Splunk Search

Splunk Search
Community Activity
FBachelin
Hi everyone, I have a search on approval success rates : stats count as TOTAL,count(eval(criteria)) as APPROVED | eva...
by FBachelin Engager in Splunk Search 07-01-2022
0 3
0
3
ballen1
Command:rex mode=sed "s/\"name":\s\"[^\"]+\"/"name":"###############"/g"Regex seems to work fine in Regex101 However,...
by ballen1 Explorer in Splunk Search 07-01-2022
0 4
0
4
timo258
Hi!I have 3 multivalue fields (max. 3 values per field) and I want to expand/extract them to single values. Data look...
by timo258 Explorer in Splunk Search 07-01-2022
0 8
0
8
Italy1358
Can someone help me pull out these data points:cw.pptx;text.html;text.txtI need it to split at the ; mark but have th...
by Italy1358 Path Finder in Splunk Search 07-01-2022
0 1
0
1
phamxuantung
Hello,I have an alert that output a csv file that look like thisPersonNumber_of_loginLogin_failPerson A1 Person B62Pe...
by phamxuantung Communicator in Splunk Search 07-01-2022
0 3
0
3
james_n
Hi experts, I have a filed called names as shown below, if i search with first line of strings then search returning ...
by james_n Path Finder in Splunk Search 07-01-2022
0 4
0
4
zsaf
  I have two columns per event I am trying to use. Well call these col1 and UknownRandomColumnName (urcn for short...
by zsaf Explorer in Splunk Search 07-01-2022
0 5
0
5
lmonahan
I want to run a query where: 1. Query1 returns resultset1containing myEvent1.uid 2. Query2 returns resultset2 contain...
by lmonahan Path Finder in Splunk Search 06-30-2022
0 2
0
2
simon1524
There is something wrong with the data output by using apendcols. The data of Total_Actual is blank from 02-2022. But...
by simon1524 Explorer in Splunk Search 06-30-2022
0 2
0
2
fereze
Hi I have a table similar to this: Brand ID_EMP Nike 123 Adidas 456 Lotto 123   other table like this: code name 123 ...
by fereze Engager in Splunk Search 06-30-2022
0 1
0
1
Seawheels51
Greetings Community ExpertsI have a group of devices that each should report state to a portal every 10 seconds. If a...
by Seawheels51 Path Finder in Splunk Search 06-30-2022
0 1
0
1
dmuley
2022-06-12 21:51:42.274 threadId=L4C9D6WIYK2K eventType="RESPONSE" data="<TestRQ>sometestdata</TestRQ>"2022-06-12 21:...
by dmuley Explorer in Splunk Search 06-30-2022
0 4
0
4
sajalbansal2
Hi Everyone, There's a small problem I'm having while using the ltrim function.Query: | makeresults | eval username="...
by sajalbansal2 Explorer in Splunk Search 06-30-2022
0 2
0
2
Splunkee
Hi, I would like to return the rex "field" from a subquery so I can print it out. How do I do that?index=... "some te...
by Splunkee Loves-to-Learn in Splunk Search 06-30-2022
0 8
0
8
splunknoob2
Hello, I have a question regarding the indexing of search results. So, I have an alert that's currently active perfor...
by splunknoob2 Observer in Splunk Search 06-30-2022
0 3
0
3
lboro_garyp
I'm struggling to create a search using an inputlookup and multiple NOT searches. Background: I have an inputlookup t...
by lboro_garyp Path Finder in Splunk Search 06-30-2022
0 3
0
3
pagnihot
Hey CommunityNeed guidance with below scenario.A user will provide an IP address as input. I want that last two octet...
by pagnihot Path Finder in Splunk Search 06-30-2022
0 5
0
5
splunkmagu
Hi,I'm using splunk web to check some searches/alerts:1. | rest /servicesNS/-/-/saved/searches/ splunk_server=local |...
by splunkmagu Explorer in Splunk Search 06-30-2022
0 1
0
1
SimonTurton
I have managed to pull together the following | mstats max(_value) prestats=true WHERE metric_name="df.used" span=1mo...
by SimonTurton New Member in Splunk Search 06-30-2022
0 1
0
1
ymcardinal
Hello, I am running the following search via the API: search index=juniper sourcetype=juniper:junos:firewall "3389"| ...
by ymcardinal New Member in Splunk Search 06-30-2022
0 0
0
0
splunkmagu
Hello,I have created a few indexes, each containing data only from one source with one sourcetype.From a search perfo...
by splunkmagu Explorer in Splunk Search 06-29-2022
0 6
0
6
DempseyWilliams
I need some help figuring out why my sed replace command is replacing all of the text to the end of the event in Splu...
by DempseyWilliams Explorer in Splunk Search 06-29-2022
0 5
0
5
mjon395
Hello, It's possible that I've had too long of a day, but I can't wrap my head around nesting many ifs.  Is anyone wi...
by mjon395 Explorer in Splunk Search 06-29-2022
0 2
0
2
Rithekakan
I have a result of Vulneraries Scan of Quater1, Quater2 , Quarter3 and the remediate scan result of each Quarter ... ...
by Rithekakan Path Finder in Splunk Search 06-29-2022
0 1
0
1
Sweet_Desire123
Hey guys , I need last 30 days stats for the use-cases that did not fire up on the ES console. Below is the query tha...
by Sweet_Desire123 Engager in Splunk Search 06-29-2022
0 3
0
3
Get Updates on the Splunk Community!

Recap | Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Recap | Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...
Top Solution Authors