Splunk Search

Splunk Search
Community Activity
splunkuser320
I want to change the column cell background based on the value, but I also want to use a wild card.Example Field valu...
by splunkuser320 Path Finder in Splunk Search 12-05-2022
0 3
0
3
cclva
I have two indexes: IndexA has a `thisId` field. IndexB has fields `otherId` and `name`. I want to write a query whic...
by cclva Explorer in Splunk Search 12-05-2022
0 3
0
3
Manasa_401
Hello Splunkers!!We have a dashboard which works on the loadjob. When users try accessing the dashboard, they are get...
by Manasa_401 Communicator in Splunk Search 12-05-2022
0 4
0
4
pmittal
raw event {... "jvm_cmd":"bin/java -Dp -Dp1=v1-Dp2=v2 -Dq -Dp3=v3 ..."} How to extract, kv pair from jvm_cmd value & ...
by pmittal Engager in Splunk Search 12-05-2022
0 13
0
13
splunklearner99
Hello Champs I've index data table change records errors B221205A1090B221205B14800B221205C33360B221205D25818 I also h...
by splunklearner99 Engager in Splunk Search 12-05-2022
0 1
0
1
indeed_2000
Hi Need to send alert like machine investigate something and after that send alert. I mean something like gptchat tal...
by indeed_2000 Motivator in Splunk Search 12-05-2022
0 0
0
0
Taruchit
Hi All,I need your help to determine the details of issues which affect users while running SPL.The details may inclu...
by Taruchit Contributor in Splunk Search 12-05-2022
0 1
0
1
marco_massari11
Hi all, I need to extract some fields for authentication events from different log types, here below some example: LO...
by marco_massari11 Communicator in Splunk Search 12-05-2022
0 3
0
3
gregbo
I have two Splunk Enterprise environments, both at 9.0.2. For users in one environment, search history goes back only...
by gregbo Communicator in Splunk Search 12-05-2022
0 2
0
2
Jouman
Hi all,I am working on calculating the response time (for max, PR99, and avg value) from Table 1.I would like to list...
by Jouman Path Finder in Splunk Search 12-05-2022
0 5
0
5
Jouman
Hi all,I would like to highlight each fields in the same column in blue.But I don't know how to configure it.Do any o...
by Jouman Path Finder in Splunk Search 12-05-2022
0 0
0
0
phamxuantung
Hello,For starter, I'm an amateur in regex query, so I use Field Extraction, but it's very clunky and cannot extract ...
by phamxuantung Communicator in Splunk Search 12-05-2022
0 5
0
5
iupreti
I've field name opened_at with the date value shown in the image. But, while taking value from it, it returns a null ...
by iupreti Explorer in Splunk Search 12-04-2022
0 4
0
4
Splunk_321
Hi, I have a string in splunk logs something like below. msg.message="Matches Logs :: Logger{clientId='hFKfFkF-K7jlp5...
by Splunk_321 Path Finder in Splunk Search 12-04-2022
0 4
0
4
YangThomas
Currently using splunkes' managed lookup table called hosts. There's a field too called hostname within the file.I'm ...
by YangThomas New Member in Splunk Search 12-04-2022
0 1
0
1
balu1211
Hi, how to extract the field "alert" with the field name action. help with the regex.. Thanks.
by balu1211 Path Finder in Splunk Search 12-03-2022
0 24
0
24
ChadW
My query: index=primary eventType=ConnectionTest msg="network check results" | spath output=connectError details.erro...
by ChadW Explorer in Splunk Search 12-02-2022
0 3
0
3
coreyCLI
I recently added a new SH to our SHC.  Show shcluster-status is good, show kvstore-status is good.  I created some kv...
by coreyCLI Communicator in Splunk Search 12-02-2022
0 1
0
1
bandit
I'm wanting to group streamstats results by either one or two fields. Grouping by sourcetype would be sufficient. Gro...
by bandit Motivator in Splunk Search 12-02-2022
0 2
0
2
BabySplunk
Hello all! I am brand new to Splunk and have learned quite a bit so far from this forum, so thank you! With that bein...
by BabySplunk Explorer in Splunk Search 12-02-2022
0 15
0
15
dhirendra761
HI Splunkers, We are getting below value inside one of field "data" in tabular format: Source success Total_Count0 ab...
by dhirendra761 Contributor in Splunk Search 12-02-2022
0 8
0
8
csahoo
Hi ,i want to calculate count based on the condition , like in the below queryif the event is 'sync' then the 'failed...
by csahoo Explorer in Splunk Search 12-02-2022
0 5
0
5
dedupper
I'm trying to use the streamstats-command with time_window to track when certain user actions happen more than twice ...
by dedupper Explorer in Splunk Search 12-01-2022
0 4
0
4
BhushanGurav
Hi, I am working on use case which has following requirements 1. high number of connections to external DNS IPs from ...
by BhushanGurav Observer in Splunk Search 12-01-2022
0 3
0
3
csahoo
index="*dockerlogs*" source="*gps-request-processor-test*" OR source="*gps-external-processor-test*" OR source="*gps-...
by csahoo Explorer in Splunk Search 12-01-2022
0 2
0
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors