Splunk Search

Splunk Search
Community Activity
bo2057
Hello,      | transaction RRN keepevicted=t | search date_hour <6 If I execute this search with a specific date(10-10...
by bo2057 Loves-to-Learn in Splunk Search 10-24-2022
0 2
0
2
nessaner
Hello, I need to take events with two kind of text (different paths) :Appended to:  G:\Streamserve\Appended to:  D:\G...
by nessaner Explorer in Splunk Search 10-24-2022
0 3
0
3
ranjithan
Hi Community, Please help me.. I have a field Expiration with values having different timezones . Could you please he...
by ranjithan Path Finder in Splunk Search 10-24-2022
0 4
0
4
splunkyphil
I need to create a new field to assign to the top results of a command using eval.  Obviously this syntax doesn't wor...
by splunkyphil Engager in Splunk Search 10-23-2022
0 2
0
2
dm1
Below is my spl   |from datamodel:"Threat_Intelligence".""Threat_Activity" |dedup threat_match_field,threat_match_val...
by dm1 Contributor in Splunk Search 10-23-2022
0 2
0
2
na
I have repeated failed logins listed as "Other" in my pie chart for Failed Logins by Host. How can I find out what th...
by na Loves-to-Learn in Splunk Search 10-23-2022
0 3
0
3
SanjayReddy
Hi All, I need help on plotting backlog data on timechart We have set of tickets in backlog on specific dates with wo...
by SplunkTrust SplunkTrust in Splunk Search 10-23-2022
0 5
0
5
noammeir
hi   our system logs test runs as single events. in some cases we would have a re-run of a test. both events are logi...
by noammeir Explorer in Splunk Search 10-23-2022
0 5
0
5
jbrenner
I have two independent/unrelated queries (same index, though) , and I want to create a timechart where there are two ...
by jbrenner Path Finder in Splunk Search 10-22-2022
0 1
0
1
ominous_ghost
Our application logs for each method: when it begins, when it ends, and the thread it is on. We are wanting to visual...
by ominous_ghost Engager in Splunk Search 10-22-2022
0 3
0
3
jcorcoran508
I have this request to build a report   7am - 1900 Monday-Friday  CST Sat 7am - noon   CST   Splunk is running on UTC...
by jcorcoran508 Path Finder in Splunk Search 10-21-2022
0 1
0
1
lugoon
[Filter: smut] lugoon's post body matched "damn", board "security-splunk-enterprise-security". Post Subject: More E...
by lugoon Explorer in Splunk Search 10-21-2022
0 0
0
0
Woodpecker
Hi,I have a list of hosts/devices say from HostA to HostZ (PS: its not  a lookup file) I want to find out which host ...
by Woodpecker Path Finder in Splunk Search 10-21-2022
0 3
0
3
babukumarreddy
Hi  For example  Using below query i can see  when we received the last log to splunk, based on that if I search for ...
by babukumarreddy Loves-to-Learn Lots in Splunk Search 10-21-2022
0 5
0
5
sjringo
Hi, I have the following SPL working fine when I have a starting event and ending event in my logs. If I have a start...
by sjringo Contributor in Splunk Search 10-21-2022
0 2
0
2
bosseres
Hello everyone! What is the best way to remove dots from domain in field? for example | eval field = lower(mvindex(sp...
by bosseres Contributor in Splunk Search 10-21-2022
0 4
0
4
dlcrooks
According to the docs for cron the Sunday code is 0.   When I try to run this cron for the first Sunday of the month ...
by dlcrooks Explorer in Splunk Search 10-21-2022
0 10
0
10
metylkinandrey
Good afternoon!I have a request based on which I create an aller: index="main" sourcetype="testsystem-script707" | ev...
by metylkinandrey Communicator in Splunk Search 10-21-2022
0 6
0
6
mv10
We have alerts for high Windows Server CPU usage, and we have automated vulnerability scanners which can trip these a...
by mv10 Path Finder in Splunk Search 10-21-2022
0 12
0
12
mnj1809
Hello, I need your help to find a way to achieve the following use case:in main search:I've to categories: Windows an...
by mnj1809 Path Finder in Splunk Search 10-21-2022
0 8
0
8
ChrisG
Beyond what's in the Search Reference and the Search Manual, are there other sites that have SPL examples available t...
by ChrisG Splunk Employee Splunk Employee in Splunk Search 10-21-2022
1 11
1
11
codeJesus
Hello,  please can someone assist with creating syntax to 1. know the numbers of desktop, laptops, servers and networ...
by codeJesus Engager in Splunk Search 10-21-2022
0 4
0
4
uagraw01
To provide further from yesterday's SPL query. I am facing huge events in multivalues. I want to break in a single ev...
by uagraw01 Motivator in Splunk Search 10-20-2022
0 1
0
1
klim
Is it possible to restrict a role to run a certain search or only be able to run saved searches?Ie a user can only ru...
by klim Path Finder in Splunk Search 10-20-2022
0 0
0
0
leeyounsoo
hello I have a question I have a data that access_log data and json data is mixed and my need is to extract field fr...
by leeyounsoo Path Finder in Splunk Search 10-20-2022
0 10
0
10
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors