Splunk Search

Splunk Search
Community Activity
Lazous
Hello, I am trying to extract the data from the following message:the header data is in quotes and for each header da...
by Lazous Engager in Splunk Search 04-18-2023
0 5
0
5
Keerthi
I am trying to get the data only when my lastlogon(field name) is Null. but the above query is still giving me data f...
by Keerthi Path Finder in Splunk Search 04-18-2023
0 2
0
2
Skysurfer
I have a query that I am using to get the count of events index=system source=/var/log/syslog/* | rex field=source "...
by Skysurfer Explorer in Splunk Search 04-18-2023
0 2
0
2
mbtsoltis
How do you convert .34999832 to 34.99% or .399345 to 39.99% I need to see the .99 and not have it round up  
by mbtsoltis Explorer in Splunk Search 04-18-2023
0 3
0
3
POR160893
Hi, I have the following Splunk query:index=ABC sourcetype=DEF dv_assignment_group="SECURITY-NETWORK-L3" | table _tim...
by POR160893 Builder in Splunk Search 04-18-2023
0 3
0
3
mathewchase
I have seen many questions about disabled due to licensing violation, but I applied a reset key and now I have this m...
by mathewchase Engager in Splunk Search 04-18-2023
1 4
1
4
shubs
Hi all,Is it currently possible to somehow create a conditional macro expansion?For example, I have different list of...
by shubs Engager in Splunk Search 04-18-2023
0 2
0
2
Sekhar
Below two events  Start event  Index= x source= xtype | spath application | search application= x app " saved note" R...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
chanhee1
There are two types of raw data. What is the regular expression to get the value between the /* special symbol and th...
by chanhee1 Loves-to-Learn Lots in Splunk Search 04-17-2023
0 3
0
3
Sekhar
I have two events one is  calculate the SLA percentage from below querys   Start event query  Index=x source type= xx...
by Sekhar Explorer in Splunk Search 04-17-2023
0 12
0
12
kdineshreddy009
can we setup an alert based on data from current time stamp & based on information on past 15mins ?say at T1, got a l...
by kdineshreddy009 New Member in Splunk Search 04-17-2023
0 3
0
3
bhagyashriyan
Hi, I have many concurrent saved searches running due to which search delayed health indicator is always red. How to ...
by bhagyashriyan Explorer in Splunk Search 04-17-2023
0 1
0
1
att35
Hi, We have a data source containing File Path's from both Windows and Linux formats.  Applying regex separately work...
by att35 Builder in Splunk Search 04-17-2023
0 4
0
4
muradgh
Hi Splunkers, I need your assistance to create a search that provides the following:SPL query I will use it to look f...
by muradgh Path Finder in Splunk Search 04-17-2023
0 2
0
2
Sekhar
We have two events Start event  Index= x source= xtype | spath application | search application= x app " saved note" ...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
becksyboy
Hi All, I have an issue which i am unable to resolve. I have a lookup with two columns: Process_Command_Line, score U...
by becksyboy Contributor in Splunk Search 04-17-2023
0 6
0
6
Abhineet
We have splunk event having field "eventdateTime"  in format mentioned below. for example eventdateTime 2023-04-17 06...
by Abhineet Loves-to-Learn Everything in Splunk Search 04-17-2023
0 2
0
2
kmhanson
I am new to Regex expressions and trying to figure them out. I am trying to extract two sections of the following log...
by kmhanson Explorer in Splunk Search 04-17-2023
0 14
0
14
shrirangphadke
Hi, Sorry if my question is repeated or too naive. I have a text input field accepting "Module name". It works perf...
by shrirangphadke Path Finder in Splunk Search 04-17-2023
3 8
3
8
Keerthi
  I am scheduling this at 9.00 AM everyday using splunk DB connect .When i see the sourcetype nextday at 9.00 AM gett...
by Keerthi Path Finder in Splunk Search 04-17-2023
0 3
0
3
jonvijay1993
I have a multiselect for software version (version is just yyyy.mm.dd or an alphanumeric string).If the user selects ...
by jonvijay1993 Explorer in Splunk Search 04-17-2023
0 4
0
4
Sekhar
We have two events query Start event Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
dvg06
Hi Legends How do I give bit more meaningful names for fields last_sum and first_sum in below query? i.e. something l...
by dvg06 Path Finder in Splunk Search 04-16-2023
1 1
1
1
GarzaREG
I have a requirement where I have been asked to monitor for new users getting added to Sudoer.  Are there specific ac...
by GarzaREG New Member in Splunk Search 04-16-2023
0 2
0
2
RanjiRaje
Hi All, I am facing some issue in using lookup command. Need your suggestions here please.. I have a lookup file as b...
by RanjiRaje Explorer in Splunk Search 04-15-2023
0 7
0
7
Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...