Splunk Search

Splunk Search
Community Activity
queriousGeorge
I have two searches that will return orderNumbers 1.index=main "Failed insert" | table orderNumber//returns small lis...
by queriousGeorge Engager in Splunk Search 02-14-2023
0 3
0
3
power12
Hello Splunkers,I have a field called state_sinfo which have values like (up,up*,up$,up^,continue,continue$,continued...
by power12 Communicator in Splunk Search 02-14-2023
0 1
0
1
akpuvvada
I am trying to find entries between a date-time range based on a field in the event 'Date'. It date-time value of the...
by akpuvvada Engager in Splunk Search 02-14-2023
0 1
0
1
nomad1981
Hi, I'm trying to build a line graph that would show me the completion time of an event on a daily basis. The complet...
by nomad1981 Explorer in Splunk Search 02-14-2023
0 3
0
3
erikschubert
Hey everyone,I want to create a search that gives me the following information in a structured way: Which type of hos...
by erikschubert Engager in Splunk Search 02-14-2023
0 3
0
3
gazoscreek
I need to provide audit details on our ES Content Library. Using rest, I can identify searches that have been updated...
by gazoscreek Path Finder in Splunk Search 02-14-2023
0 1
0
1
joock3r
Hi, I have a lookup definition that look like that: When I'm running this search with looking up in this lookup difi...
by joock3r Explorer in Splunk Search 02-14-2023
0 1
0
1
zacksoft_wf
I want to write a rex to extract values in a field that are delimited by comma. index=group sourcetype="ext:user_acco...
by zacksoft_wf Contributor in Splunk Search 02-14-2023
0 4
0
4
villnooB
HiGreatly appreciate your help, would like to know if there is any way i could filter out a value based from another ...
by villnooB Explorer in Splunk Search 02-14-2023
0 1
0
1
max8006
Hi,I have logs separated by a tab. I have defined FIELD_DELIMITER=tab, INDEXED_EXTRACTIONS=tsv FIELD_NAMES etc in pro...
by max8006 Explorer in Splunk Search 02-14-2023
0 1
0
1
rvillaflores
Hi, I'm trying to extract logs via API using /v2/event/find Found here: Retrieve Events V2 | API Reference | Splunk D...
by rvillaflores Loves-to-Learn in Splunk Search 02-14-2023
0 0
0
0
disasters
My query is this.   index=log AND 1378   There are two event   20230112, 1378, error A/B/C, duration 100 20230112, 13...
by disasters Explorer in Splunk Search 02-13-2023
0 7
0
7
drathbo
Good afternoon, I'm looking for a way to track impossible travel events for users who are logging in to applications ...
by drathbo New Member in Splunk Search 02-13-2023
0 3
0
3
ak9092
Not sure if this is possible through Splunk query but what i am trying to do is basically retrieve field value from o...
by ak9092 Path Finder in Splunk Search 02-13-2023
0 1
0
1
marco_massari11
Hi, I have different mails in my logs and I need to filter them in order to distinguish real users from technical use...
by marco_massari11 Communicator in Splunk Search 02-13-2023
0 1
0
1
ssharma
I am new to slunk, I have to create one dashboard and compare current day with same day of last week based on request...
by ssharma Loves-to-Learn Lots in Splunk Search 02-13-2023
0 5
0
5
neerajs_81
Hi All, My Dashboard panel which calls a report search is showing "Search did not return any events." When i click on...
by neerajs_81 Builder in Splunk Search 02-13-2023
0 4
0
4
sukansingh
I have a query and at the end I want to sort the data by specific column But column is dynamically generated. i can g...
by sukansingh Explorer in Splunk Search 02-13-2023
0 5
0
5
buttsurfer
  index=index1 type=1 feature IN ([search index=index1 type=type2 application=weather_app | dedup feature | f...
by buttsurfer Path Finder in Splunk Search 02-12-2023
0 2
0
2
pavanae
I have a field called folder_path which gives the values as follows. folder_path\Device\XYZ\Users\user_A\AppData\prog...
by pavanae Builder in Splunk Search 02-12-2023
0 3
0
3
buttsurfer
I have a user table which shows which department each user belongs to. I want to join this with another table on User...
by buttsurfer Path Finder in Splunk Search 02-12-2023
0 3
0
3
Chris231289
Hello i am new I have combined data from cyclogs,adserver logs and firewall logs how can i search for data that happe...
by Chris231289 Loves-to-Learn Lots in Splunk Search 02-12-2023
0 4
0
4
buttsurfer
The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with...
by buttsurfer Path Finder in Splunk Search 02-12-2023
0 1
0
1
tb5821
rex field=title "(?titleNEW(.*?)(?:-))" I have this rex command above but it still outputs the dash at the end which...
by tb5821 Communicator in Splunk Search 02-11-2023
0 2
0
2
szabados
I want to use a lookup table, but every time, I add the command to my search "| lookup name_of_my_lookup", I'm gettin...
by szabados Communicator in Splunk Search 02-10-2023
1 5
1
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...