Splunk Search

Splunk Search
Community Activity
LogUx
Hello Splunker! I created below regex from the raw events. And I want to create an alert which show the event in one ...
by LogUx Motivator in Splunk Search 10-06-2022
0 5
0
5
alakdam
One dashboard was made by me. I'm showing my colleagues my dashboard. Problem: When my coworkers or I access that Spl...
by alakdam Path Finder in Splunk Search 10-06-2022
0 2
0
2
san112491
Static data with one common field app Name as splunk query.
by san112491 New Member in Splunk Search 10-06-2022
0 2
0
2
alakdam
I have a data where I got empty object. I would like count in total how many empty object in one table data and also ...
by alakdam Path Finder in Splunk Search 10-05-2022
0 10
0
10
akshayinnamuri
HiI am looking for query where say for example user=xyz which is present in multiple watchlists [watchlist_A.csv, wat...
by akshayinnamuri Loves-to-Learn Lots in Splunk Search 10-05-2022
0 1
0
1
rkoster
| makeresults count=1| eval list_split_failure_1 = "fail:,searching old data:,searching new"| eval list_split_failure...
by rkoster Explorer in Splunk Search 10-05-2022
0 1
0
1
username13
Hi guys,I need to evaluate a disruption.  It can last multiple hours, so I need to use data which is at least 4h old....
by username13 Explorer in Splunk Search 10-05-2022
0 3
0
3
reed_kelly
I would like to send a search with a specific time range to people in different time zones. I can use earliest and la...
by reed_kelly Contributor in Splunk Search 10-05-2022
0 6
0
6
Julia1231
Hi everybody, I am creating a Dashboard using Splunk and I'm searching for a solution. I have a list machine accordin...
by Julia1231 Communicator in Splunk Search 10-05-2022
0 2
0
2
Rajaion
Hello community, I am having a problem with a dashboard that I am setting up based on Splunk OnCall data, in order to...
by Rajaion Path Finder in Splunk Search 10-05-2022
0 6
0
6
monicateja
Hi, How can we calculate milli seconds to seconds for this field -> transactionDuration=20058?
by monicateja Explorer in Splunk Search 10-05-2022
0 3
0
3
leon12
Hey Guys, I have the following data in Splunk. Each eventdata has 4 lines (which are seperated through newLines) and ...
by leon12 Loves-to-Learn in Splunk Search 10-05-2022
0 1
0
1
jip31
Hello as you can see "type" field as 3 values : stand, vd or xe if the "type" field is "vd" or "xe", I need to gather...
by jip31 Motivator in Splunk Search 10-05-2022
0 6
0
6
untitledman27
i All   There are query splunk like this :  (index=Prod sourcetype=ProdApp (host=Prod01 OR Prod02) source="/prodlib/S...
by untitledman27 Loves-to-Learn Everything in Splunk Search 10-05-2022
0 24
0
24
monicateja
How can i convert timestamp to date for below timestamp to just date 2022-10-04. timestamp: 2022-10-04 19:52:00.151 ...
by monicateja Explorer in Splunk Search 10-05-2022
0 3
0
3
batabay
Hi Splunkers, I have data like this,  Primary Key_1:      subkey_1 : subvalue_1      subkey_2 : subvalue_2 Primary Ke...
by batabay Path Finder in Splunk Search 10-05-2022
0 3
0
3
charlottelimcl
Hi all, I am trying to feed results of a query into another of a different time and index and I'm facing issues with ...
by charlottelimcl Explorer in Splunk Search 10-05-2022
0 5
0
5
preview
For the search record: I edited an already functional dashboard in the studio, tweaking the layout. Part of that was ...
by preview Engager in Splunk Search 10-04-2022
2 0
2
0
yk010123
I have a log entry with the current format:  field=A_B (delimited by underscore)How can I extract this data into two ...
by yk010123 Path Finder in Splunk Search 10-04-2022
0 1
0
1
DBattisto
Hello, I have an API call that is bringing in json data to my Splunk environment. When I do a basic query of the inde...
by DBattisto Communicator in Splunk Search 10-04-2022
0 1
0
1
yk010123
I have the following log:   Requests over Threshold found: {"kv":{"top_requests":[{"operation_name":"get","last_dispa...
by yk010123 Path Finder in Splunk Search 10-04-2022
0 8
0
8
Atchyuth_P
Hi,   | tstats earliest(_time) as Earliest latest(_time) as Latest where index=_internal by _time, index, sourcetype,...
by Atchyuth_P Path Finder in Splunk Search 10-04-2022
0 1
0
1
Glasses2
Hi, I am b/t a rock and a wall, looking for any suggestion to solved this. I am using the URL ToolBox to dissect URI ...
by Glasses2 Communicator in Splunk Search 10-04-2022
0 5
0
5
simpkins1958
host="*" index=main sourcetype=WwanSignal uid="3F77F61645E8323E205F832212" | table _time deviceName user quality prev...
by simpkins1958 Contributor in Splunk Search 10-04-2022
0 15
0
15
saurabh_ha
I want to create the new_field when other values of field_1 is less than of first value.Here in below example as 23 g...
by saurabh_ha Explorer in Splunk Search 10-04-2022
0 2
0
2
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...