Splunk Search

Splunk Search
Community Activity
Skysurfer
I have a query that I am using to get the count of events index=system source=/var/log/syslog/* | rex field=source "...
by Skysurfer Explorer in Splunk Search 04-18-2023
0 2
0
2
mbtsoltis
How do you convert .34999832 to 34.99% or .399345 to 39.99% I need to see the .99 and not have it round up  
by mbtsoltis Explorer in Splunk Search 04-18-2023
0 3
0
3
POR160893
Hi, I have the following Splunk query:index=ABC sourcetype=DEF dv_assignment_group="SECURITY-NETWORK-L3" | table _tim...
by POR160893 Builder in Splunk Search 04-18-2023
0 3
0
3
mathewchase
I have seen many questions about disabled due to licensing violation, but I applied a reset key and now I have this m...
by mathewchase Engager in Splunk Search 04-18-2023
1 4
1
4
shubs
Hi all,Is it currently possible to somehow create a conditional macro expansion?For example, I have different list of...
by shubs Engager in Splunk Search 04-18-2023
0 2
0
2
Sekhar
Below two events  Start event  Index= x source= xtype | spath application | search application= x app " saved note" R...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
chanhee1
There are two types of raw data. What is the regular expression to get the value between the /* special symbol and th...
by chanhee1 Loves-to-Learn Lots in Splunk Search 04-17-2023
0 3
0
3
Sekhar
I have two events one is  calculate the SLA percentage from below querys   Start event query  Index=x source type= xx...
by Sekhar Explorer in Splunk Search 04-17-2023
0 12
0
12
kdineshreddy009
can we setup an alert based on data from current time stamp & based on information on past 15mins ?say at T1, got a l...
by kdineshreddy009 New Member in Splunk Search 04-17-2023
0 3
0
3
bhagyashriyan
Hi, I have many concurrent saved searches running due to which search delayed health indicator is always red. How to ...
by bhagyashriyan Explorer in Splunk Search 04-17-2023
0 1
0
1
att35
Hi, We have a data source containing File Path's from both Windows and Linux formats.  Applying regex separately work...
by att35 Builder in Splunk Search 04-17-2023
0 4
0
4
muradgh
Hi Splunkers, I need your assistance to create a search that provides the following:SPL query I will use it to look f...
by muradgh Path Finder in Splunk Search 04-17-2023
0 2
0
2
Sekhar
We have two events Start event  Index= x source= xtype | spath application | search application= x app " saved note" ...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
becksyboy
Hi All, I have an issue which i am unable to resolve. I have a lookup with two columns: Process_Command_Line, score U...
by becksyboy Contributor in Splunk Search 04-17-2023
0 6
0
6
Abhineet
We have splunk event having field "eventdateTime"  in format mentioned below. for example eventdateTime 2023-04-17 06...
by Abhineet Loves-to-Learn Everything in Splunk Search 04-17-2023
0 2
0
2
kmhanson
I am new to Regex expressions and trying to figure them out. I am trying to extract two sections of the following log...
by kmhanson Explorer in Splunk Search 04-17-2023
0 14
0
14
shrirangphadke
Hi, Sorry if my question is repeated or too naive. I have a text input field accepting "Module name". It works perf...
by shrirangphadke Path Finder in Splunk Search 04-17-2023
3 8
3
8
Keerthi
  I am scheduling this at 9.00 AM everyday using splunk DB connect .When i see the sourcetype nextday at 9.00 AM gett...
by Keerthi Path Finder in Splunk Search 04-17-2023
0 3
0
3
jonvijay1993
I have a multiselect for software version (version is just yyyy.mm.dd or an alphanumeric string).If the user selects ...
by jonvijay1993 Explorer in Splunk Search 04-17-2023
0 4
0
4
Sekhar
We have two events query Start event Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
dvg06
Hi Legends How do I give bit more meaningful names for fields last_sum and first_sum in below query? i.e. something l...
by dvg06 Path Finder in Splunk Search 04-16-2023
1 1
1
1
GarzaREG
I have a requirement where I have been asked to monitor for new users getting added to Sudoer.  Are there specific ac...
by GarzaREG New Member in Splunk Search 04-16-2023
0 2
0
2
RanjiRaje
Hi All, I am facing some issue in using lookup command. Need your suggestions here please.. I have a lookup file as b...
by RanjiRaje Explorer in Splunk Search 04-15-2023
0 7
0
7
willsy
Hello,Trying to complete a search that uses metrics to monitor when a device has not been connected for the last 90 d...
by willsy Communicator in Splunk Search 04-15-2023
0 2
0
2
khourihan_splun
I have a search that returns unique visitors query over 30 days' worth of logs : Using dc() it was a lot slower. Here...
by khourihan_splun Splunk Employee Splunk Employee in Splunk Search 04-15-2023
5 3
5
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...