Splunk Search

Splunk Search
Community Activity
shantu
I have created several search-time field extractions to filter out Credit Card numbers from our logs: \s+(?<CCVisaNu...
by shantu Explorer in Splunk Search 03-17-2015
1 2
1
2
brod_geico
Hello folks, I'm not a developer but trying to see how I can finish this task. Here is my requirement: Every week...
by brod_geico Path Finder in Splunk Search 03-17-2015
0 2
0
2
HattrickNZ
I have a field with values like this "NENAME1/Some text:romc" I would like to somethink like this eval field=, but t...
by HattrickNZ Motivator in Splunk Search 03-17-2015
0 8
0
8
vtsguerrero
Hello guys, sup? We've got this piece of log which is a MySql log and we should not change the layout, but need to e...
by vtsguerrero Contributor in Splunk Search 03-17-2015
0 7
0
7
jstaley
Hello Everyone, After doing quite a bit of research I believe I have the correct process for filtering out informati...
by jstaley Explorer in Splunk Search 03-17-2015
0 6
0
6
70250939
indexに"count"というフィールドがあり、"user"ごとに"count"を合計を出し、数が多い順に表示させています。 |stats sum(count) by user |sort - sum(count) 数が少ないひ...
by 70250939 Explorer in Splunk Search 03-17-2015
0 4
0
4
OmarDee
0
3
dwalker1
Hi Folks, I have a dashboard that automatically populates a drop-down based on a search with CDATA. I want to be ab...
by dwalker1 New Member in Splunk Search 03-17-2015
0 3
0
3
lblum
Hello, I'm trying to convert an hexadecimal field to base two (binary). Let me show you an exemple : field_hex=fff...
by lblum New Member in Splunk Search 03-16-2015
0 6
0
6
HattrickNZ
I have the following search ...| eval limit4Graph=Limit-Usage | fields userLabel limit4Graph Usage percent Note: Lim...
by HattrickNZ Motivator in Splunk Search 03-16-2015
0 2
0
2
t82921389
http://docs.splunk.com/Documentation/Splunk/6.2.2/ReleaseNotes/KnownIssues shows many defects/issues listed with eac...
by t82921389 Explorer in Splunk Search 03-16-2015
1 6
1
6
alaorath
I'm having no success in filtering out the "-- MARK --" messages from my syslogs. Here is my props.conf: [source::\...
by alaorath Path Finder in Splunk Search 03-16-2015
0 5
0
5
mitcanmit
In my logs, I have the below part and I want to extract success {\"state\":\"success\", How do I formulate it with...
by mitcanmit Explorer in Splunk Search 03-16-2015
0 2
0
2
jolver14
Hello all, I have a search I'm trying to get just right -- and its 99% there: disk_usage | dedup host |chart sum(di...
by jolver14 New Member in Splunk Search 03-16-2015
0 8
0
8
masonmorales
I have multiline events that contain anywhere from 1 to 30 status codes per event. For example: status = success sta...
by masonmorales Influencer in Splunk Search 03-16-2015
1 2
1
2
christian_l
Hi there, I'd like to build individual Dashboards per Splunk-User (LDAP mapped). As there is a huge number of employ...
by christian_l Path Finder in Splunk Search 03-16-2015
4 3
4
3
harshal_chakran
Hi, I want to display the data only from last day's 6pm to next day 6pm. I tried various forms of earliest and latest...
by harshal_chakran Builder in Splunk Search 03-16-2015
0 2
0
2
frankloron
I have a feeling there is a simple solution to this, I am just not seeing it. Possibly appending null data at the st...
by frankloron Explorer in Splunk Search 03-16-2015
3 10
3
10
clymbouris
I have an Access List input that looks like this "|ALLOW-LABS.LOCAL\Accounting_FS_Access-0x1301ff-OI|CI|0=GenericRea...
by clymbouris Path Finder in Splunk Search 03-16-2015
0 1
0
1
jravida
Hi folks, I'm doing a lookup table (on some data that would take too much time to explain without more confusion), i...
by jravida Communicator in Splunk Search 03-16-2015
1 3
1
3
kshanky143
Hello I have 2 tables. Table 1 has two columns 'STATUS ' and 'COUNT' STATUS ----- COUNT Passed ----- 10 Failed...
by kshanky143 Path Finder in Splunk Search 03-15-2015
0 1
0
1
kgreat
For example, I need to search for all rehire dates between 12-01-2014 through 12-31-2014 "rehire date"=earliest="12/...
by kgreat Path Finder in Splunk Search 03-15-2015
0 7
0
7
HattrickNZ
I have the below graph I get this graph with a query similar to: ...| stats max(c117) as whatever max(limit2) as "...
by HattrickNZ Motivator in Splunk Search 03-15-2015
0 6
0
6
cdupuis123
I’m in a pickle (splunk license) again this morning and I’m trying to address it via a transform. bit bucket for win...
by cdupuis123 Path Finder in Splunk Search 03-15-2015
0 4
0
4
seanel
So here is a sample event: Sun Mar 15 12:59:52 UTC 2015 dpStatusEthernetInterfaceStatusName.eth0 = eth0 dpStatusEthe...
by seanel Path Finder in Splunk Search 03-15-2015
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors