Splunk Search

Splunk Search
Community Activity
dmoberg
For the type of data I am trying to extract, Event Sampling really speeds up the query. This works fine when executin...
by dmoberg Path Finder in Splunk Search 09-28-2022
0 5
0
5
simon1524
For example, the "SUBMIT_DATE" is split by date and time. Then define some period of time as a value(A/B/C). Can this...
by simon1524 Explorer in Splunk Search 09-27-2022
0 8
0
8
ghostrider
I want to filter the search results based on tx_id that I extract in the 2nd rex. Meaning only those results that hav...
by ghostrider Path Finder in Splunk Search 09-27-2022
0 2
0
2
Sanjana
Hello, I have data like below.  {"property":"XYZ", "period":{ "start":"2022-09-16", "end":"2022-10-02" }, "nb-day":17...
by Sanjana Explorer in Splunk Search 09-27-2022
0 7
0
7
Sanjana
Hey all, I am trying to extract dynamic field from json . {"period":{"start":"2023-04-17","end":"2023-05-14"},"check-...
by Sanjana Explorer in Splunk Search 09-27-2022
0 5
0
5
dennis_u
Say, we have events like this: _timefwsrc_ipdest_ipdest_portfw_rule_action8/1/22 1:30:00.000 AMfw1192.168.50.518.8.8....
by dennis_u Observer in Splunk Search 09-27-2022
0 2
0
2
kevinb0011
Good morning, Curious to see if anyone has used a similar dataset in Splunk and/or any suggestions on the best way to...
by kevinb0011 Explorer in Splunk Search 09-27-2022
0 5
0
5
cbiraris
Hi Team,I have  several Dashboards that contain base searches data from reports  for example: <search id="baseSearch"...
by cbiraris Path Finder in Splunk Search 09-27-2022
0 3
0
3
tomapatan
I have 2 fields: the values of fieldA are present in fieldB and I need to remove the first part of fieldB up to the v...
by tomapatan Contributor in Splunk Search 09-27-2022
0 3
0
3
ninja_panda
I want to create a Bar chart with the logs where the key would be the stats count field name and value would be the s...
by ninja_panda Engager in Splunk Search 09-27-2022
0 4
0
4
angadbagga
Here is my query. In final line chart when I hover, I am not getting different dates.  Rather only 26th Sept (Today's...
by angadbagga Explorer in Splunk Search 09-27-2022
0 9
0
9
asafd
Hi, I have multiple panels that need to run timecharts like these: something | table _time,A,B</query> | search A="1"...
by asafd Explorer in Splunk Search 09-27-2022
0 1
0
1
anooshac
Hi all,I am calculating a value from data and i want to plot it in a timechart. | where status!="ABORTED" | streamsta...
by anooshac Communicator in Splunk Search 09-27-2022
0 7
0
7
dmoberg
I have a need to compare the average time for certain events with the 5 min bucket/bins of the same events. The idea ...
by dmoberg Path Finder in Splunk Search 09-27-2022
0 4
0
4
zacksoft_wf
How do I know if a TA is used by any user.I have a TA laying around, and I doubt is is been used. But before removing...
by zacksoft_wf Contributor in Splunk Search 09-27-2022
0 4
0
4
yuanliu
I'm trying to use the Splunk 9 addition in foreach iteration with ITEM, but it always returns "Failed to parse templa...
by SplunkTrust SplunkTrust in Splunk Search 09-26-2022
0 3
0
3
klischatb
Hello everyone!i have the following search:     index="xyz" "restart" | eval _time = strftime(_time,"%F %H:%M:%S") | ...
by klischatb Path Finder in Splunk Search 09-26-2022
0 4
0
4
bapun18
I am running a query |tstats count latest(_time) where index=abcd by host, my requirement is to create an alert when ...
by bapun18 Communicator in Splunk Search 09-26-2022
0 4
0
4
fpedrosa
Hi,I have this search:| stats count by application | eval application = case( application=="malware-detection",...
by fpedrosa Engager in Splunk Search 09-26-2022
0 1
0
1
KyleMcDougall
Hi all, I'm trying to get a list of phone numbers for each event by sessionId. I can't quite figure it out. I think I...
by KyleMcDougall Path Finder in Splunk Search 09-26-2022
0 3
0
3
vrmandadi
I am using the below search to first get the difference in time everytime I see an event which has boot timestamp in ...
by vrmandadi Builder in Splunk Search 09-26-2022
0 10
0
10
Julia1231
Hi everyone, I am searching data in Splunk, after different steps, I have now this table:   _timecountTypeMon Sep 12 ...
by Julia1231 Communicator in Splunk Search 09-26-2022
0 1
0
1
Julia1231
Hi everyone, I use dbxquery and get this result from database: idcount12312456244786   Also I have a csv file already...
by Julia1231 Communicator in Splunk Search 09-26-2022
0 3
0
3
Snehraj
Hello All, I have email exchange transactional data with below fields. Looking some data with span of 1day. Like how ...
by Snehraj New Member in Splunk Search 09-26-2022
0 1
0
1
quietferret
Hi Community! I am trying to find a good example of setting a background image to a classic dashboard.  This process ...
by quietferret Loves-to-Learn in Splunk Search 09-26-2022
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...