Splunk Search

Splunk Search
Community Activity
KH
I'm extremely new to Splunk and finding learning SPL very frustrating. I'm trying to look for windows log on events/ ...
by KH Engager in Splunk Search 09-08-2022
0 2
0
2
Finn
I have encountered an issue with the foreach command on mv-fields.When I execute my search, Splunk says: "Error in 'e...
by Finn Explorer in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
What is the difference between now() and _time?
by smanojkumar Contributor in Splunk Search 09-08-2022
0 2
0
2
Dharani
Hi, Below is the example for raw log: 20220906T23:43:58+03:00#0115dummyvalue.com#01110.111.169.11:51868#01110.45.38.1...
by Dharani Path Finder in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
Start_Time=092659Start_Date=20220908My requirement is to find the job amount many jobs that runs longer than a day, t...
by smanojkumar Contributor in Splunk Search 09-08-2022
0 3
0
3
responsys_cm
I'm trying to make the Linux audit daemon data play nice. One of the challenges is that a particular action can trig...
by responsys_cm Builder in Splunk Search 09-08-2022
0 2
0
2
mydog8it
I have a comma delimited multivalue field that contains text and a digit in each value pair that I am trying to find ...
by mydog8it Builder in Splunk Search 09-08-2022
1 14
1
14
CybSec1
Hello,I have logs like : samples={'xxxxxxx' : {'111' :{'222' :{'333'}}}}{'yyyyyyy'{'444'}}{'zzzzzzz'}I need to take a...
by CybSec1 New Member in Splunk Search 09-08-2022
0 2
0
2
FGAnders
Hi, Is there any way to exclude any events that has more than one value of a field  from end result.    index=X statu...
by FGAnders Explorer in Splunk Search 09-08-2022
0 2
0
2
PepposChris
Hello,   I've been using SPLUNK search REST API for a while now and just today i've run into the following issue.   W...
by PepposChris Observer in Splunk Search 09-07-2022
0 4
0
4
kpavan
Hi All, Am looking for query to have multiple earliest days  index=something sourcetype=something earliest=-7d@d late...
by kpavan Path Finder in Splunk Search 09-07-2022
0 3
0
3
jhcbazinga95
Hey all, Can someone help me out with a JSON related question! Many many thanks!  I have a JSON arrays field in this...
by jhcbazinga95 Loves-to-Learn Everything in Splunk Search 09-07-2022
0 3
0
3
SS1
Hi, I have 2 searches where the dedup strategy is different, i want to combine the 2 searches but need help with dedu...
by SS1 Path Finder in Splunk Search 09-07-2022
0 1
0
1
janderhungrige
Hi,I want to count the numbers of containers per company. Each data point has a container id, company id, and much mo...
by janderhungrige Observer in Splunk Search 09-07-2022
0 1
0
1
Kislac
Greetings. Is it possible merge 2 search? If there is any common value than connect it. If there is no match keep the...
by Kislac Engager in Splunk Search 09-07-2022
0 4
0
4
uagraw01
@ITWhisper As per the Below Screenshot I want to add Custom time frame. Where user can able to select any time frame ...
by uagraw01 Motivator in Splunk Search 09-07-2022
0 9
0
9
Mick_OBrien
I have logs of the format... 2022-09-07T01:42:06.321624+00:00 micro.service 2867ce23-bdfd-48eb-ba5a-40e1e8a93987[[APP...
by Mick_OBrien Path Finder in Splunk Search 09-07-2022
0 5
0
5
metylkinandrey
I have two message threads, each thread consists of ten messages. I need to request to display these two chains in on...
by metylkinandrey Communicator in Splunk Search 09-07-2022
0 6
0
6
surens
How to count each log value separately?("*error*","*info*","*warn*")
by surens Explorer in Splunk Search 09-07-2022
0 6
0
6
uagraw01
  In the above, I am comparing the last 15m data to the current week's 15m data. And I am getting good results.    ...
by uagraw01 Motivator in Splunk Search 09-06-2022
0 5
0
5
pwilson
I am trying to add a percentage to the total row generated by addcoltotals. I would like to show the total percentage...
by pwilson Explorer in Splunk Search 09-06-2022
0 1
0
1
roayers
I've found many samples of how to convert an IPv4 to many different formats but I can't seem to locate one to convert...
by roayers Explorer in Splunk Search 09-06-2022
0 3
0
3
elmadi_fares
I have a problem triggering an alert on a splunk request based on a cron job that runs this way: Search query: index...
by elmadi_fares Loves-to-Learn Everything in Splunk Search 09-06-2022
0 3
0
3
m0rt1f4g0
I have a table with the next information:Fecha31/08/2022 16:16:4331/08/2022 16:19:4831/08/2022 16:16:3431/08/2022 16:...
by m0rt1f4g0 Explorer in Splunk Search 09-06-2022
0 4
0
4
ramkyreddy
I have to decrease the fields names font size, like subgroup, platforms, bkcname etc.. (all fields present in the tab...
by ramkyreddy Explorer in Splunk Search 09-06-2022
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...