Splunk Search

Splunk Search
Community Activity
therockhead
Beginner here, I'm trying to do the following in one query 1) Get all unique users and the count of users 2) Using...
by therockhead Path Finder in Splunk Search 03-24-2015
0 14
0
14
jizzmaster
I have a field, Count, which is adding up to several thousand. I don't care that it is 74,743, though. I just want to...
by jizzmaster Path Finder in Splunk Search 03-24-2015
0 1
0
1
danje57
Hello, I try to create stats to have all countries and cities that communicate with my servers. I made this search:...
by danje57 Path Finder in Splunk Search 03-24-2015
1 4
1
4
kestasm
Hello, I want to exclude all the WinEventLogs for service C:\Windows\System32\svchost.exe which doesnt contain the d...
by kestasm Path Finder in Splunk Search 03-24-2015
0 10
0
10
Sloefke
Hi, I'm trying to determine the span parameter for timechart dynamically, but I can't find a way to get it to work. ...
by Sloefke Path Finder in Splunk Search 03-24-2015
1 8
1
8
tb5821
How does splunk work with multiple sub-searches? If I want to have two sub-searches which one is evaluated first? Is ...
by tb5821 Communicator in Splunk Search 03-23-2015
3 4
3
4
HattrickNZ
I am thinking of using lookups for categorizing field values into certain categories, as below. Using lookups is prob...
by HattrickNZ Motivator in Splunk Search 03-23-2015
0 13
0
13
sohnaeo
Hello Guys, I am new to Splunk so please bear with me. I am having an issue and couldn't find any resolution yet. I...
by sohnaeo New Member in Splunk Search 03-23-2015
0 8
0
8
ccollord
Hi, To make a long story short i have some logs that are key value pairs, like so: foo="bar" dog="cat" frog="bat" Un...
by ccollord Explorer in Splunk Search 03-23-2015
1 2
1
2
dfenko
I am trying to track email sending logs, using information that we adjust in the message_id while sending a message. ...
by dfenko Explorer in Splunk Search 03-23-2015
0 8
0
8
pedromvieira
Hi. I'd like to rex a field that starts with another field value. EX: ****Data UA=Mozilla/5.0 (Linux; Android 4.0...
by pedromvieira Communicator in Splunk Search 03-23-2015
1 2
1
2
tjohnson341
I am attempting to extract fields from a file which was created to be human readable, so it has fields aligned at cer...
by tjohnson341 Explorer in Splunk Search 03-23-2015
0 4
0
4
bheemireddi
Any ideas around this? When I use the fields command in this search: some search | fields Activity1, Activity2... ...
by bheemireddi Communicator in Splunk Search 03-23-2015
0 4
0
4
phuehne
The two queries: search sourcetype="access*" host="www*" | timechart count by host and search sourcetype="access*" ho...
by phuehne Explorer in Splunk Search 03-23-2015
1 8
1
8
HeinzWaescher
Hi, after updating to 6.2.2 I tried to set up a new automatic lookup. I've created the lookup definition, but I can'...
by HeinzWaescher Motivator in Splunk Search 03-23-2015
0 2
0
2
a212830
Hi, I have a tcp data stream that has embedded hosts that I need to transform, and I'm hoping to get some regex help...
by a212830 Champion in Splunk Search 03-22-2015
0 1
0
1
Sloefke
Hi, I have defined a macro that returns an amount of seconds with "s" appended to it, based on a start and end time...
by Sloefke Path Finder in Splunk Search 03-22-2015
0 5
0
5
seanh71
I have splunk monitoring on a network port, a remote application logs an ASCII number to that port. How do I create ...
by seanh71 New Member in Splunk Search 03-22-2015
0 1
0
1
jturnervbs
I am collecting group membership data daily into Splunk and I need to know how to search for changes that occur over ...
by jturnervbs Engager in Splunk Search 03-22-2015
1 1
1
1
adylent
Can anyone recommend a search to audit when an eventtype definition is changed?
by adylent Path Finder in Splunk Search 03-22-2015
0 3
0
3
talbot7
Displaying outside temperature with timechart. The graph show 0~100, but my entire data set is 70~90. Is there a wa...
by talbot7 Path Finder in Splunk Search 03-22-2015
5 2
5
2
SY715
Now I have a table like below. ID, Result, SerNum, Place 1, success, AAAAA, XXXXX 2, success, BBBBB, YYYYY 3, failur...
by SY715 Explorer in Splunk Search 03-21-2015
2 3
2
3
ckurtz
Just moved to a new 6.2.2 Search Head Cluster (SHC) from a Search Head Pool (SHP) which had mounted bundles enabled. ...
by ckurtz Path Finder in Splunk Search 03-20-2015
0 1
0
1
IngloriousSplun
I have two different network sensors - Sensor A and Sensor B. Each has their own event format that I aggregate in Sp...
by IngloriousSplun Communicator in Splunk Search 03-20-2015
2 10
2
10
harshal_chakran
Hi, I have a csv file as shown below: DATE VALUE 1-Jan 2 02-Jan 3 04-Jan 5 05-Jan ...
by harshal_chakran Builder in Splunk Search 03-20-2015
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...