Splunk Search

Splunk Search
Community Activity
ft_kd02
Hi all,I'm in the process of setting up performance reporting for services provided for a client. The logic in questi...
by ft_kd02 Path Finder in Splunk Search 05-23-2022
0 1
0
1
marnee
Can you alter the Splunk search used for an alert? I don't see any way to alter it. I am being asked to choose a pr...
by marnee Explorer in Splunk Search 05-23-2022
2 8
2
8
Italy1358
When a user is added i need the time to be recorded and displayed in a field called used_added. I created the field n...
by Italy1358 Path Finder in Splunk Search 05-23-2022
0 1
0
1
vrmandadi
I am trying to  create a search  which will give the difference in count for a field called "id" and show what are th...
by vrmandadi Builder in Splunk Search 05-23-2022
0 5
0
5
dezmadi
I have below query as query returning  null   <search id="dfLatencyOverallProcessingDelayBaseSearch"> <query>index="d...
by dezmadi Path Finder in Splunk Search 05-23-2022
0 1
0
1
dezmadi
I want to hide columName from 2nd row onwards for below table <row><panel><title>STATS : SLI/SLO Dashboard count</tit...
by dezmadi Path Finder in Splunk Search 05-23-2022
1 1
1
1
TB
Hi,I am trying to create a table but how do I  extract these information in my query? I tried double quote " " but it...
by TB New Member in Splunk Search 05-22-2022
0 1
0
1
RiberaJoice
I have a query to fetch account create endpoint and errors after   (index=foo "account/create") OR (index=bar ERROR) ...
by RiberaJoice Splunk Employee Splunk Employee in Splunk Search 05-21-2022
0 1
0
1
seajay1221
I have an index with ~200 fields and need to know the single most common non-null value for each field. How do I unco...
by seajay1221 Engager in Splunk Search 05-20-2022
0 2
0
2
Rodrigo_Larios
Hi guys,  This is one example of my data: Optional("{\"operationName\":\"createCart\",\"variables\":{\"customerId\":\...
by Rodrigo_Larios Explorer in Splunk Search 05-20-2022
0 1
0
1
fatsug
Hi, if someone could help me out with, or point me in a nice direction to, producing a search which shows if/when a t...
by fatsug Builder in Splunk Search 05-20-2022
0 5
0
5
Pat
When doing an extracted field can the regex named capture group be based on a back reference.  The idea is I would ha...
by Pat Path Finder in Splunk Search 05-20-2022
0 1
0
1
g_paternicola
Hi everyone,  I'm trying to get the following search work, but for some reason I'm doing something wrong: inputlookup...
by g_paternicola Path Finder in Splunk Search 05-20-2022
0 3
0
3
denissotoacc
I have the following _raw field in my index: _raw Response Headers: {'Date': 'Fri, 13 May 2022 02:59:3...
by denissotoacc Path Finder in Splunk Search 05-20-2022
0 3
0
3
JoeHubner
I would like to add a column to a chart that is the difference of the two columns before it in an application where I...
by JoeHubner Explorer in Splunk Search 05-20-2022
0 2
0
2
Gzuluaga
Hi, I'm pretty new in splunk, I've been reading a lot of documentation and other questions here, but I don't find the...
by Gzuluaga Explorer in Splunk Search 05-20-2022
0 7
0
7
crucifier_0
Hey, i want a regex result from 10.66.189.62 -- -- -[17/May/2022:05:59:16--0400]--502- "POST /astra/sliceHTTP/1.1" re...
by crucifier_0 Explorer in Splunk Search 05-20-2022
0 1
0
1
Bradd23
Hi i'm trying to capture 2 fields, the first part of this word (LON) and the remaining (RTI2_SND.TRACE) within the sa...
by Bradd23 Loves-to-Learn Lots in Splunk Search 05-20-2022
0 1
0
1
Becherer
I have events from a device sent to splunk every day seen in the example below. Here is an example of that I want to ...
by Becherer Explorer in Splunk Search 05-20-2022
0 5
0
5
ak9092
Hey Splunkers, I am not sure if this is possible or not but what i was trying to do is something like passing the val...
by ak9092 Path Finder in Splunk Search 05-20-2022
0 3
0
3
jeffh2022
I've got a query I want to run on a daily basis, and write the results to a lookup (# of results once per day) then, ...
by jeffh2022 New Member in Splunk Search 05-20-2022
0 2
0
2
the_rains
We have just started using the IT Essentials App, we are generating alarms based on thresholds being breached, the th...
by the_rains Engager in Splunk Search 05-20-2022
0 0
0
0
Mattjj
Hi all,We are trying to show the bytes/s, averaged over 15 mins.  I'm getting far lower results if I use per_second t...
by Mattjj Explorer in Splunk Search 05-20-2022
0 0
0
0
asdinesh
I want to convert the result from https://community.splunk.com/t5/Splunk-Search/Find-users-who-have-done-an-event-A-b...
by asdinesh Engager in Splunk Search 05-20-2022
0 3
0
3
girtsgr
Hi, I seem to be stuck with something pretty trivial. I have events with users and corresponding hostnames, eg: UserH...
by girtsgr Explorer in Splunk Search 05-20-2022
0 2
0
2
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors