Splunk Search

Splunk Search
Community Activity
siemengr
I'm trying to exclude specific src_ip addresses from the results of a firewall query (example below). The query compl...
by siemengr Engager in Splunk Search 08-23-2022
0 3
0
3
jalo23
I can't figure out the correct syntax for the second eval statement or what else I should use instead of eval. I know...
by jalo23 Explorer in Splunk Search 08-23-2022
0 2
0
2
fperalde
Hello, Here is my data! Basically everything is in the same table, however I separated to better explain my problem! ...
by fperalde Engager in Splunk Search 08-23-2022
0 1
0
1
mistydennis
Hi all - I am trying to take one lookup and limit its results with another lookup.  I can kinda get it to work with m...
by mistydennis Communicator in Splunk Search 08-23-2022
0 3
0
3
xiyangyang
I found follow logs in _audit logs.  The user who run this search cannot access internal logs, so I assume the underl...
by xiyangyang Path Finder in Splunk Search 08-23-2022
0 1
0
1
brad_
Hello, the request below works perfectly thanks to the help found on this forum.Now I would like to automate this req...
by brad_ Engager in Splunk Search 08-23-2022
0 14
0
14
Veeru
index=A host="bd*" OR host="p*" source="/apps/logs/*" | bin _time span="30m" | stats values(point) as point values(pr...
by Veeru Path Finder in Splunk Search 08-23-2022
0 6
0
6
FoxMike
Hi all, Is there a possibility that when you've made a query with the hits you want, that also the next x amounts of ...
by FoxMike Engager in Splunk Search 08-23-2022
0 2
0
2
SplunkDash
Hello, is there any way we can extract fields from this sample data, any help will be highly appreciated. Thank you! ...
by SplunkDash Motivator in Splunk Search 08-23-2022
0 6
0
6
masoud
It is sort of like multiplying the set with itself and getting a subset in mathematical term.   my data is sth like t...
by masoud Explorer in Splunk Search 08-23-2022
0 6
0
6
tushki6391
Hi everyone,   StateIDAPP_timeINFOABCCar19/08/22 19:51INFOABCCar19/08/22 19:52INFODEFCar20/08/22 19:53INFOZZZBook30/0...
by tushki6391 New Member in Splunk Search 08-22-2022
0 3
0
3
firstname
Given the below example events: Initial event: [stuff] apple.bean.carrot2donut.57.egg.fish(10) max:311 min 15 avg 101...
by firstname Explorer in Splunk Search 08-22-2022
0 4
0
4
Sanz
Hi All,I am trying to view a lookup file that has the sharing set on this app only from another app than it is define...
by Sanz Explorer in Splunk Search 08-22-2022
0 3
0
3
sgtlongwell
I have a kvstore like below populated with about 1mil rows.  _keynamecount1count2calculated_number1calculated_number2...
by sgtlongwell New Member in Splunk Search 08-22-2022
0 1
0
1
SS1
Hi,I have my current search giving below output, I want to have stats listed by Month. Can someone help on this oneCu...
by SS1 Path Finder in Splunk Search 08-22-2022
0 5
0
5
deton0
Hi I'm trying to search for multiple strings within all fields of my index using fieldsummary, e.g. index=centre_data...
by deton0 Explorer in Splunk Search 08-22-2022
0 2
0
2
biswa2112
I want to capture the Path (\Απεσταλμένα) and Subject (TYPICAL MAIN SHELF) .  I am using below regex Subject\W\s(?<Su...
by biswa2112 Engager in Splunk Search 08-22-2022
0 1
0
1
SS1
Hi, I need help to extract the 3 words after [yyy] using regex,  True [xxx] [yyy] Issue with ios phone 11 False [yyy]...
by SS1 Path Finder in Splunk Search 08-22-2022
0 2
0
2
Edwin1471
Hi, Is there a way to rename a specific value in the column of the table.  For example:  
by Edwin1471 Path Finder in Splunk Search 08-22-2022
0 1
0
1
tankhanandita
Hi I want to extract the unique user ID for the users that are successfully logging in the KTB system [2/11/00 12:45:...
by tankhanandita Explorer in Splunk Search 08-22-2022
0 1
0
1
dmbr
How do I compare the values of the most recent event to the event before that and show only the difference?In one exa...
by dmbr Explorer in Splunk Search 08-21-2022
0 1
0
1
djoobbani
So i am representing endpoint url (y-axis) and http status code (x-axis). I can show the count of each url & status c...
by djoobbani Path Finder in Splunk Search 08-21-2022
0 10
0
10
Santosh2
Hi All,  I have one dashboard in that I am fetching the results from a input look up file. I am getting the results b...
by Santosh2 Path Finder in Splunk Search 08-21-2022
0 2
0
2
N0Excuse_
Hi, I am new to Splunk, I would like to create a command where it can find top 10 events happened within 24 hours. in...
by N0Excuse_ New Member in Splunk Search 08-21-2022
0 2
0
2
madhavanv
I have following eval based macro to return a string, in the end I am expecting macro to return something like "earli...
by madhavanv New Member in Splunk Search 08-20-2022
0 1
0
1
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors