Splunk Search

Splunk Search
Community Activity
mananzeh
i have 2 csv file first one has name and idsecond one has the id only i can extract the common id but i couldn’t find...
by mananzeh New Member in Splunk Search 11-08-2022
0 1
0
1
metylkinandrey
Good afternoon! I'm noticing that my time format in the messages I send to /services/collector/raw isn't being parsed...
by metylkinandrey Communicator in Splunk Search 11-08-2022
0 8
0
8
DavideASR
Hi, I'm trying to extract string "domain.com" from <mail@domain.com> How can i extract string between "@" and ">" ? T...
by DavideASR Engager in Splunk Search 11-08-2022
0 1
0
1
_pravin
Hi Community,   I have the below search query     index=_internal [ `set_local_host`] source=*license_usage.log*...
by _pravin Contributor in Splunk Search 11-08-2022
0 4
0
4
danielbb
Hello,Is there a way to convert this query to run with tstats? It is _slow_ when running it for two weeks of data...i...
by danielbb Motivator in Splunk Search 11-08-2022
0 2
0
2
dtccsundar
I have 3 date columns.I have already calculated the difference between current day and the diff is in days are the va...
by dtccsundar Path Finder in Splunk Search 11-08-2022
0 4
0
4
klim
I have a search head cluster and I will have scheduled reports that send data to a summary index. I don't want other ...
by klim Path Finder in Splunk Search 11-07-2022
0 2
0
2
mskrzynski
Hello, can anyone tell me why this configuration isn’t working?I would like to change index name from main to hue, I’...
by mskrzynski Explorer in Splunk Search 11-07-2022
0 10
0
10
Damek
Hello, I am currently using the |append method for some queries, but was curious if there is a better way for me to b...
by Damek Engager in Splunk Search 11-07-2022
0 2
0
2
dmbrcx
Dumb question I cannot find a simple answer to. 藍 If I run a simple timechart search for 7 days, 30 days or 90 days -...
by dmbrcx Explorer in Splunk Search 11-07-2022
0 3
0
3
nabeel652
Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both...
by nabeel652 Builder in Splunk Search 11-07-2022
0 2
0
2
ff170a
I have a dataset with a multiline field called Logs. The field typically has values like the below,     "mId": "Nul...
by ff170a Explorer in Splunk Search 11-07-2022
0 3
0
3
sh254087
I have a table with 1 column and 6 rows which I'll be changing to 1 row and 6 columns using transpose and eventually ...
by sh254087 Communicator in Splunk Search 11-07-2022
0 6
0
6
iamtheclient20
I have a SPL, when first running the result is appearing but once the query is finished the error have shown below: |...
by iamtheclient20 Explorer in Splunk Search 11-07-2022
1 8
1
8
Aryc090908
 Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _...
by Aryc090908 Explorer in Splunk Search 11-07-2022
0 3
0
3
Hisham
Hi, I have generated a search which return list of hosts and the count of events for these host. sometime the host va...
by Hisham Engager in Splunk Search 11-07-2022
0 1
0
1
lennys26
On an existing dashboard I have a rather complex query that generates a timechart on which I am looking to use annota...
by lennys26 Communicator in Splunk Search 11-07-2022
0 2
0
2
jhilton90
I am using the following rex command to extract an id number, which is in the following format: 1e4gd5g7-4fy6-fg567-3...
by jhilton90 Path Finder in Splunk Search 11-07-2022
0 7
0
7
nihvk
I am looking for an alert when any search in (rest /services/saved/searches splunk_server=local) is being modified.
by nihvk Explorer in Splunk Search 11-07-2022
0 1
0
1
AKG11
Hi, I am looking to create timeseries graph based on multiple fields.we could have multiple hosts and each host have ...
by AKG11 Path Finder in Splunk Search 11-07-2022
0 5
0
5
karjsim
Hi,I have events which are received when action is finished on my system. Event contains start and stop time for acti...
by karjsim Loves-to-Learn Lots in Splunk Search 11-07-2022
0 9
0
9
sidtalup27
Hello, I have installed an App, and the data in APP is written to "MAIN" index. When I am search for DATA from the AP...
by sidtalup27 Explorer in Splunk Search 11-07-2022
0 3
0
3
anuhya_b
Hello Everyone, I have a field in this format and this information is fetched from a json array.Label apple 1apple 2a...
by anuhya_b Observer in Splunk Search 11-07-2022
0 1
0
1
mkshah
Hi ,how to do i display number of blocked and allowed threats with different severities in a timeframe(e.g monthly).S...
by mkshah New Member in Splunk Search 11-06-2022
0 1
0
1
user33
Hello, I am very new to Splunk. I am wondering how to split these two values into separate rows. The "API_Name" value...
by user33 Path Finder in Splunk Search 11-06-2022
0 7
0
7
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors