Splunk Search

Splunk Search
Community Activity
jip31
hello Why doesn't my post process search work when using timechart command?     <search id="cap"> <query> `...
by jip31 Motivator in Splunk Search 11-17-2022
0 17
0
17
wangkevin1029
Hi, Splunkers,    I  want to search string like abc/efg in my log using  multiselect field.  I directly defined this ...
by wangkevin1029 Communicator in Splunk Search 11-17-2022
0 2
0
2
vagnet
Hi Splunkers, I want to create a macro that will be looking inside a lookup file, but in a way that will not break th...
by vagnet Explorer in Splunk Search 11-17-2022
0 4
0
4
adent
I am trying to add a field to a search using a lookup table. However, my key field  is sometimes blank and I get an e...
by adent Explorer in Splunk Search 11-17-2022
0 1
0
1
hermitfeather
Hello!I currently have this eval in a search of mine:   | eval exists=if(like(_raw, "%xa recovery%"), 0, 1)   Is ther...
by hermitfeather Loves-to-Learn in Splunk Search 11-17-2022
0 2
0
2
karu0711
I want to be the order I list below?Very High High MediumLowVery Low Info
by karu0711 Communicator in Splunk Search 11-17-2022
0 2
0
2
jip31
hi as you can see I use a relative time in my search in order to filter events on today between 7h and 19h   earliest...
by jip31 Motivator in Splunk Search 11-17-2022
0 3
0
3
metylkinandrey
Good afternoon, I have already raised a similar topic. The last time I was cleared up the situation, but the problem ...
by metylkinandrey Communicator in Splunk Search 11-17-2022
0 9
0
9
msarro
We have a data source which contains two columns, both of which contain valuable information. In any event, either on...
by msarro Builder in Splunk Search 11-17-2022
1 8
1
8
noammeir
hiI am trying to get my dashboard better and move all of the different searches to a single/couple of base searches a...
by noammeir Explorer in Splunk Search 11-17-2022
0 3
0
3
directtv999
sample json: Hosts: { [-]   Nodepool1: { [-]       Cluster: xyz1       Accountid: idxyz   Nodepool3: { [-]      Clust...
by directtv999 Loves-to-Learn Lots in Splunk Search 11-17-2022
0 7
0
7
sc_admin11
i am trying to create a custom field like host and source by making changes in atteched  photos of entrypoint.sh and ...
by sc_admin11 Explorer in Splunk Search 11-16-2022
0 0
0
0
JyotiP
I have the following query :sourcetype="docker" AppDomain=Eos Level=INFO Message="Eos request calculated" | eval Val_...
by JyotiP Path Finder in Splunk Search 11-16-2022
0 3
0
3
YatMan
Sample event   { durationMs: 83 properties: { url: https://mywebsite/v1/organization/41547/bui...
by YatMan Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunky21
Hi all, I'm attempting to develop a regex that will pick up on a value contained in [ ] brackets (see below): Log val...
by Splunky21 Explorer in Splunk Search 11-16-2022
0 2
0
2
judges88
Trying to get these UUID/GUIDs to extract from the message field. Hoping to create a rex to extract everything after ...
by judges88 Explorer in Splunk Search 11-16-2022
0 5
0
5
JohnnyMnemonic
I have read all the posts about "merging fields" and none of the options work for me. I have events where the same va...
by JohnnyMnemonic Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunkstart
Hi All, these are the logger info counts which are generated in splunk  Total numner where inds-a 20Total numner wher...
by Splunkstart Explorer in Splunk Search 11-16-2022
0 4
0
4
jip31
hi I want to not display the week end in my chart for example, if i use a time picler range of 7 days, I just want to...
by jip31 Motivator in Splunk Search 11-16-2022
0 11
0
11
anu41
I am having issue with "Status" values as below and screenshot, please find below json and search query. Please advis...
by anu41 Explorer in Splunk Search 11-16-2022
0 2
0
2
SumanPalisetty
Hi,Sometimes if we are doing base search, if not handled properly, you will see page loading, how do you handle it?Re...
by SumanPalisetty Path Finder in Splunk Search 11-16-2022
0 1
0
1
Abdullah
Dears,   We need your support to convert below search to tstats search. (index=os_windows OR index=workstation*) tag=...
by Abdullah Explorer in Splunk Search 11-16-2022
0 3
0
3
neerajs_81
Hello,  We have been using this query to list out hosts that are not sending logs since past 24h.  It has been workin...
by neerajs_81 Builder in Splunk Search 11-16-2022
0 8
0
8
KMoryson
I have the following table of activities: InternalExternalDirection1.1.1.12.2.2.2Outbound3.3.3.34.4.4.4Inbound5.5.5.5...
by KMoryson Explorer in Splunk Search 11-16-2022
0 2
0
2
sivakumargik
sample event "USR_LOGIN","USR_EMP_NO","USR_LAST_NAME","USR_FIRST_NAME","USR_DISPLAY_NAME","USR_STATUS","USR_EMAIL","...
by sivakumargik New Member in Splunk Search 11-16-2022
0 6
0
6
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...