Splunk Search

Splunk Search
Community Activity
uagraw01
Hello Splunkers!! As per my requirement my current results are as below : severityVulnablitiesCritical3Medium 4Low6  ...
by uagraw01 Motivator in Splunk Search 10-26-2022
0 5
0
5
edwinmae
Hi, Log format is JSON I have a Field named Organization Now when Organization = "Systèmes" , this will have the foll...
by edwinmae Path Finder in Splunk Search 10-26-2022
0 0
0
0
Mckechnie
I am trying to create a search which looks for an EventCode 4624 followed by another EventCode 4625 from same user, i...
by Mckechnie Engager in Splunk Search 10-26-2022
0 1
0
1
philbond
Hi all,Due to utf16/8-mismatch, I find a lot of utf16 \xnn chars in my events; this makes the json-parser  kind of lo...
by philbond Observer in Splunk Search 10-26-2022
0 1
0
1
bowesmana
https://community.splunk.com/t5/Splunk-Search/Fields-vs-table-vs-nothing/m-p/498525#M194897 I was looking at a Splunk...
by SplunkTrust SplunkTrust in Splunk Search 10-25-2022
1 6
1
6
jwalzerpitt
I am having a brain fart on trying to figure out how to find the total bytes per application and the the percent of e...
by jwalzerpitt Influencer in Splunk Search 10-25-2022
0 2
0
2
MM0071
I have a text box in a splunk dashboard and I'm trying to find out how I can separate values entered into the text bo...
by MM0071 Path Finder in Splunk Search 10-25-2022
0 4
0
4
vjsplunk
I am getting fewer events when using rename command in splunk. ( Compared to the search where I haven't used rename)....
by vjsplunk Loves-to-Learn Everything in Splunk Search 10-25-2022
0 3
0
3
marceldera
Inter join is not displaying any results.   the search works however, nothing is showing up on the screen index = ten...
by marceldera Explorer in Splunk Search 10-25-2022
0 1
0
1
msarkaus
I'm trying to combine two simular values from the same field. and rename the values. I would like to combine  /v1/pr...
by msarkaus Path Finder in Splunk Search 10-25-2022
0 1
0
1
vmpj
I have three graphs that show results based on a global time range.However, if I have no results (no errors) the thir...
by vmpj Loves-to-Learn in Splunk Search 10-25-2022
0 6
0
6
sjringo
I have seen several posts asking similar questions but I am not that much of a UI guy so they do not make sense. I ha...
by sjringo Contributor in Splunk Search 10-25-2022
0 0
0
0
JoDeBa
Hello, I've been searching the internet for quite a while. But can't find any approach. I have a primary search that ...
by JoDeBa Loves-to-Learn in Splunk Search 10-24-2022
0 2
0
2
apps_inpaytech
I have a seemingly simple request: list the events and indicate if it occurred during an outage. I have been trying f...
by apps_inpaytech Explorer in Splunk Search 10-24-2022
0 6
0
6
testingMemes
Can I limit foreach iterations, or place a where clause (or other filter) in the foreach subsearch? I'm attempting to...
by testingMemes Engager in Splunk Search 10-24-2022
0 2
0
2
richnavis88
Hello,  I have to avoid matching several values in a fields.  The following works, but I"m wondering if there is a mo...
by richnavis88 Explorer in Splunk Search 10-24-2022
1 2
1
2
es5
Hello all, I have a search that's something like this:       index=* sourcetype=* ID=* (value=1 OR value=2 OR value=...
by es5 Loves-to-Learn Lots in Splunk Search 10-24-2022
0 7
0
7
angersleek
I have the following query:  application_id=12345 STATUS_CODE IN (300, 400, 500)| head 10 How can I modify this such ...
by angersleek Path Finder in Splunk Search 10-24-2022
0 1
0
1
bo2057
Hello,      | transaction RRN keepevicted=t | search date_hour <6 If I execute this search with a specific date(10-10...
by bo2057 Loves-to-Learn in Splunk Search 10-24-2022
0 2
0
2
nessaner
Hello, I need to take events with two kind of text (different paths) :Appended to:  G:\Streamserve\Appended to:  D:\G...
by nessaner Explorer in Splunk Search 10-24-2022
0 3
0
3
ranjithan
Hi Community, Please help me.. I have a field Expiration with values having different timezones . Could you please he...
by ranjithan Path Finder in Splunk Search 10-24-2022
0 4
0
4
splunkyphil
I need to create a new field to assign to the top results of a command using eval.  Obviously this syntax doesn't wor...
by splunkyphil Engager in Splunk Search 10-23-2022
0 2
0
2
dm1
Below is my spl   |from datamodel:"Threat_Intelligence".""Threat_Activity" |dedup threat_match_field,threat_match_val...
by dm1 Contributor in Splunk Search 10-23-2022
0 2
0
2
na
I have repeated failed logins listed as "Other" in my pie chart for Failed Logins by Host. How can I find out what th...
by na Loves-to-Learn in Splunk Search 10-23-2022
0 3
0
3
SanjayReddy
Hi All, I need help on plotting backlog data on timechart We have set of tickets in backlog on specific dates with wo...
by SplunkTrust SplunkTrust in Splunk Search 10-23-2022
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...