Splunk Search

Splunk Search
Community Activity
itsmevic70
    index=servicenow assignment_group_name="security" status=* | stats count by number,status,group_name,created_on  ...
by itsmevic70 Explorer in Splunk Search 01-16-2023
0 2
0
2
vishal_pcap
How can I write a query like following? index=my_app| eval userError="Error while fetching User"| eval addressError =...
by vishal_pcap Explorer in Splunk Search 01-16-2023
0 10
0
10
pratibha0610
Hi all, Could some please help me with this query. I have 3 different sources from which i want to match the fields. ...
by pratibha0610 Explorer in Splunk Search 01-16-2023
0 1
0
1
sekhar463
hai All, i have events like below  from how can i filter events if for ex: 6th character in C*E**M  IS M want to filt...
by sekhar463 Path Finder in Splunk Search 01-16-2023
0 6
0
6
charlix
Seeing different results when performing similiar searches and not sure on the reason.  base search is the same for b...
by charlix Engager in Splunk Search 01-16-2023
0 2
0
2
quangtran
Hi,I have the below output :1/16/2023 7:51:43 AM 1EE8 PACKET 000001D9C25E6180 UDP Rcv 10.8.64.132 646b Q [0001 D NOER...
by quangtran Explorer in Splunk Search 01-15-2023
0 2
0
2
auzelevski
Hello, I have the following query in one of the panels in my dashboard.       | mstats p95(prometheus.container_memor...
by auzelevski Explorer in Splunk Search 01-15-2023
0 0
0
0
bwyn
I have a significant number of dashboards that use dbxquery to pull data from a significant number of servers running...
by bwyn Observer in Splunk Search 01-14-2023
0 2
0
2
amorales_splunk
I want to use the dedup command and see which values it removes from a field. Is this possible?
by amorales_splunk Splunk Employee Splunk Employee in Splunk Search 01-13-2023
0 2
0
2
trilocho
I have events like below-a3bcd: Info1234x:NullValue-a3bcd: Info1234x:NullValue-b3bcd: Info1234x:NullValue2-c3bcd: Inf...
by trilocho Loves-to-Learn in Splunk Search 01-13-2023
0 2
0
2
Babuduraiswamy
Hi,  I looking for rex sed cmd to extract the value from the field.eg:  input field1 = d:\AppDynamics\machineagent\ve...
by Babuduraiswamy Engager in Splunk Search 01-13-2023
0 3
0
3
commanman
Hey there Splunk hero's, Story/Background: So, there is this variable called "src_ip" in my correlation search. The "...
by commanman Explorer in Splunk Search 01-13-2023
0 8
0
8
buttsurfer
 I want to run this search but i have to concatenate the string with a variable and it doesn't work      | rest splun...
by buttsurfer Path Finder in Splunk Search 01-13-2023
0 5
0
5
runiyal
Hello All, I have following lines in the log file -   Server8 runiyal 2023-01-12 09:48:41,880 INFO Plugin.DOCUMENT By...
by runiyal Path Finder in Splunk Search 01-12-2023
0 3
0
3
sjs
Hey people, my requirement is as such I have extracted these columns from my data using the query my query | rex "fil...
by sjs Path Finder in Splunk Search 01-12-2023
0 4
0
4
jayygee3
I'm hoping to get some help or direction. I have seen a few different forum posts where the search pulled how many co...
by jayygee3 Engager in Splunk Search 01-12-2023
0 2
0
2
splunkuser320
Hi, Not sure what the issue is. I got the solution from the other answers, but it's not working for me.I am getting d...
by splunkuser320 Path Finder in Splunk Search 01-12-2023
0 1
0
1
Neonbeeflash
I want to create alert to check on all indexes event count and alert the list of all indexes that have no events in t...
by Neonbeeflash Explorer in Splunk Search 01-12-2023
0 4
0
4
buttsurfer
I have a search that outputs a table like below          user  |  host  |  app-------------------------------------  ...
by buttsurfer Path Finder in Splunk Search 01-12-2023
0 3
0
3
siksaw33
2023-01-09T16:46:00.780076351Z app_name=default-java environment=e3 ns=one pod_container=default-java pod_name=defaul...
by siksaw33 Path Finder in Splunk Search 01-12-2023
0 4
0
4
buttsurfer
 I have a SPL search that returns a field with multiple values (names of lookups). I want to concat the lookup name a...
by buttsurfer Path Finder in Splunk Search 01-12-2023
0 2
0
2
Wonjon
I would like to fit an ARIMA model to my data with a search something like this: <base search>| timechart span=5m avg...
by Wonjon Observer in Splunk Search 01-12-2023
0 0
0
0
pp3295
hi all, we  are creating one dashboard having two tables , in that we have set different folder locations for monitor...
by pp3295 Explorer in Splunk Search 01-12-2023
0 6
0
6
TBH0
Hey all, I'm attempting to compare a variable (we'll call it cDOW), which is set to (strftime(now(), "%A")),  to a DO...
by TBH0 Explorer in Splunk Search 01-11-2023
0 5
0
5
pm771
HelloI have a Splunk query that looks like following: index=something "*abc*" OR "*def*" OR "*hig*"  These substrings...
by pm771 Communicator in Splunk Search 01-11-2023
0 2
0
2
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...