Splunk Search

Splunk Search
Community Activity
POR160893
Hi, I have a dashboard where the data is coming from a lookup called "ABC" which has 2 fields called "src_ip" and "de...
by POR160893 Builder in Splunk Search 05-25-2023
0 2
0
2
JohnCM8181
I am trying to write a search that displays a table that shows whether a log in cloud watch exists or not every 15 mi...
by JohnCM8181 New Member in Splunk Search 05-25-2023
0 1
0
1
damode1
I have the below sample botsv3 sample data set which is sysmon in xml format. I need to convert that into json format...
by damode1 Path Finder in Splunk Search 05-24-2023
0 5
0
5
TravellingGuy
Hi! I have a search query problem that's wrecking my newbie brain. I have log events that look like this:     { "op...
by TravellingGuy Engager in Splunk Search 05-24-2023
0 4
0
4
risingflight143
Hi All I have a room mailbox in office365 and i want to get the information of how many meetings were booked for one ...
by risingflight143 Explorer in Splunk Search 05-24-2023
0 1
0
1
man03359
I am relatively new to Splunk and I am trying to extracting fields in Splunk,  I have a pattern I am attempting to ex...
by man03359 Communicator in Splunk Search 05-24-2023
0 6
0
6
k_ashabi
I have a lookup table from which I need to read the IP addresses one by one, perform calculations on each address, an...
by k_ashabi Loves-to-Learn Lots in Splunk Search 05-24-2023
0 7
0
7
neeravmathur
Hi All, We noticed that one of our Heavy Forwarder has not been sending _audit and _internal logs to our indexer. It ...
by neeravmathur Path Finder in Splunk Search 05-24-2023
0 7
0
7
devtech83
I have mail.log. This is displayed in the "Event" column:     May 24 14:02:05 srv7 amavis[10129]: (10129-08) Passed C...
by devtech83 Engager in Splunk Search 05-24-2023
0 1
0
1
jonvijay1993
I have a query for for my dropdown with tokens inserted here and there and whenever the values on those tokens change...
by jonvijay1993 Explorer in Splunk Search 05-24-2023
0 4
0
4
jenkinsta
I am making a trend chart of specific data set. What I am looking for is (generic example)index=nessus | eval Month=s...
by jenkinsta Path Finder in Splunk Search 05-24-2023
0 2
0
2
jonvijay1993
I have a union [] command that I want to execute only if a check box is checked, how can I manage this? SPL2 branch d...
by jonvijay1993 Explorer in Splunk Search 05-24-2023
0 11
0
11
acontarciego
What's the quickest and safest way to move indexed data from one location to another? I have data that is currently s...
by acontarciego Explorer in Splunk Search 05-23-2023
3 7
3
7
dm1
I want to convert some of the below individual json objects in the event into nested single json object like the seco...
by dm1 Contributor in Splunk Search 05-23-2023
0 2
0
2
damode1
I want to convert some of the below individual json objects in the event into nested single json object like the seco...
by damode1 Path Finder in Splunk Search 05-23-2023
0 2
0
2
rolabrie
Using the Splunk addon for AWS to collect ec2 instance metadata I get an array called tags with key/value pairs such ...
by rolabrie Loves-to-Learn in Splunk Search 05-23-2023
0 8
0
8
jacobfrasca
I am trying to use a lookup we use to track usage of exceptions in one of our platforms so that we can remove unneede...
by jacobfrasca New Member in Splunk Search 05-23-2023
0 1
0
1
jialiu907
I am looking to have a time chart table that has a dropdown menu based on a token,  be able to show all of the values...
by jialiu907 Path Finder in Splunk Search 05-23-2023
0 2
0
2
umd06
I have a cron job that creates a lookup file under $splunkhome$/etc/apps/search/lookups on one of the search heads. H...
by umd06 Engager in Splunk Search 05-23-2023
0 1
0
1
SwervyMcBourbon
For these following two events:  { "people": { "bob": 172, "maria": 161 } } { "people": { "bob": 1...
by SwervyMcBourbon Engager in Splunk Search 05-23-2023
0 2
0
2
POR160893
On Splunk, I have the following 2 searches: 1)`ABC_logs(traffic)` user != "unknown" src_ip IN (*) dest_ip IN (*) | st...
by POR160893 Builder in Splunk Search 05-23-2023
0 1
0
1
AnaSpiStats
This is my search:message_data_type=gd*| timechart count by message_data_type limit=10These are my results:But I need...
by AnaSpiStats Engager in Splunk Search 05-23-2023
0 3
0
3
msalghamdi
Hello Splunkers,    i want to to extract a 10-digit path from a url but unfortunately i always get this error: Error ...
by msalghamdi Path Finder in Splunk Search 05-23-2023
0 3
0
3
KalebeRS
I have a table with 3 different csv files that I have to show, with different values.When I select the value that I w...
by KalebeRS Explorer in Splunk Search 05-23-2023
0 1
0
1
super_edition
Hello,  I have below search query     index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshi...
by super_edition Path Finder in Splunk Search 05-23-2023
0 2
0
2
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...