Splunk Search

Splunk Search
Community Activity
AL3Z
Hi all, I'm looking for the search how we can seperate the multiple columns in to single column  Ex: Host         sca...
by AL3Z Builder in Splunk Search 05-09-2023
0 1
0
1
gvk_us
Hi, We have applications Availability data in splunk.With below SPL, I got this data. Base_SPL..| streamstats reset_o...
by gvk_us Explorer in Splunk Search 05-09-2023
0 7
0
7
AL3Z
Hi All, How do we list out the fields in tabular format..Eg: hostname  action  windows     allowed                   ...
by AL3Z Builder in Splunk Search 05-09-2023
0 1
0
1
Vish
In the below chart if u can see i have used round and avg to first_response and closure time. But my values are not a...
by Vish Explorer in Splunk Search 05-09-2023
0 4
0
4
thenormalone
I have a dashboard that has a dropdown which takes in the values from a csv file. Is there a way I can add on to the ...
by thenormalone Path Finder in Splunk Search 05-08-2023
0 3
0
3
balcv
I have a field returned with some search data that contains a date and time in UTC.  I would like to be able to add 1...
by balcv Contributor in Splunk Search 05-07-2023
0 2
0
2
Jouman
Hi all,  I have a field named as item_description which is an array of decimal value, which represents the descriptio...
by Jouman Path Finder in Splunk Search 05-06-2023
0 4
0
4
LearningGuy
how do I escape single quote within DBXquery SQL like commandFor example:   content = '. . . . . .  src_port': 20, 'd...
by LearningGuy Motivator in Splunk Search 05-06-2023
0 1
0
1
landen99
I would like to import a lookup table in a subsearch for a raw value search: index=i1 sourcetype=st1 [inputlookup us...
by landen99 Motivator in Splunk Search 05-06-2023
2 6
2
6
srv007
The data is in key value format instead of field value due to limitation of fields to be used. There are 10+ key valu...
by srv007 Path Finder in Splunk Search 05-06-2023
0 9
0
9
spl_stu
How to view the currently running search of Splunk and display the amount of memory consumed during the execution of ...
by spl_stu Explorer in Splunk Search 05-06-2023
0 4
0
4
Blackdragon7
I can load a Sysmon  log into Splunk as a lookup table, but how do I view it after that? What code do I use to view t...
by Blackdragon7 Observer in Splunk Search 05-05-2023
0 7
0
7
bmanikya
Distcp job application_1681357021637_0984 MAPREDUCE Wed May 3 04:32:32 MST 2023 Wed May 3 04:32:40 MST 2023 SUCCEEDED...
by bmanikya Loves-to-Learn Everything in Splunk Search 05-05-2023
0 6
0
6
kc_prane
Hi I am using the below query and i need the results in hourly basis for the time i selected ?   "My Base search"   |...
by kc_prane Communicator in Splunk Search 05-05-2023
0 2
0
2
pavanae
I have a Splunk search outputs result as follows. DetailslinkProduct Details :Product 1:- ABC123Product 2:- DEF456abc...
by pavanae Builder in Splunk Search 05-05-2023
0 1
0
1
Jsk1950
I try to show all the value in Spluk dashoard . I have this kind of data   { returnCode= 2,  itemCount=35, cdt=4 , li...
by Jsk1950 New Member in Splunk Search 05-05-2023
0 0
0
0
DeanDeleon0
Hello, I'm using the following search string to monitor SQL Server DB Tables that are being audited by SQL Server Aud...
by DeanDeleon0 Path Finder in Splunk Search 05-05-2023
0 11
0
11
superisk
Hi all, I am confident with strptime/strftime but i'm really struggling with the correct strptime argument for the fo...
by superisk Explorer in Splunk Search 05-05-2023
0 2
0
2
pavanae
I have a Splunk search outputs result as follows. DetailslinkProduct Details :Product 1:- ABC123Product 2:- DEF456abc...
by pavanae Builder in Splunk Search 05-05-2023
0 0
0
0
Ramana246
what is the indexer acknowledgement  parameters in Outputs.conf?
by Ramana246 Explorer in Splunk Search 05-05-2023
0 1
0
1
Ramana246
if we are executing an eval statement to create a new field, will it be added to the data in the disk?
by Ramana246 Explorer in Splunk Search 05-05-2023
0 2
0
2
Ramana246
based on the search time which is best, stats or transaction.
by Ramana246 Explorer in Splunk Search 05-05-2023
0 3
0
3
fatsug
I'm trying to use tstats to calculate the daily total number of events for an index per day for one week. Then calcul...
by fatsug Builder in Splunk Search 05-05-2023
0 2
0
2
secphilomath1
I am trying to eventually get to the point where I can add this to props.conf but am trying out the searches in splun...
by secphilomath1 Explorer in Splunk Search 05-05-2023
0 15
0
15
Sekhar
We have created base serach query but I required to created root search base on that .
by Sekhar Explorer in Splunk Search 05-04-2023
0 3
0
3
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors