Splunk Search

Splunk Search
Community Activity
JR_Akaviri
I'm trying to find any new MFA factors(DUO) used by any user in the past X days in order to create an alert.  As an e...
by JR_Akaviri Engager in Splunk Search 07-17-2022
0 1
0
1
Minasdad
file1.csv and file2.csv with a common field of "Tests". Wanting to compare File2 field "Tests" against file1.csv fiel...
by Minasdad Path Finder in Splunk Search 07-17-2022
0 2
0
2
Gzee
Hi, Novice splunker here. My search only extracts 1st 10-digit number and my data contains atleast 4 or more  10-digi...
by Gzee Engager in Splunk Search 07-17-2022
0 1
0
1
DPOIRE
Good Day,I need help to calculate the time difference for field "@timestamp" containing time format 2022-07-14T09:05:...
by DPOIRE Path Finder in Splunk Search 07-15-2022
0 16
0
16
yshen
I need to first issue an alert for overheat temperature 24 hours in advance for the affected locations, for their for...
by yshen Communicator in Splunk Search 07-15-2022
1 3
1
3
Veeru
index=a host="b" source="0*_R_S_C_ajf" OWNER=dw*|eval ODate=strptime(ODATE,"%Y%m%d")|eval ODATE=strftime(ODate,"%Y-%m...
by Veeru Path Finder in Splunk Search 07-15-2022
0 6
0
6
ggilmore1
I have been trying to extract a field to list domain admins from AD logs. The logs have all the admins starting with ...
by ggilmore1 Explorer in Splunk Search 07-14-2022
0 8
0
8
csahoo
index="*dockerlogs*" source="*gps-request-processor-dev*" OR source="*gps-external-processor-dev*" OR source="*gps-ar...
by csahoo Explorer in Splunk Search 07-14-2022
0 1
0
1
mjones414
I have a scenario where I am analyzing the format of a given string to determine what the name of the format is (e.g....
by mjones414 Contributor in Splunk Search 07-14-2022
0 3
0
3
florianhh
Hi Splunkers, I try to get a new internal field "_application" added to certain events. So i added a new field via th...
by florianhh Explorer in Splunk Search 07-14-2022
0 3
0
3
willspk
Hey everyone, I've got all our firewall logs going into separate index. When I perform a search just using the index ...
by willspk Engager in Splunk Search 07-14-2022
0 1
0
1
mcscjlf
Hello, In my search I'm trying to get a series of events (transact - which is in the _raw field) counted out by anoth...
by mcscjlf Explorer in Splunk Search 07-14-2022
0 1
0
1
Marian
Here is a reduced version of my JSON: {<!-- -->   records: [     {<!-- -->       errors: 4       name: name1       plugin: p1       t...
by Marian Explorer in Splunk Search 07-14-2022
0 4
0
4
HelloItsMe76
I have a table like the below   Category   | Time |  Count of string A | t-5mins | 18 A | t-10mins | 7 A | t-15mins |...
by HelloItsMe76 Explorer in Splunk Search 07-14-2022
0 3
0
3
yshen
I want to compare the daily temperature measurements at the same period, but different days by a stacked temperature ...
by yshen Communicator in Splunk Search 07-14-2022
0 2
0
2
Splunk3
Hi , I have created one graph for Success and failure result, but not able to change the color, How I can have the re...
by Splunk3 Explorer in Splunk Search 07-14-2022
0 1
0
1
hettervik
Hi folks. Whenever you do a search in Splunk you can review the lispy in search.log. For example, if I search for my ...
by hettervik Builder in Splunk Search 07-14-2022
0 4
0
4
Ahmedkhalil
Dears, i would like to create chart that contain two different x axis and one y axis using xyseries command but i cou...
by Ahmedkhalil Communicator in Splunk Search 07-14-2022
0 3
0
3
Poojitha
Hi Team,I have a field like below :Cost :0.45655345534530.00004354634660.00213456677880.0000000005657I want to get va...
by Poojitha Communicator in Splunk Search 07-14-2022
0 4
0
4
akshayinnamuri
Hi below is one of the requirementI have multiple lookuptableexample number  name   lookuptable1               abc   ...
by akshayinnamuri Loves-to-Learn Lots in Splunk Search 07-14-2022
0 2
0
2
msallman
I seem to be stuck with the 100 result limit for a subsearch. I've changed maxout&#61; to 10000 in limits.conf (and resta...
by msallman Explorer in Splunk Search 07-14-2022
3 5
3
5
jmc82
What is the Splunk equivalent of an SQL IN clause. I want to run a query where some field has a value which is presen...
by jmc82 Explorer in Splunk Search 07-14-2022
5 14
5
14
neerajs_81
Hi All, I have this simple search that shows logins from same SRC IP  to multiple Destination hosts.  Can someone pls...
by neerajs_81 Builder in Splunk Search 07-14-2022
0 4
0
4
shyam_v
I have two queries from the same set of index and app names using different search terms from which I am extracting a...
by shyam_v New Member in Splunk Search 07-13-2022
0 2
0
2
mchuli934
Hi, I am trying to get all events with two different kinds of objectname(A or B vs C) but with the same username and ...
by mchuli934 Loves-to-Learn Lots in Splunk Search 07-13-2022
0 3
0
3
Get Updates on the Splunk Community!

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...
Top Solution Authors