Splunk Search

Splunk Search
Community Activity
bam22
In the below search I am looking for rules hit by count, but how or where would I add a NOT or !, if I wanted to know...
by bam22 Engager in Splunk Search 01-24-2023
0 1
0
1
rprior
I have six eventtype's that each check Juniper router logs for an Interface bounce (an up/down event). These are work...
by rprior Explorer in Splunk Search 01-24-2023
0 3
0
3
munang
I'm trying to get data by registering it as a Splunk script using Python code. But the problem only occurs when I run...
by munang Path Finder in Splunk Search 01-24-2023
0 2
0
2
ipteam
Hello Guys, I'd like to create a search based on business hours, and like to use a field with value like this: "2023/...
by ipteam Engager in Splunk Search 01-23-2023
0 5
0
5
anrak33
My data looks like the following  student_idbrowser_idguiddatetimex_id12_aChrome_211221/9/23 14:45788a13_aChrome_4121...
by anrak33 Explorer in Splunk Search 01-23-2023
0 7
0
7
spl_1991
Given the below scenario: base search| table service_name,status,count Service_name Status Count serviceA 500_IN...
by spl_1991 Engager in Splunk Search 01-23-2023
0 2
0
2
villnooB
Is it possible to assign a value to a different fields. I am trying to combine two different events but the same inde...
by villnooB Explorer in Splunk Search 01-23-2023
0 4
0
4
kyokkygo
Hi! I try to accelerate only one dataset in datamodel with multiple datasets. How i can do it through datamodel.conf ...
by kyokkygo Engager in Splunk Search 01-23-2023
0 2
0
2
poojithavasanth
Hello, I have a Regex for splitting a Person full name into Person lastname, firstname and middlename. Regex used: (?...
by poojithavasanth Explorer in Splunk Search 01-23-2023
0 5
0
5
sjaitly
I need to extract ITSI app version from app.conf fileTo display the data on a dashoboard I found a way sing the confi...
by sjaitly Engager in Splunk Search 01-23-2023
0 3
0
3
sjs
Hey people, I want to find out the total number of hours that elapsed from the last event raised.   This is what I wa...
by sjs Path Finder in Splunk Search 01-22-2023
0 1
0
1
Daksesh
The position of IP address is getting changed(appearing before or after https) in the logs, in such scenario how rege...
by Daksesh Explorer in Splunk Search 01-22-2023
0 5
0
5
splunkos
Hello!Can I ask something very basic as it will help me get started quickly?How can I structure a query to:1) group r...
by splunkos New Member in Splunk Search 01-22-2023
0 1
0
1
Stephcg
I have an application that have some instances/hosts. Because of change of throughput or instability new instances/ho...
by Stephcg Explorer in Splunk Search 01-21-2023
0 2
0
2
nikonjd
Hello, We have migrated from an app called Mirth to Splunk. With Mirth we used a tool called Interface Explorer for H...
by nikonjd New Member in Splunk Search 01-20-2023
0 1
0
1
cwl
間違ったデータがインデックスされてしまいましたが、どのようにインデックス内のデータを削除すれば良いでしょうか?
by cwl Contributor in Splunk Search 01-20-2023
3 3
3
3
DEADBEEF
I have a dashboard with a table with 6 headers.  I would like to bold the text of the second, fourth, and fifth colum...
by DEADBEEF Path Finder in Splunk Search 01-20-2023
0 15
0
15
ravida
Hi folks, I have a realtime search that looks at failed windows logins, producing a "single value" timechart visualiz...
by ravida Explorer in Splunk Search 01-20-2023
0 1
0
1
wangkevin1029
Hi, Splunkers, I have the following token handler,   if input "Gucid_token_with3handlers" is 2 digits number, it will...
by wangkevin1029 Communicator in Splunk Search 01-20-2023
0 2
0
2
vinothkumark
I have a field A which has percentage values. Also, I have a field B which has percentage values in it. Both are diff...
by vinothkumark Path Finder in Splunk Search 01-20-2023
0 3
0
3
Dharani
Hi, I need to show error messages for one particular service. But the challenge here is that for example , I need to ...
by Dharani Path Finder in Splunk Search 01-20-2023
0 2
0
2
tamduong16
I were able to append the count of each slice in the pie-chart to the back of each slice info. But I really want to d...
by tamduong16 Contributor in Splunk Search 01-20-2023
0 3
0
3
Nidd
I have some error logs like below:     TYPE=ERROR, DATE_TIME=2022-12-31 03:30:27,281, CLASS_NAME=myClass, METHOD_NAME...
by Nidd Path Finder in Splunk Search 01-20-2023
0 1
0
1
sumitnagal
I am using tstats command from a while, right now we want to make tstats command to limit record as we are using in k...
by sumitnagal Path Finder in Splunk Search 01-20-2023
0 6
0
6
belladonna
Hello! I want to make an error monitoring dashboard. I want to have a table with (operation| okOperations/allOperat...
by belladonna New Member in Splunk Search 01-20-2023
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...