Splunk Search

Splunk Search
Community Activity
edwinmae
Hi, I try to calculate the duration I have extracted 2 fields, start_time and end_time -- I believe both times shoul...
by edwinmae Path Finder in Splunk Search 06-03-2022
0 2
0
2
yaharga
I have a field called query that's like so:(index="abc" OR index="def") (host="ghi" OR host="jkl") (sourcetype="mno" ...
by yaharga Path Finder in Splunk Search 06-03-2022
0 7
0
7
KMoryson
Hi, I am working on a way to find an orphaned asset based on asset inventory I have in a lookup, which looks somethin...
by KMoryson Explorer in Splunk Search 06-03-2022
0 4
0
4
Sasti
Hi All,      I'm trying to extract the username from the _raw field using regex, how do I extract the username. The u...
by Sasti Engager in Splunk Search 06-03-2022
0 6
0
6
michael92956
Hopefully I can explain this in a way where it can be understood and fingers crossed answered.  I have a search that ...
by michael92956 New Member in Splunk Search 06-03-2022
0 1
0
1
sashib
Hi I need to extract only name values (first word value eg:james) from the below Name filed I tried with  rex field=N...
by sashib Explorer in Splunk Search 06-03-2022
0 4
0
4
heavenisreal
Hi There, I am trying to generate a choropleth map of US using the following command :| iplocation final_ip|search Co...
by heavenisreal Loves-to-Learn Lots in Splunk Search 06-02-2022
0 5
0
5
juliop3p
Hi guys, I'm a Splunk beginner and I'm having some trouble making a specific query. I have a health check log, I want...
by juliop3p Explorer in Splunk Search 06-02-2022
0 1
0
1
heavenisreal
Hi There, How do I showcase only US on the choropleth map for the dashboard? That is the dashboard panel should have ...
by heavenisreal Loves-to-Learn Lots in Splunk Search 06-02-2022
0 0
0
0
KyleMcDougall
Hello, I'm trying to pull the final value for a product name. In a single event, we make multiple calls to an API for...
by KyleMcDougall Path Finder in Splunk Search 06-02-2022
0 1
0
1
dw_jcro
To start - I was suggested this solution, but despite the fact that the question is very similar the answer marked as...
by dw_jcro Loves-to-Learn Lots in Splunk Search 06-02-2022
0 5
0
5
MatBav
Hey guys, I hope you're doing well,    I didn't receive the SMS verification code or SMS alters on the Splunk on-call...
by MatBav New Member in Splunk Search 06-02-2022
0 0
0
0
blurblebot
Is there any way to make Splunk stop a search once it has found the first event matching your search? limit=1 in the...
by blurblebot Communicator in Splunk Search 06-02-2022
1 3
1
3
dpatel01
Hi Splunkers, I am stuck at how can I get counts for Yesterday and Last week. so ask is when select relative time fro...
by dpatel01 Loves-to-Learn in Splunk Search 06-02-2022
0 2
0
2
Jasper
Hello all, I had a question that I have been trying to figure out how to address within a concise SPL query.  I have ...
by Jasper Loves-to-Learn Lots in Splunk Search 06-02-2022
0 2
0
2
aroc725
Is there a way to change the order of the "stack_trace" attribute, so it shows up last within the log message ?
by aroc725 Loves-to-Learn in Splunk Search 06-02-2022
0 6
0
6
indeed_2000
Hi I have table like this: name    color           status jack        red               fail jack        blue        ...
by indeed_2000 Motivator in Splunk Search 06-02-2022
0 18
0
18
indeed_2000
hi need to calculate count and percentage of fields. orginal post here, the main issue is fields contain space or bal...
by indeed_2000 Motivator in Splunk Search 06-02-2022
0 1
0
1
ruhibansal
I have json in following format. { "timestamp": "1625577829075", "debug": "true", "A_real": { "Sig1": { ...
by ruhibansal Explorer in Splunk Search 06-02-2022
0 4
0
4
saurabhbdwj
index="SOMETHING"  earliest=-30d@d| stats earliest(_time) as action_StartTime latest(_time) as action_EndTime| eval e...
by saurabhbdwj Engager in Splunk Search 06-02-2022
0 2
0
2
Woodpecker
Hi,I have an SPL, which should exclude the ip values from 4 lookups. So i tried it with a subsearch approach. But thi...
by Woodpecker Path Finder in Splunk Search 06-01-2022
0 1
0
1
-Chris-
How does Splunk calculate Time to Triage, what data does it use? e.g. time an event occurred and time the event was p...
by -Chris- Observer in Splunk Search 06-01-2022
0 3
0
3
cvg1wby
I have a macro that starts with a search command.  When I ran it, I noticed I was getting a different number of resul...
by cvg1wby Explorer in Splunk Search 06-01-2022
0 2
0
2
agallegos
I am trying to do a search where by:   index=firewall (src_ip=172.16.0.0/12)  dest_ip!(172.16.0.0/12) | table src_ip ...
by agallegos Engager in Splunk Search 06-01-2022
0 3
0
3
Robert11
I am running Splunk Enterprise and am trying to create a dashboard panel "Events" search string that pulls multiple W...
by Robert11 Path Finder in Splunk Search 06-01-2022
0 6
0
6
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors