Splunk Search

Splunk Search
Community Activity
Derson
When I use walklex on my indexes, it doesn't appear to be following the time specifications very well. Does anybody k...
by Derson Explorer in Splunk Search 01-29-2023
0 0
0
0
andyfromoz
We have a particular file of the format: Field1, Field2, Timestamp field, Field4, Field5, Number of records, Field7 ...
by andyfromoz Explorer in Splunk Search 01-28-2023
1 4
1
4
Vani_26
Hi allwhen i run my original query i am getting one result and when i execute the same query using tstats i am gettin...
by Vani_26 Path Finder in Splunk Search 01-28-2023
0 3
0
3
axelmunoz
Hey all! I have a saved search that runs on a schedule and generates those "artifacts", I know I can access a specifi...
by axelmunoz New Member in Splunk Search 01-28-2023
0 3
0
3
mohdmikhael
Hi,I recently came across this warning on Splunk web and was just wondering if anyone else has encountered this befor...
by mohdmikhael Explorer in Splunk Search 01-27-2023
0 3
0
3
batham
Hi, My Strptime function is not working for the below format. date format: 1/13/23 11:44:11.543 AM eval  time_epoc= s...
by batham Explorer in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
Currently I have an inputlookup csv that contains a list of IP addresses and lookup csv that has a list of subnets. I...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
I'm doing a search for server names and will eventually extract to to a csv. However, each result comes out as one of...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 4
0
4
pjanssen007
I'm trying to filter out events like the ones below using the regex expression regex _raw!="^[A-Za-z0-9]{4}:.*$"   bu...
by pjanssen007 Explorer in Splunk Search 01-27-2023
0 6
0
6
qcjacobo2577
Currently running Splunk Universal Forwarder version 9.0.3. Looking to ignore Windows event logs (EventCode = 4103) u...
by qcjacobo2577 Path Finder in Splunk Search 01-27-2023
0 14
0
14
finchy
Hi Is there a way to search across multiple Lookup files to find text within them ?  I know that you can use | inputl...
by finchy Explorer in Splunk Search 01-27-2023
0 4
0
4
bapun18
I want to disable the feature of save as, user can able to search but shouldn't be able to save it as a dashboard or ...
by bapun18 Communicator in Splunk Search 01-27-2023
0 2
0
2
jip12048
Hi all, I am new to Spluntk and have problem with my search. I have a Lookup table: Error.csv Filter*Error1**Error2**...
by jip12048 Engager in Splunk Search 01-27-2023
0 1
0
1
kalaiyarasi
|eval TotalApps=if(match('Total',"NTB"),"1","0") |eval In-Progress=if('Total'="NTB" AND isnull('APPL_SUB-DATE'),"1","...
by kalaiyarasi Loves-to-Learn Lots in Splunk Search 01-27-2023
0 5
0
5
amitrinx
I have 2 events having fields1. id_cse_event: sqsmessageid,timestamp2. Scim: sqs_message_id, timestamp.I want to sear...
by amitrinx Explorer in Splunk Search 01-27-2023
0 3
0
3
sdhiaeddine
Hi,Please could you help with parsing this json data to table       { "list_element": [ { "element": "{\"var1\"...
by sdhiaeddine Explorer in Splunk Search 01-26-2023
0 5
0
5
Macky_29
Dear experts , I am searching on my bot index, which contain conve-id and rest of the fields are stored as payload. U...
by Macky_29 Explorer in Splunk Search 01-26-2023
0 5
0
5
prasant
I have sample.csv file with about 30000 rows with columns: sample data data  value1   value25600012345   abc xxx7890...
by prasant Path Finder in Splunk Search 01-26-2023
0 5
0
5
michaeler
I feel like I'm dancing circles around the solution to this problem. I created a field named "Duration" with rex that...
by michaeler Communicator in Splunk Search 01-26-2023
0 1
0
1
Skeer-Jamf
So after searching here it seems like a lot of people have trouble parsing/handling WinEventLogs. I want to ask if th...
by Skeer-Jamf Path Finder in Splunk Search 01-26-2023
0 6
0
6
cdieringerwm
Greetings. My Splunk instance parses messages which has a JSON array type: ```{ tags: ["info", "foo", "bar"] }```Let'...
by cdieringerwm Observer in Splunk Search 01-26-2023
0 1
0
1
security_mike
Hi All, I'm pretty new to Splunk so forgive me if this is an easy question. I'm trying to figure out how to a) search...
by security_mike Explorer in Splunk Search 01-26-2023
0 4
0
4
jason_hotchkiss
I have a horizontal bar chart usingthe following post processing search:| stats count by urgency| eval urgency = if(u...
by jason_hotchkiss Communicator in Splunk Search 01-26-2023
0 3
0
3
michaeler
I am trying to determine the average time for a set of issues to get resolved. I already created a field named "Durat...
by michaeler Communicator in Splunk Search 01-26-2023
0 3
0
3
Cyberguru
Query doesnt bring up anything. Try to pull RDP connections in my environment:      event_simpleName=UserLogon LogonT...
by Cyberguru Engager in Splunk Search 01-26-2023
0 2
0
2
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...
Top Solution Authors