Splunk Search

Splunk Search
Community Activity
David_M
I am VERY new to splunk so please bear with me.  I have a search, index=vulnerability "list of packages installed on ...
by David_M Explorer in Splunk Search 11-18-2022
0 2
0
2
anu41
I need to create a Dashboard with below columns  from below event data.   I couldn't able to get "Status" column valu...
by anu41 Explorer in Splunk Search 11-18-2022
0 6
0
6
cbrbkrm
Let's say we have couple of fields in our dataset (called my_dataset) : event_time, event_type, user, field1 and fiel...
by cbrbkrm Loves-to-Learn in Splunk Search 11-18-2022
0 1
0
1
jip31
hello Why doesn't my post process search work when using timechart command?     <search id="cap"> <query> `...
by jip31 Motivator in Splunk Search 11-17-2022
0 17
0
17
wangkevin1029
Hi, Splunkers,    I  want to search string like abc/efg in my log using  multiselect field.  I directly defined this ...
by wangkevin1029 Communicator in Splunk Search 11-17-2022
0 2
0
2
vagnet
Hi Splunkers, I want to create a macro that will be looking inside a lookup file, but in a way that will not break th...
by vagnet Explorer in Splunk Search 11-17-2022
0 4
0
4
adent
I am trying to add a field to a search using a lookup table. However, my key field  is sometimes blank and I get an e...
by adent Explorer in Splunk Search 11-17-2022
0 1
0
1
hermitfeather
Hello!I currently have this eval in a search of mine:   | eval exists=if(like(_raw, "%xa recovery%"), 0, 1)   Is ther...
by hermitfeather Loves-to-Learn in Splunk Search 11-17-2022
0 2
0
2
karu0711
I want to be the order I list below?Very High High MediumLowVery Low Info
by karu0711 Communicator in Splunk Search 11-17-2022
0 2
0
2
jip31
hi as you can see I use a relative time in my search in order to filter events on today between 7h and 19h   earliest...
by jip31 Motivator in Splunk Search 11-17-2022
0 3
0
3
metylkinandrey
Good afternoon, I have already raised a similar topic. The last time I was cleared up the situation, but the problem ...
by metylkinandrey Communicator in Splunk Search 11-17-2022
0 9
0
9
msarro
We have a data source which contains two columns, both of which contain valuable information. In any event, either on...
by msarro Builder in Splunk Search 11-17-2022
1 8
1
8
noammeir
hiI am trying to get my dashboard better and move all of the different searches to a single/couple of base searches a...
by noammeir Explorer in Splunk Search 11-17-2022
0 3
0
3
directtv999
sample json: Hosts: { [-]   Nodepool1: { [-]       Cluster: xyz1       Accountid: idxyz   Nodepool3: { [-]      Clust...
by directtv999 Loves-to-Learn Lots in Splunk Search 11-17-2022
0 7
0
7
sc_admin11
i am trying to create a custom field like host and source by making changes in atteched  photos of entrypoint.sh and ...
by sc_admin11 Explorer in Splunk Search 11-16-2022
0 0
0
0
JyotiP
I have the following query :sourcetype="docker" AppDomain=Eos Level=INFO Message="Eos request calculated" | eval Val_...
by JyotiP Path Finder in Splunk Search 11-16-2022
0 3
0
3
YatMan
Sample event   { durationMs: 83 properties: { url: https://mywebsite/v1/organization/41547/bui...
by YatMan Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunky21
Hi all, I'm attempting to develop a regex that will pick up on a value contained in [ ] brackets (see below): Log val...
by Splunky21 Explorer in Splunk Search 11-16-2022
0 2
0
2
judges88
Trying to get these UUID/GUIDs to extract from the message field. Hoping to create a rex to extract everything after ...
by judges88 Explorer in Splunk Search 11-16-2022
0 5
0
5
JohnnyMnemonic
I have read all the posts about "merging fields" and none of the options work for me. I have events where the same va...
by JohnnyMnemonic Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunkstart
Hi All, these are the logger info counts which are generated in splunk  Total numner where inds-a 20Total numner wher...
by Splunkstart Explorer in Splunk Search 11-16-2022
0 4
0
4
jip31
hi I want to not display the week end in my chart for example, if i use a time picler range of 7 days, I just want to...
by jip31 Motivator in Splunk Search 11-16-2022
0 11
0
11
anu41
I am having issue with "Status" values as below and screenshot, please find below json and search query. Please advis...
by anu41 Explorer in Splunk Search 11-16-2022
0 2
0
2
SumanPalisetty
Hi,Sometimes if we are doing base search, if not handled properly, you will see page loading, how do you handle it?Re...
by SumanPalisetty Path Finder in Splunk Search 11-16-2022
0 1
0
1
Abdullah
Dears,   We need your support to convert below search to tstats search. (index=os_windows OR index=workstation*) tag=...
by Abdullah Explorer in Splunk Search 11-16-2022
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors