Splunk Search

Splunk Search
Community Activity
herndona
I am working on a search that will take a massive list of user groups and table the servers under such group. An exa...
by herndona Engager in Splunk Search 02-12-2015
0 1
0
1
landen99
Let's say that I do an outputlookup after a timechart command. Now I have a csv file that should be formatted for th...
by landen99 Motivator in Splunk Search 02-12-2015
0 17
0
17
rlough
Basically I have a field "Name" and I want to keep all events with duplicate "Name"s. So exactly the opposite of dedu...
by rlough Path Finder in Splunk Search 02-12-2015
1 4
1
4
broman
I have problem with saving regex for extracting class name Here is my regex (?i)\[([0-9a-zA-Z\.\s\-]*(\[[0-9]&ast...
by broman Explorer in Splunk Search 02-12-2015
0 6
0
6
Muryoutaisuu
Hi guys I have a CSV file with following structure: +--------+-----------+------------+ | DEV_ID | attr_name | att...
by Muryoutaisuu Communicator in Splunk Search 02-12-2015
0 3
0
3
Jason
Is it possible to set field name and value with rex - or some other command - on the search bar? I have a large XML...
by Jason Motivator in Splunk Search 02-12-2015
1 4
1
4
VikasSinha
I have a bash script which list the Application name and its version as follows in a file which is indexed by Splunk ...
by VikasSinha New Member in Splunk Search 02-12-2015
0 2
0
2
himynamesdave
Attached is some data that you should be able to use to reproduce what I am trying to achieve. Events.csv – extract ...
by himynamesdave Contributor in Splunk Search 02-12-2015
0 2
0
2
shayfa
Hi , I have this query : sourcetype= Filed=X [search sourcetype= Filed=X | iplocation IPAddress | stats dc(Cou...
by shayfa Path Finder in Splunk Search 02-12-2015
1 4
1
4
freeofwind
{%searchmanager id="test" search='eventcount summarize=false index=$input_index$ | fields index | map search="|m...
by freeofwind New Member in Splunk Search 02-11-2015
0 1
0
1
pjb2160
Hello, I have two log sources (AD logs and approval logs) which I am performing a correlation on (via a join). Each...
by pjb2160 Path Finder in Splunk Search 02-11-2015
0 5
0
5
OMohi
I am looking for a tool to perform text mining searches, adhoc and based on lookup criteria/table, and the ability t...
by OMohi Path Finder in Splunk Search 02-11-2015
0 2
0
2
servlette
I am logging something like: Foo=123|456 When I query Splunk to get me Foo, it only prints 123 and it ignores |456. ...
by servlette Engager in Splunk Search 02-11-2015
0 5
0
5
ccsfdave
I'm sorry, I am not even sure how to ask this question or whether the subject line really explains what I am after. ...
by ccsfdave Builder in Splunk Search 02-11-2015
0 2
0
2
jewettg
So my question is based on something I am trying to do, but my splunk-foo is not powerful enough to figure this out! ...
by jewettg Explorer in Splunk Search 02-11-2015
0 1
0
1
sugitime
I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on Janu...
by sugitime Explorer in Splunk Search 02-11-2015
1 1
1
1
redc
I have two sets of data that I'm trying to join. Both data sets have a field for SystemMessageId value, but in the s...
by redc Builder in Splunk Search 02-11-2015
0 7
0
7
darrend
Hi Guys I am trying to automatically create a lookup table based on results from searches, part of the search will b...
by darrend Path Finder in Splunk Search 02-11-2015
0 4
0
4
the_wolverine
I want to disable these searches that run automatically when a user is in the search view or launcher view.
by the_wolverine Champion in Splunk Search 02-11-2015
3 2
3
2
snehal8
Hello Everyone, I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with a...
by snehal8 Path Finder in Splunk Search 02-11-2015
0 8
0
8
markthompson
Hello, I have a search that tables certain values from my data fields, although i wish to create a new field on all e...
by markthompson Builder in Splunk Search 02-11-2015
4 3
4
3
celsohso
I would like to convert a earliest and latest time and concatenate in a string value, so I could have that in my Dash...
by celsohso Path Finder in Splunk Search 02-10-2015
1 5
1
5
rmurthy
Hello, I am looking for a solution to manage my splunk objects (searches, event type, macros, lookups, etc). There ar...
by rmurthy Engager in Splunk Search 02-10-2015
4 2
4
2
skoelpin
I'm creating dashboards for the error status. We currently have 3 different statuses (200,404, and 0). The '200' stat...
by SplunkTrust SplunkTrust in Splunk Search 02-10-2015
0 4
0
4
ltrand
I was wondering if it was possible to write a props.conf something similar to the following: props: [sourcetype = m...
by ltrand Contributor in Splunk Search 02-10-2015
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...