Splunk Search

Splunk Search
Community Activity
aa0
Hi all,I want to extract the following word with rex expression:ABC\qq1234 expected result: qq1234Please note that th...
by aa0 Path Finder in Splunk Search 01-09-2023
0 2
0
2
niks987
Happy New Year to all of you. So I have syslog in which we have details of the devices and switches. The requirement ...
by niks987 Explorer in Splunk Search 01-09-2023
0 0
0
0
vineela
i need to extract fields which are in json format i have been trying using spath command for extracting the following...
by vineela Path Finder in Splunk Search 01-09-2023
0 8
0
8
Rakzskull
I'd want to merge two regex strings into a single one; any suggestions would be greatly appreciated.Reference Search ...
by Rakzskull Path Finder in Splunk Search 01-09-2023
0 2
0
2
Jagadeesh2022
Hi Friends, My requirement: I want to trigger SNOW ticket from Splunk alert. Before trigger I want to check any open ...
by Jagadeesh2022 Path Finder in Splunk Search 01-09-2023
0 5
0
5
martinhelgegren
Hi! I have various syslog clients sending me logs about their current state (a certain process). Eg. [timestamp] host...
by martinhelgegren Explorer in Splunk Search 01-08-2023
0 8
0
8
x3ncrypt
There is a lookup table with a row called 'ip' containing multiple ip address values which I would like to correlate ...
by x3ncrypt Loves-to-Learn Everything in Splunk Search 01-08-2023
0 6
0
6
sc_admin11
I have uploaded the screenshots of logs of same time but in one log stack and task field is empty and in one it is fi...
by sc_admin11 Explorer in Splunk Search 01-08-2023
0 6
0
6
shruti14
index=mysql sourcetype=audit_log earliest=1| rex field=source "\/home\/mysqld\/(?<Database1>.*)\/audit\/"| rex ...
by shruti14 Explorer in Splunk Search 01-08-2023
0 6
0
6
SplunkDash
Hello, I have a few use cases to send data from SPLUNK to consumers in real time, and consumers have both Linux/Windo...
by SplunkDash Motivator in Splunk Search 01-07-2023
0 9
0
9
sekhar463
Hai All, from the below search  how to convert secs to HH:MM format  age fields is getting time in secs   index=_inte...
by sekhar463 Path Finder in Splunk Search 01-07-2023
0 3
0
3
scootsblue48
Hi, I have been looking to see if splunk has the capability of searching for loggins outside of a specified set time ...
by scootsblue48 New Member in Splunk Search 01-06-2023
0 2
0
2
DesertSocBum
I am trying to match results to ONLY the names in a list I have using a lookup.  I cant figure out for the life of me...
by DesertSocBum Explorer in Splunk Search 01-06-2023
0 6
0
6
dtarnaine920
Hi, I'm trying to come up with a query to generate the count of strings in a json field in a log, across all events. ...
by dtarnaine920 Explorer in Splunk Search 01-06-2023
0 5
0
5
add53
I'm fairly new to Splunk and I am having some trouble grouping somethings they way I want I have some data which all ...
by add53 Engager in Splunk Search 01-06-2023
0 2
0
2
aa0
Hi all,I have two similar words that giving the same meaning. How can I standardize them into one value to prevent in...
by aa0 Path Finder in Splunk Search 01-06-2023
0 3
0
3
Aj01
I am using a query and getting the logs but getting "**Setting up error code and description**" as the error message ...
by Aj01 Path Finder in Splunk Search 01-06-2023
0 4
0
4
MrIncredible
Query: index="web_app" (application= "abc-dxn-message-api" AND tracepoint= "START") (facility="d55075aaedc86d65776766...
by MrIncredible Explorer in Splunk Search 01-06-2023
0 4
0
4
sekhar463
Hi All, Good day, we have installed forwarders in multiple windows servers. any splunk search to know the memory usag...
by sekhar463 Path Finder in Splunk Search 01-06-2023
0 2
0
2
Julia1231
Hi, I want to check if all the value (from different fields) are < a, it will mark as yes. If one of them > a, it wil...
by Julia1231 Communicator in Splunk Search 01-06-2023
0 2
0
2
7ryota
Hi all, I have a inputlookup file named as leavers.csv which ill be automatically update this file contain the userID...
by 7ryota Explorer in Splunk Search 01-05-2023
0 1
0
1
phamxuantung
Hello,I'm using stats list() to merge all my value into one field, but I want them to seperate with each other by ";"...
by phamxuantung Communicator in Splunk Search 01-05-2023
0 1
0
1
vl951f
We had some feeds with host="unassigned". the following tstats will not return any result for some feeds, but it work...
by vl951f Path Finder in Splunk Search 01-05-2023
0 5
0
5
james_n
HI, I have a simple query i.e |timechart count by something The span should change dynamically, for EX: if I selec...
by james_n Path Finder in Splunk Search 01-05-2023
0 5
0
5
kmarx
I'm trying to optimize execution of a custom command by caching information it processes, but just for the duration o...
by kmarx Explorer in Splunk Search 01-05-2023
0 1
0
1
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...