Splunk Search

Splunk Search
Community Activity
Tioluwani-Ada
I am a beginner. Why is stats avg(response_time) not working after extracting response_time? index="testing1" source=...
by Tioluwani-Ada Engager in Splunk Search 03-28-2023
0 2
0
2
atebysandwich
I'm pretty sure the answer to my question is regex but I'm not too savy with it. I have a few values in an IP field f...
by atebysandwich Path Finder in Splunk Search 03-28-2023
0 3
0
3
mldavis195
I have some JSON that looks similar to this:     { "foo": "bar", "x": { "hello": "world", "y"...
by mldavis195 Explorer in Splunk Search 03-28-2023
0 2
0
2
priya1926
Hi Team,   I need a rex command to extract subject field from the event _raw.. Currently i am splitting the fields wi...
by priya1926 Path Finder in Splunk Search 03-28-2023
0 4
0
4
yohhpark
Let say I have a result belowindex = indextestsource=stestbunch of evals = evalssourcetype=sttext| table ID Status Re...
by yohhpark Path Finder in Splunk Search 03-28-2023
0 6
0
6
salv1
Hello fellow splunkers, I'm posting here because I would gladly have help with the following query. Let's say I have ...
by salv1 Engager in Splunk Search 03-28-2023
0 1
0
1
DPOIRE
I have this search that is working and returning a average Delay value:Search Command | eval epoch_timestamp=strptime...
by DPOIRE Path Finder in Splunk Search 03-28-2023
0 3
0
3
sarit_s
Hello I need to add alert action to many alerts,Is it possible to add the same action to all of the alerts in one tim...
by sarit_s Communicator in Splunk Search 03-28-2023
0 1
0
1
michaelnorup
My regex from the message field looks like this.   | rex field=Message "\W(?<Hostname>\S+)\s\w+\W(?<Build>\S+)\s\w+\W...
by michaelnorup Communicator in Splunk Search 03-28-2023
0 4
0
4
klay824
Hi, I have a query that is making two different searches and displaying the stats of each. Example:index="example" TE...
by klay824 Explorer in Splunk Search 03-28-2023
0 6
0
6
TrangCIC81
Hello All, I have been able to create a table that lists the top users that have been uploading files the most to clo...
by TrangCIC81 Communicator in Splunk Search 03-28-2023
0 4
0
4
drogo
Hello, I want to extract fiends from below log format. Can someone please help. Log format - 2023-03-21 04:14:13.859,...
by drogo Explorer in Splunk Search 03-27-2023
0 5
0
5
chrisschum
We have a standard configuration for our workstations. Several of the fields are static but some are dynamic (but the...
by chrisschum Path Finder in Splunk Search 03-27-2023
0 2
0
2
woodlandrelic
HI  So I have this dashboard showing the below.  HBSS      ACAS        CMRSACAS    CMRSHBSS89              92        ...
by woodlandrelic Path Finder in Splunk Search 03-27-2023
0 2
0
2
yohhpark
Search 1. | inputlookup test1.csv | table ITEM1 ITEM2   Search 2. | inputlookup test2.csv | table ITEM 1 ITEM3   Conc...
by yohhpark Path Finder in Splunk Search 03-27-2023
0 4
0
4
apignata
I have the following JSON structure in my events. I am trying to figure out an SPL Query to format the JSON in a tabl...
by apignata Explorer in Splunk Search 03-27-2023
0 1
0
1
vickycoder27
I have a curl response which is json string[], I am able to fetch the data using split(), mvexpand() and then substri...
by vickycoder27 Explorer in Splunk Search 03-26-2023
0 4
0
4
itsmevic
I'm running the below query to find out when was the last time an index checked in. However, in using this query the ...
by itsmevic Communicator in Splunk Search 03-26-2023
0 5
0
5
bt149
I have a log set from FW's. These logs have a field called "src."  From what I can tell, this field is populated with...
by bt149 Path Finder in Splunk Search 03-25-2023
0 4
0
4
SplunkNewbie100
Hi all,   I  want to replace random substrings in path: C:\Users\sjfklsj\Appdata\.... -> C:\Users\---\Appdata\.... C:...
by SplunkNewbie100 New Member in Splunk Search 03-25-2023
0 2
0
2
bosseres
Hello everyone In the result of my search I got such results (last command was stats values(list) as list, values(sta...
by bosseres Contributor in Splunk Search 03-25-2023
0 3
0
3
Sven1
I am working to merge two searches. The first search outputs one or more account names:     index=x sourcetype=y | ta...
by Sven1 Path Finder in Splunk Search 03-24-2023
0 12
0
12
Abhineet
Hi,  looking for splunk query having field name similar to field in lookup file with respective value in lookup file....
by Abhineet Loves-to-Learn Everything in Splunk Search 03-24-2023
0 6
0
6
pierre_weg
Hello fellows!I have a sourcetype called cmdb with a field called BIA to any src_host. After this join index=lab sour...
by pierre_weg Path Finder in Splunk Search 03-24-2023
0 6
0
6
Veeru
Actually I want to pass the time from first query to second and get results out on basis of first query time.First qu...
by Veeru Path Finder in Splunk Search 03-24-2023
0 1
0
1
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...