Splunk Search

Splunk Search
Community Activity
darphboubou
Hello, I have a lookup on which we have two columns, one with the computer name and the other with the OS version. Wh...
by darphboubou Explorer in Splunk Search 07-18-2022
0 10
0
10
sambitmahantaes
I am not able to find the host field information for the events coming from a particular machine.  This is related to...
by sambitmahantaes Explorer in Splunk Search 07-18-2022
0 7
0
7
wealot
Hi all, I have events coming in that have multivalue fields, but not always the same fields are multivalue. I want al...
by wealot Explorer in Splunk Search 07-18-2022
0 2
0
2
registration9
We have a FIG (fluentD/InfluxDB/Grafana) setup in which we want to change the IG part to Splunk. We have several das...
by registration9 New Member in Splunk Search 07-17-2022
0 2
0
2
cxm0u4e
Let's say I have a multivalue fieldA and a fieldB. I know you can do something like "| where field=value" in a search...
by cxm0u4e Engager in Splunk Search 07-17-2022
0 2
0
2
Ashwin3
Hi team, As per my requirement, on changing a particular form element [Token 1] , a set of other tokens [Token2,Token...
by Ashwin3 Engager in Splunk Search 07-17-2022
0 2
0
2
JR_Akaviri
I'm trying to find any new MFA factors(DUO) used by any user in the past X days in order to create an alert.  As an e...
by JR_Akaviri Engager in Splunk Search 07-17-2022
0 1
0
1
Minasdad
file1.csv and file2.csv with a common field of "Tests". Wanting to compare File2 field "Tests" against file1.csv fiel...
by Minasdad Path Finder in Splunk Search 07-17-2022
0 2
0
2
Gzee
Hi, Novice splunker here. My search only extracts 1st 10-digit number and my data contains atleast 4 or more  10-digi...
by Gzee Engager in Splunk Search 07-17-2022
0 1
0
1
DPOIRE
Good Day,I need help to calculate the time difference for field "@timestamp" containing time format 2022-07-14T09:05:...
by DPOIRE Path Finder in Splunk Search 07-15-2022
0 16
0
16
yshen
I need to first issue an alert for overheat temperature 24 hours in advance for the affected locations, for their for...
by yshen Communicator in Splunk Search 07-15-2022
1 3
1
3
Veeru
index=a host="b" source="0*_R_S_C_ajf" OWNER=dw*|eval ODate=strptime(ODATE,"%Y%m%d")|eval ODATE=strftime(ODate,"%Y-%m...
by Veeru Path Finder in Splunk Search 07-15-2022
0 6
0
6
ggilmore1
I have been trying to extract a field to list domain admins from AD logs. The logs have all the admins starting with ...
by ggilmore1 Explorer in Splunk Search 07-14-2022
0 8
0
8
csahoo
index="*dockerlogs*" source="*gps-request-processor-dev*" OR source="*gps-external-processor-dev*" OR source="*gps-ar...
by csahoo Explorer in Splunk Search 07-14-2022
0 1
0
1
mjones414
I have a scenario where I am analyzing the format of a given string to determine what the name of the format is (e.g....
by mjones414 Contributor in Splunk Search 07-14-2022
0 3
0
3
florianhh
Hi Splunkers, I try to get a new internal field "_application" added to certain events. So i added a new field via th...
by florianhh Explorer in Splunk Search 07-14-2022
0 3
0
3
willspk
Hey everyone, I've got all our firewall logs going into separate index. When I perform a search just using the index ...
by willspk Engager in Splunk Search 07-14-2022
0 1
0
1
mcscjlf
Hello, In my search I'm trying to get a series of events (transact - which is in the _raw field) counted out by anoth...
by mcscjlf Explorer in Splunk Search 07-14-2022
0 1
0
1
Marian
Here is a reduced version of my JSON: {<!-- -->   records: [     {<!-- -->       errors: 4       name: name1       plugin: p1       t...
by Marian Explorer in Splunk Search 07-14-2022
0 4
0
4
HelloItsMe76
I have a table like the below   Category   | Time |  Count of string A | t-5mins | 18 A | t-10mins | 7 A | t-15mins |...
by HelloItsMe76 Explorer in Splunk Search 07-14-2022
0 3
0
3
yshen
I want to compare the daily temperature measurements at the same period, but different days by a stacked temperature ...
by yshen Communicator in Splunk Search 07-14-2022
0 2
0
2
Splunk3
Hi , I have created one graph for Success and failure result, but not able to change the color, How I can have the re...
by Splunk3 Explorer in Splunk Search 07-14-2022
0 1
0
1
hettervik
Hi folks. Whenever you do a search in Splunk you can review the lispy in search.log. For example, if I search for my ...
by hettervik Builder in Splunk Search 07-14-2022
0 4
0
4
Ahmedkhalil
Dears, i would like to create chart that contain two different x axis and one y axis using xyseries command but i cou...
by Ahmedkhalil Communicator in Splunk Search 07-14-2022
0 3
0
3
Poojitha
Hi Team,I have a field like below :Cost :0.45655345534530.00004354634660.00213456677880.0000000005657I want to get va...
by Poojitha Communicator in Splunk Search 07-14-2022
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...