Splunk Search

Splunk Search
Community Activity
sdorich
I have events in xml format. Some of the events include this header: xml version="1.0" encoding="UTF-8" standalone="...
by sdorich Communicator in Splunk Search 02-18-2014
1 4
1
4
dctopper
Hi, I've run into a problem: Splunk ingests Window's security events in such a way that field names may occur more t...
by dctopper Explorer in Splunk Search 02-18-2014
0 2
0
2
johnsmithbitter
I'm trying to create a search that provides me with the average duration between VALIDATED and ARCHIVED only if it co...
by johnsmithbitter Explorer in Splunk Search 02-17-2014
0 7
0
7
jaj
I have a filed in my logs "labeDatal" and I also have another field that I trace out called "labelDataSpec" i.e. log...
by jaj Path Finder in Splunk Search 02-17-2014
0 1
0
1
changwoo
start_time = > 2014-02-13T22:57:15+0900 end_ time = > 2014-02-13T23:59:54+0900 how can i get the time difference ??...
by changwoo Communicator in Splunk Search 02-17-2014
0 3
0
3
the_wolverine
Previously we have encountered issues with using CAPS in index name configuration. What other issues should we be aw...
by the_wolverine Champion in Splunk Search 02-17-2014
0 4
0
4
surfjose
Hi I have a log-file with diffrent time formats. Is it possible to extract this diffrent timestamps with TIME_PREFIX ...
by surfjose New Member in Splunk Search 02-17-2014
0 2
0
2
kdb8916
I am trying to extract info from the _raw result of my Splunk query. Currently my _raw result is: _raw="2014-02-13 1...
by kdb8916 Explorer in Splunk Search 02-17-2014
1 5
1
5
harshal_chakran
Hi, I have used a code in advance xml for 3 buttons <module name="HTML" layoutPanel="panel_row3_col1"> <param n...
by harshal_chakran Builder in Splunk Search 02-17-2014
0 1
0
1
jimjohn
How can I join and group data from 2 different hosts. Say I have HostA , HostB and ID as common field in 2 hosts. I w...
by jimjohn Path Finder in Splunk Search 02-17-2014
0 1
0
1
SplunkBaby
Hi I have 2 data source say DS1 and DS2. There is a common field called EMPID for this two data source. I want to gen...
by SplunkBaby Explorer in Splunk Search 02-17-2014
0 2
0
2
ndkhoiits
I have a log file which contains a log like following: 2014-02-14 01:49:22,938 Updated this customer: email: test@te...
by ndkhoiits Explorer in Splunk Search 02-16-2014
0 3
0
3
the_wolverine
dbinspect has to be run on the indexer. It can't be run from the search head. How do I get the result from my searc...
by the_wolverine Champion in Splunk Search 02-16-2014
0 2
0
2
bckq
This is my search: index=cloud (cloud_severity="High" OR cloud_severity="Disaster") | dedup cloud_info,cloud_hostnam...
by bckq Path Finder in Splunk Search 02-16-2014
1 4
1
4
thesteve
I ran a search and noticed something unexpected in my results. Of course the error I saw was not an informative one,...
by thesteve Path Finder in Splunk Search 02-14-2014
0 4
0
4
juniormint
Imagine I have a bunch of indexes named app1, app2, app3, .... appN. Assuming I have search permissions on all of th...
by juniormint Communicator in Splunk Search 02-14-2014
0 3
0
3
juniormint
I would like filter certain known data events into three different indexes (possibly more in the future). Events ha...
by juniormint Communicator in Splunk Search 02-14-2014
0 6
0
6
aelliott
I have a spreadsheet with a list of locations. I have a list of Categories. I have events of incidents with an office...
by aelliott Motivator in Splunk Search 02-14-2014
0 1
0
1
sdorich
I'm trying to match everything in quotes in the following log file example. I've been working on this for a while and...
by sdorich Communicator in Splunk Search 02-14-2014
0 8
0
8
helge
This might be a bug in Splunk 6.0.1 (on Windows). I am building a web framework app. Each dashboard has a timerange v...
by helge Builder in Splunk Search 02-14-2014
1 7
1
7
harshal_chakran
Hi, I am using a advance xml to show a chart, including the job progress indicator, which is as follows:- <module na...
by harshal_chakran Builder in Splunk Search 02-14-2014
0 2
0
2
fmayot
I'm using a subsearch multiple times within a search. Is Splunk able to optimize this and run the subsearch only once...
by fmayot New Member in Splunk Search 02-14-2014
0 3
0
3
darshan_singh01
Feb 13 22:01:25 XXXINFQST03 sshd[9161]: Accepted password for admin from Above is the message I am getting from Lin...
by darshan_singh01 Path Finder in Splunk Search 02-13-2014
0 1
0
1
wsnyder2
We can not get field extraction to work with IIS log files. Any suggestions? transforms.conf [iisw3cfields] DELIMS ...
by wsnyder2 Path Finder in Splunk Search 02-13-2014
0 3
0
3
richnavis
I have a bulletin message indicating that a restart of the splunk service is required due to enabling/disabling a spl...
by richnavis Contributor in Splunk Search 02-13-2014
0 6
0
6
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...