Splunk Search

Splunk Search
Community Activity
x3ncrypt
There is a lookup table with a row called 'ip' containing multiple ip address values which I would like to correlate ...
by x3ncrypt Loves-to-Learn Everything in Splunk Search 01-08-2023
0 6
0
6
sc_admin11
I have uploaded the screenshots of logs of same time but in one log stack and task field is empty and in one it is fi...
by sc_admin11 Explorer in Splunk Search 01-08-2023
0 6
0
6
shruti14
index=mysql sourcetype=audit_log earliest=1| rex field=source "\/home\/mysqld\/(?<Database1>.*)\/audit\/"| rex ...
by shruti14 Explorer in Splunk Search 01-08-2023
0 6
0
6
SplunkDash
Hello, I have a few use cases to send data from SPLUNK to consumers in real time, and consumers have both Linux/Windo...
by SplunkDash Motivator in Splunk Search 01-07-2023
0 9
0
9
sekhar463
Hai All, from the below search  how to convert secs to HH:MM format  age fields is getting time in secs   index=_inte...
by sekhar463 Path Finder in Splunk Search 01-07-2023
0 3
0
3
scootsblue48
Hi, I have been looking to see if splunk has the capability of searching for loggins outside of a specified set time ...
by scootsblue48 New Member in Splunk Search 01-06-2023
0 2
0
2
DesertSocBum
I am trying to match results to ONLY the names in a list I have using a lookup.  I cant figure out for the life of me...
by DesertSocBum Explorer in Splunk Search 01-06-2023
0 6
0
6
dtarnaine920
Hi, I'm trying to come up with a query to generate the count of strings in a json field in a log, across all events. ...
by dtarnaine920 Explorer in Splunk Search 01-06-2023
0 5
0
5
add53
I'm fairly new to Splunk and I am having some trouble grouping somethings they way I want I have some data which all ...
by add53 Engager in Splunk Search 01-06-2023
0 2
0
2
aa0
Hi all,I have two similar words that giving the same meaning. How can I standardize them into one value to prevent in...
by aa0 Path Finder in Splunk Search 01-06-2023
0 3
0
3
Aj01
I am using a query and getting the logs but getting "**Setting up error code and description**" as the error message ...
by Aj01 Path Finder in Splunk Search 01-06-2023
0 4
0
4
MrIncredible
Query: index="web_app" (application= "abc-dxn-message-api" AND tracepoint= "START") (facility="d55075aaedc86d65776766...
by MrIncredible Explorer in Splunk Search 01-06-2023
0 4
0
4
sekhar463
Hi All, Good day, we have installed forwarders in multiple windows servers. any splunk search to know the memory usag...
by sekhar463 Path Finder in Splunk Search 01-06-2023
0 2
0
2
Julia1231
Hi, I want to check if all the value (from different fields) are < a, it will mark as yes. If one of them > a, it wil...
by Julia1231 Communicator in Splunk Search 01-06-2023
0 2
0
2
7ryota
Hi all, I have a inputlookup file named as leavers.csv which ill be automatically update this file contain the userID...
by 7ryota Explorer in Splunk Search 01-05-2023
0 1
0
1
phamxuantung
Hello,I'm using stats list() to merge all my value into one field, but I want them to seperate with each other by ";"...
by phamxuantung Communicator in Splunk Search 01-05-2023
0 1
0
1
vl951f
We had some feeds with host="unassigned". the following tstats will not return any result for some feeds, but it work...
by vl951f Path Finder in Splunk Search 01-05-2023
0 5
0
5
james_n
HI, I have a simple query i.e |timechart count by something The span should change dynamically, for EX: if I selec...
by james_n Path Finder in Splunk Search 01-05-2023
0 5
0
5
kmarx
I'm trying to optimize execution of a custom command by caching information it processes, but just for the duration o...
by kmarx Explorer in Splunk Search 01-05-2023
0 1
0
1
BongoNations
Hi I have this SPL query but getting this error? Error in 'rename' command: Usage: rename [old_name AS/TO/-> new_name...
by BongoNations Explorer in Splunk Search 01-05-2023
0 1
0
1
arkadyz1
I have made a custom search command which accepts some values, forms a network request and submits it. It works great...
by arkadyz1 Builder in Splunk Search 01-05-2023
2 3
2
3
pinVie
Hi all, I am currently a little bit stuck ... Commands.conf looks like this:[tc]chunked = truefilename = tc.py [t]ret...
by pinVie Path Finder in Splunk Search 01-05-2023
0 7
0
7
zoe
Hi,  If I want to show the percentage, then I use  <option name="charting.chart.showPercent">true</option> but if I w...
by zoe Path Finder in Splunk Search 01-05-2023
0 1
0
1
mikecal
I'm trying to use the following search to capture information regarding an identification code:   index=calabrio MSG_...
by mikecal Explorer in Splunk Search 01-05-2023
0 3
0
3
Dzmitry
Hi guys, I have a search for the host with check_id statuses: index="..." exec_mode="..." host="..."  check_id="..." ...
by Dzmitry Explorer in Splunk Search 01-05-2023
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...