Splunk Search

Splunk Search
Community Activity
chanhee1
There are two types of raw data. What is the regular expression to get the value between the /* special symbol and th...
by chanhee1 Loves-to-Learn Lots in Splunk Search 04-17-2023
0 3
0
3
Sekhar
I have two events one is  calculate the SLA percentage from below querys   Start event query  Index=x source type= xx...
by Sekhar Explorer in Splunk Search 04-17-2023
0 12
0
12
kdineshreddy009
can we setup an alert based on data from current time stamp & based on information on past 15mins ?say at T1, got a l...
by kdineshreddy009 New Member in Splunk Search 04-17-2023
0 3
0
3
bhagyashriyan
Hi, I have many concurrent saved searches running due to which search delayed health indicator is always red. How to ...
by bhagyashriyan Explorer in Splunk Search 04-17-2023
0 1
0
1
att35
Hi, We have a data source containing File Path's from both Windows and Linux formats.  Applying regex separately work...
by att35 Builder in Splunk Search 04-17-2023
0 4
0
4
muradgh
Hi Splunkers, I need your assistance to create a search that provides the following:SPL query I will use it to look f...
by muradgh Path Finder in Splunk Search 04-17-2023
0 2
0
2
Sekhar
We have two events Start event  Index= x source= xtype | spath application | search application= x app " saved note" ...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
becksyboy
Hi All, I have an issue which i am unable to resolve. I have a lookup with two columns: Process_Command_Line, score U...
by becksyboy Contributor in Splunk Search 04-17-2023
0 6
0
6
Abhineet
We have splunk event having field "eventdateTime"  in format mentioned below. for example eventdateTime 2023-04-17 06...
by Abhineet Loves-to-Learn Everything in Splunk Search 04-17-2023
0 2
0
2
kmhanson
I am new to Regex expressions and trying to figure them out. I am trying to extract two sections of the following log...
by kmhanson Explorer in Splunk Search 04-17-2023
0 14
0
14
shrirangphadke
Hi, Sorry if my question is repeated or too naive. I have a text input field accepting "Module name". It works perf...
by shrirangphadke Path Finder in Splunk Search 04-17-2023
3 8
3
8
Keerthi
  I am scheduling this at 9.00 AM everyday using splunk DB connect .When i see the sourcetype nextday at 9.00 AM gett...
by Keerthi Path Finder in Splunk Search 04-17-2023
0 3
0
3
jonvijay1993
I have a multiselect for software version (version is just yyyy.mm.dd or an alphanumeric string).If the user selects ...
by jonvijay1993 Explorer in Splunk Search 04-17-2023
0 4
0
4
Sekhar
We have two events query Start event Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
dvg06
Hi Legends How do I give bit more meaningful names for fields last_sum and first_sum in below query? i.e. something l...
by dvg06 Path Finder in Splunk Search 04-16-2023
1 1
1
1
GarzaREG
I have a requirement where I have been asked to monitor for new users getting added to Sudoer.  Are there specific ac...
by GarzaREG New Member in Splunk Search 04-16-2023
0 2
0
2
RanjiRaje
Hi All, I am facing some issue in using lookup command. Need your suggestions here please.. I have a lookup file as b...
by RanjiRaje Explorer in Splunk Search 04-15-2023
0 7
0
7
willsy
Hello,Trying to complete a search that uses metrics to monitor when a device has not been connected for the last 90 d...
by willsy Communicator in Splunk Search 04-15-2023
0 2
0
2
khourihan_splun
I have a search that returns unique visitors query over 30 days' worth of logs : Using dc() it was a lot slower. Here...
by khourihan_splun Splunk Employee Splunk Employee in Splunk Search 04-15-2023
5 3
5
3
Macphisto
I have a 2015 log that I need to analyze  I have a 2015 Aruba log I need to analyze.  The log does not have the year,...
by Macphisto Loves-to-Learn Lots in Splunk Search 04-15-2023
0 7
0
7
super_edition
Hello Everyone, Below is the set of the log response pattern: "message":{"input":"999.111.000.999 - - [06/Apr/2023:05...
by super_edition Path Finder in Splunk Search 04-15-2023
0 10
0
10
yoshileigh66
I have noticed that the event_ids that I cannot find documentation for are associated with two eventtypes together. H...
by yoshileigh66 Explorer in Splunk Search 04-15-2023
0 2
0
2
Sekhar
I have two events one is  Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd 2nd event ...
by Sekhar Explorer in Splunk Search 04-14-2023
0 3
0
3
kgorzynski
Some Splunk customers have encountered the following error message when performing searches: The search job with sid=...
by kgorzynski Splunk Employee Splunk Employee in Splunk Search 04-14-2023
1 0
1
0
hawkik1
I am attempting (for the first tiume) to convert the following regex search to work in transforms.conf, but can't see...
by hawkik1 Loves-to-Learn Everything in Splunk Search 04-14-2023
0 6
0
6
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...