Splunk Search

Splunk Search
Community Activity
Taruchit
Hi All,I need your help to determine the details of issues which affect users while running SPL.The details may inclu...
by Taruchit Contributor in Splunk Search 12-05-2022
0 1
0
1
marco_massari11
Hi all, I need to extract some fields for authentication events from different log types, here below some example: LO...
by marco_massari11 Communicator in Splunk Search 12-05-2022
0 3
0
3
gregbo
I have two Splunk Enterprise environments, both at 9.0.2. For users in one environment, search history goes back only...
by gregbo Communicator in Splunk Search 12-05-2022
0 2
0
2
Jouman
Hi all,I am working on calculating the response time (for max, PR99, and avg value) from Table 1.I would like to list...
by Jouman Path Finder in Splunk Search 12-05-2022
0 5
0
5
Jouman
Hi all,I would like to highlight each fields in the same column in blue.But I don't know how to configure it.Do any o...
by Jouman Path Finder in Splunk Search 12-05-2022
0 0
0
0
phamxuantung
Hello,For starter, I'm an amateur in regex query, so I use Field Extraction, but it's very clunky and cannot extract ...
by phamxuantung Communicator in Splunk Search 12-05-2022
0 5
0
5
iupreti
I've field name opened_at with the date value shown in the image. But, while taking value from it, it returns a null ...
by iupreti Explorer in Splunk Search 12-04-2022
0 4
0
4
Splunk_321
Hi, I have a string in splunk logs something like below. msg.message="Matches Logs :: Logger{clientId='hFKfFkF-K7jlp5...
by Splunk_321 Path Finder in Splunk Search 12-04-2022
0 4
0
4
YangThomas
Currently using splunkes' managed lookup table called hosts. There's a field too called hostname within the file.I'm ...
by YangThomas New Member in Splunk Search 12-04-2022
0 1
0
1
balu1211
Hi, how to extract the field "alert" with the field name action. help with the regex.. Thanks.
by balu1211 Path Finder in Splunk Search 12-03-2022
0 24
0
24
ChadW
My query: index=primary eventType=ConnectionTest msg="network check results" | spath output=connectError details.erro...
by ChadW Explorer in Splunk Search 12-02-2022
0 3
0
3
coreyCLI
I recently added a new SH to our SHC.  Show shcluster-status is good, show kvstore-status is good.  I created some kv...
by coreyCLI Communicator in Splunk Search 12-02-2022
0 1
0
1
bandit
I'm wanting to group streamstats results by either one or two fields. Grouping by sourcetype would be sufficient. Gro...
by bandit Motivator in Splunk Search 12-02-2022
0 2
0
2
BabySplunk
Hello all! I am brand new to Splunk and have learned quite a bit so far from this forum, so thank you! With that bein...
by BabySplunk Explorer in Splunk Search 12-02-2022
0 15
0
15
dhirendra761
HI Splunkers, We are getting below value inside one of field "data" in tabular format: Source success Total_Count0 ab...
by dhirendra761 Contributor in Splunk Search 12-02-2022
0 8
0
8
csahoo
Hi ,i want to calculate count based on the condition , like in the below queryif the event is 'sync' then the 'failed...
by csahoo Explorer in Splunk Search 12-02-2022
0 5
0
5
dedupper
I'm trying to use the streamstats-command with time_window to track when certain user actions happen more than twice ...
by dedupper Explorer in Splunk Search 12-01-2022
0 4
0
4
BhushanGurav
Hi, I am working on use case which has following requirements 1. high number of connections to external DNS IPs from ...
by BhushanGurav Observer in Splunk Search 12-01-2022
0 3
0
3
csahoo
index="*dockerlogs*" source="*gps-request-processor-test*" OR source="*gps-external-processor-test*" OR source="*gps-...
by csahoo Explorer in Splunk Search 12-01-2022
0 2
0
2
bosseres
Hello everyone! I have basic search index=main| stats list(src.port), list(dst.port) count(src.ip) as COUNT by id How...
by bosseres Contributor in Splunk Search 12-01-2022
0 3
0
3
jhilton90
So I'm trying to turn a single value number into a percentage but the code just returns a number still. Here's my cod...
by jhilton90 Path Finder in Splunk Search 12-01-2022
0 9
0
9
SplunkDash
Hello, I have use cases to find the Delta between 2 sets of events. We get events once a day, our objective is to fin...
by SplunkDash Motivator in Splunk Search 12-01-2022
0 12
0
12
sekhar463
hi All,can you help with splunk search to get time only from date time.example as 2022/11/28 17:00:00 want to get onl...
by sekhar463 Path Finder in Splunk Search 12-01-2022
0 7
0
7
Nithianandan
Hello Splunkers, Workflows are monitored through splunk. Workflows has different stages like running , paused, cancel...
by Nithianandan Observer in Splunk Search 12-01-2022
0 2
0
2
harsush
index=XX sourcetype=YY source=*/log/abc.log| dedup _time, bppm_message, bppm_nodename sortby -_indextime| rex field=b...
by harsush Path Finder in Splunk Search 12-01-2022
0 3
0
3
Get Updates on the Splunk Community!

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...