explorer in Splunk Search 04-27-2015
0 3
0
3
shengcow
I have a little confusion about how time stamp actually works. I want to do a very simple query to combine the result...
by shengcow Explorer in Splunk Search 04-27-2015
0 6
0
6
HattrickNZ
I am trying to understand better how splunk regex works. I have the below example: This is a sample of the data I a...
by HattrickNZ Motivator in Splunk Search 04-27-2015
0 7
0
7
wjblazek
I have log data like this: 2015-04-22 14:10:02,351 [ACTIVE] PerfLogger [CCID] - Message: subprocess.name.1; Duration:...
by wjblazek Explorer in Splunk Search 04-27-2015
0 4
0
4
fw42
Hey folks, I have a web application that logs several log lines per request. Each line is tagged with the request id...
by fw42 New Member in Splunk Search 04-27-2015
0 6
0
6
Splunkster45
Currently, a log file is being written to every 5 minutes that displays each user logged in at that specific point in...
by Splunkster45 Communicator in Splunk Search 04-27-2015
0 3
0
3
skender27
Hi, I am new to Splunk, but I already like its features. I was trying to extract a field from my loaded .csv file a...
by skender27 Contributor in Splunk Search 04-27-2015
0 4
0
4
StevenPol
What is going on here? All fields are technically working correctly, as I can filter by them, use them in stats or e...
by StevenPol Engager in Splunk Search 04-27-2015
3 1
3
1
HeinzWaescher
Hi, what is the easiest way to filter out event duplicates without adding every field in the dedup command? Is |...
by HeinzWaescher Motivator in Splunk Search 04-27-2015
2 6
2
6
chrismeyer75
For example, on one result I have a field 'Transactionid' equal to '12345' and on another result I have a field 'tran...
by chrismeyer75 New Member in Splunk Search 04-27-2015
0 11
0
11
nibinabr
Is there a splunk search that I can use to find the latest timestamp when an app was installed? Is there an internal ...
by nibinabr Communicator in Splunk Search 04-27-2015
0 2
0
2
Laya123
Hi, I need small help from you, I am calculating duration of each transaction of on userid. My query: index=A sou...
by Laya123 Communicator in Splunk Search 04-27-2015
0 9
0
9
rodrigorsilva
Hi, I have two scheduled searches that run every 1 hour with retroactive time interval (earliest = -1h). I need to p...
by rodrigorsilva Communicator in Splunk Search 04-27-2015
0 2
0
2
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...