Splunk Search

Splunk Search
Community Activity
kimberlytrayson
My data looks as follows: host col2 ---- ---- A SUCCESS A ERROR B ERROR B SUCCESS B SUCCESS C ERROR Here ...
by kimberlytrayson Path Finder in Splunk Search 08-30-2022
0 1
0
1
m_khatibo88
Hi Community,   I have these alerts on EDR and I want to create a correlation search to show these alerts on the Splu...
by m_khatibo88 New Member in Splunk Search 08-30-2022
0 1
0
1
Khuzair81
status=Auto, Manual car= BMW, Honda, Audi index * | stats count(status) as Total by car Is there anyway I can get the...
by Khuzair81 Path Finder in Splunk Search 08-29-2022
0 2
0
2
mcristinzio
How do list multiple sources in a query: sourcetype=xml source="/wealthsuite/tti/current/*"?
by mcristinzio New Member in Splunk Search 08-29-2022
0 3
0
3
sh254087
I want to change the title text on the tabs from, for example, "Login|Splunk" or "Dashboards | Splunk 7.1.2" to a tex...
by sh254087 Communicator in Splunk Search 08-29-2022
0 4
0
4
jotne
I was searing for a simple way to convert all types of mac address to "more" standard format.  Found various solution...
by jotne Builder in Splunk Search 08-29-2022
1 0
1
0
djcascione
Hi  I have a SPL query that needs to adjust at search time when we are falling in and out of BST.  During BST, the se...
by djcascione Explorer in Splunk Search 08-29-2022
0 7
0
7
marceldera
How can i rename the value of the policy name from = to "contains".  Instead of saying "index=tenable* sourcetype="*"...
by marceldera Explorer in Splunk Search 08-29-2022
0 1
0
1
maniishpawar
Hi All, We are generating a log that records in and out timestamp in epoch for a specific set of transactions and we ...
by maniishpawar Path Finder in Splunk Search 08-29-2022
0 3
0
3
vijay_k
<input type="multiselect" token="product_token" searchWhenChanged="true"><label>Product types</label><choice value="*...
by vijay_k Engager in Splunk Search 08-29-2022
0 5
0
5
Rajaion
Hello community, I have a problem with a search that does not return a result. For the purposes of a dashboard, I nee...
by Rajaion Path Finder in Splunk Search 08-29-2022
0 2
0
2
mspoerr
Hello, I have a chart with dynamic field names displayed as table and would like to change the order of the columns: ...
by mspoerr Path Finder in Splunk Search 08-28-2022
0 3
0
3
syed
 I'm looking at events and I'm trying to determine which files are not "deleted" from the folder on a server after fi...
by syed Observer in Splunk Search 08-28-2022
0 6
0
6
jeff
We have different log sources that may format the MAC address as: af:af:af:af:af:af af-af-af-af-af-af af.af.a...
by jeff Contributor in Splunk Search 08-28-2022
0 9
0
9
Edwin1471
Hi, how can I combine two fields (2.1 and 2.2) into one field (Main calculation) I have a table :    I would like to...
by Edwin1471 Path Finder in Splunk Search 08-28-2022
0 3
0
3
Edwin1471
Hi, How can I transform a table, so that the result would look something like this  
by Edwin1471 Path Finder in Splunk Search 08-27-2022
0 4
0
4
MT
I have a dashboard that gets its base query from a dropdown option and that to run that base query takes the values f...
by MT New Member in Splunk Search 08-27-2022
0 1
0
1
timgren
I'm trying to collapse a of data into earliest/lastest by _time,  with the time is contiguous. Such as: 2022-08-27 07...
by timgren Path Finder in Splunk Search 08-27-2022
0 2
0
2
janroc
Hi all,How do I get two fileds "ip numbers" in an timechart?I tried the aggregate fileds, but show up wrong in my vis...
by janroc Explorer in Splunk Search 08-27-2022
0 7
0
7
jeremyrenard
Hi, I am having some troubles to merge two searches and I am looking for the best way to do this. We have firewall tr...
by jeremyrenard Explorer in Splunk Search 08-27-2022
0 5
0
5
SplunkDash
Hello, I have one data source and getting feed through the inputs.conf file located under default folder and it is cu...
by SplunkDash Motivator in Splunk Search 08-27-2022
0 4
0
4
johnraftery
Hi, I have a graph which is produced by this timechart command: timechart max(duration) as TPS_MAX, sum(par_new_du...
by johnraftery Communicator in Splunk Search 08-26-2022
0 5
0
5
firstname
I may use a search similar to this: index=mock_index source=mock_source| eval event = _raw| stats count as frequency ...
by firstname Explorer in Splunk Search 08-26-2022
0 3
0
3
ramana4u
I have two separate logs ( Request.log, and Response.log ).   Events from App1 will be recorded in Request.log. Event...
by ramana4u Explorer in Splunk Search 08-26-2022
0 5
0
5
hayashi_ayr728
Hello. I am in problem. I have  log like this.   1.example.log 2022/08/24 12:04:00,ExampreA,"xxx"xx"xxx"xxxx"xxx"xxxx...
by hayashi_ayr728 Engager in Splunk Search 08-26-2022
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...