Splunk Search

Splunk Search
Community Activity
f_666dhn
I have an example data on csv named invent.csv like this: I want to map ip values ​​to host output using lookup usin...
by f_666dhn Explorer in Splunk Search 04-19-2023
0 1
0
1
Anidy21
This is application insight query which i need to write in splunk , can some one help me please let a=traces| where c...
by Anidy21 Engager in Splunk Search 04-19-2023
0 7
0
7
yk010123
I calculate the requests per second for my application using the following query:   method!=GET process="start" | tim...
by yk010123 Path Finder in Splunk Search 04-19-2023
0 1
0
1
btsr
Hi, I need some help with querying log events based on field values nested inside a escaped raw JSON object property....
by btsr Explorer in Splunk Search 04-19-2023
0 4
0
4
bitnapper
Hi, I regularly have the problem, that I save searches containing regexes with $ characters to a dashboard where they...
by bitnapper Path Finder in Splunk Search 04-19-2023
0 11
0
11
ASR1022
I am currently working on a search dashboard.  I have the dashboard created and the search (Submit Button).  In this ...
by ASR1022 Loves-to-Learn Lots in Splunk Search 04-19-2023
0 4
0
4
splunkcol
Hi, I have installed the virustotal add-on for Splunk.When I enter the dashboards that are already pre-built I find t...
by splunkcol Builder in Splunk Search 04-19-2023
0 0
0
0
Henesys
So there's ton of documentations of whitelisting through the subsearch approach using lookups, however, is it possibl...
by Henesys New Member in Splunk Search 04-19-2023
0 3
0
3
random_event
I need to count the number of times an alert has triggered in a specific time window (say, last 24 hours).  I am tryi...
by random_event Explorer in Splunk Search 04-19-2023
0 3
0
3
zacksoft_wf
I have a field called 'description'. I want to be able to extract MD5, SHA1, SHA256 values present in this field.Need...
by zacksoft_wf Contributor in Splunk Search 04-19-2023
0 3
0
3
willsy
index=test sourcetype=csv source=prtg.csv host=prtg device=all "Down for"=*| rename "Down for" AS Downtime| eval "Dow...
by willsy Communicator in Splunk Search 04-19-2023
0 7
0
7
harshparikhxlrd
Trying to replace the blank values on my dashboard with 0s. If table is empty, should display 0. On the logs data, it...
by harshparikhxlrd Path Finder in Splunk Search 04-18-2023
0 2
0
2
super_edition
Hello  Using the below query, I am trying to build a response     index=my_index openshift_cluster="cluster009" sourc...
by super_edition Path Finder in Splunk Search 04-18-2023
0 2
0
2
navb
We have two CMDB tables logs in to Splunk 1.  CMDB Business application - Business related info 2. CMDB Rel - Relatio...
by navb Loves-to-Learn in Splunk Search 04-18-2023
0 3
0
3
GaryZ
I have the following search string in my chart panel.  "Arguments.category{}"= "$TestSuite$" TestSuite is defined by ...
by GaryZ Path Finder in Splunk Search 04-18-2023
0 7
0
7
Lazous
Hello, I am trying to extract the data from the following message:the header data is in quotes and for each header da...
by Lazous Engager in Splunk Search 04-18-2023
0 5
0
5
Keerthi
I am trying to get the data only when my lastlogon(field name) is Null. but the above query is still giving me data f...
by Keerthi Path Finder in Splunk Search 04-18-2023
0 2
0
2
Skysurfer
I have a query that I am using to get the count of events index=system source=/var/log/syslog/* | rex field=source "...
by Skysurfer Explorer in Splunk Search 04-18-2023
0 2
0
2
mbtsoltis
How do you convert .34999832 to 34.99% or .399345 to 39.99% I need to see the .99 and not have it round up  
by mbtsoltis Explorer in Splunk Search 04-18-2023
0 3
0
3
POR160893
Hi, I have the following Splunk query:index=ABC sourcetype=DEF dv_assignment_group="SECURITY-NETWORK-L3" | table _tim...
by POR160893 Builder in Splunk Search 04-18-2023
0 3
0
3
mathewchase
I have seen many questions about disabled due to licensing violation, but I applied a reset key and now I have this m...
by mathewchase Engager in Splunk Search 04-18-2023
1 4
1
4
shubs
Hi all,Is it currently possible to somehow create a conditional macro expansion?For example, I have different list of...
by shubs Engager in Splunk Search 04-18-2023
0 2
0
2
Sekhar
Below two events  Start event  Index= x source= xtype | spath application | search application= x app " saved note" R...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
chanhee1
There are two types of raw data. What is the regular expression to get the value between the /* special symbol and th...
by chanhee1 Loves-to-Learn Lots in Splunk Search 04-17-2023
0 3
0
3
Sekhar
I have two events one is  calculate the SLA percentage from below querys   Start event query  Index=x source type= xx...
by Sekhar Explorer in Splunk Search 04-17-2023
0 12
0
12
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors