Splunk Search

Splunk Search
Community Activity
the_rains
We have just started using the IT Essentials App, we are generating alarms based on thresholds being breached, the th...
by the_rains Engager in Splunk Search 05-20-2022
0 0
0
0
Mattjj
Hi all,We are trying to show the bytes/s, averaged over 15 mins.  I'm getting far lower results if I use per_second t...
by Mattjj Explorer in Splunk Search 05-20-2022
0 0
0
0
asdinesh
I want to convert the result from https://community.splunk.com/t5/Splunk-Search/Find-users-who-have-done-an-event-A-b...
by asdinesh Engager in Splunk Search 05-20-2022
0 3
0
3
girtsgr
Hi, I seem to be stuck with something pretty trivial. I have events with users and corresponding hostnames, eg: UserH...
by girtsgr Explorer in Splunk Search 05-20-2022
0 2
0
2
nicolass
Hello! Splunk newbie here - I was hoping to get some advice on how to condense this search query I have. Is there ano...
by nicolass Engager in Splunk Search 05-20-2022
0 2
0
2
Khanu89
Hello - Thank you in advance for the help. I am getting following raw data in Splunk events which I'd like to pull in...
by Khanu89 Path Finder in Splunk Search 05-19-2022
0 9
0
9
dezmadi
Hi,   I am using below query in my Dashboard index="deng03-cis-dev-audit" | spath PATH=data.labels.verbose_message ou...
by dezmadi Path Finder in Splunk Search 05-19-2022
0 2
0
2
dzyfer
Hi, I have a timechart that is currently split into 8-hour shift bins, however as it is a timechart, the x-axis only ...
by dzyfer Path Finder in Splunk Search 05-19-2022
0 1
0
1
manojntr
Here is the example of the search looks like : index=x* OR index=y* OR index=z* Iabcd 12_* ( earliest=05/09/2022:00:0...
by manojntr Observer in Splunk Search 05-19-2022
0 4
0
4
ritesh14
|>TYPE|2022-04-25 18:38:40|2d7e908bo82cb8|1725357403659|HERE|TYPE/272|1,856|1.2.0|ABC|351c481f2de|NONE<||>TYPE|2022-0...
by ritesh14 Explorer in Splunk Search 05-19-2022
0 2
0
2
kpavan
Hi, am trying to find list of ip's from search1 which are missing in search2 and get all the ip from search1 and calc...
by kpavan Path Finder in Splunk Search 05-19-2022
0 3
0
3
khayamgondal
I have a field with the following values. How can I calculate the product i.e multiply all values with each other? Th...
by khayamgondal Engager in Splunk Search 05-19-2022
0 1
0
1
ahadalioglu
Hi there,I want to filter out some records if they match multiple criteria, for example:host   service  state========...
by ahadalioglu Explorer in Splunk Search 05-19-2022
0 11
0
11
nalagito
Hello, I have this query:     | mstats avg(_value) as packets WHERE index=metrics_index sourcetype=network_metrics (m...
by nalagito Loves-to-Learn Lots in Splunk Search 05-19-2022
0 3
0
3
Italy1358
Here is my xml code so far:<form version="1.1" theme="dark"><init><set token="none">None</set><set token="tokTypeInpu...
by Italy1358 Path Finder in Splunk Search 05-19-2022
0 0
0
0
Julia1231
Hi,I have a table like this:id       value1            122             10I want to do this calculation by splunk: (10...
by Julia1231 Communicator in Splunk Search 05-19-2022
0 6
0
6
flo_cognosec
I could then populate a dropdown list with indices  Somehow I could not get this done, would be cool if somebody cou...
by flo_cognosec Communicator in Splunk Search 05-19-2022
15 32
15
32
shashaikhhh
Hi,This is splunk query and it returns nested JSON object  Query:sourcetype=_json_fluentd source="***" | search messa...
by shashaikhhh Explorer in Splunk Search 05-19-2022
0 4
0
4
badrinath
I am unable to use time picker in real time in classic dashboard is it not supported or am I having this problem.  so...
by badrinath Path Finder in Splunk Search 05-19-2022
0 5
0
5
ashidhingra
search Items NOT present in Indexfor exampleif day = Mon,tues,wedoutput query1 and query3 (as two separate  tables)if...
by ashidhingra Path Finder in Splunk Search 05-18-2022
0 1
0
1
ajdyer2000
Hi. Has any one come across  hidden Double Quotes (") in a field and how to remove it? (maybe a "sed" regex) The doub...
by ajdyer2000 Path Finder in Splunk Search 05-18-2022
0 3
0
3
ankurborah
Getting below error message on SH message box:  Search peer <Indexer_host> has the following message: Problem replica...
by ankurborah Path Finder in Splunk Search 05-18-2022
0 7
0
7
RemyaT
Given below is a snippet of splunk event. My requirement is to find all the occurrences of "isOutstanding": true. Her...
by RemyaT Explorer in Splunk Search 05-18-2022
0 4
0
4
ashidhingra
if statement to output multiple tables in splunk?For example I have 3 tables that have the following dataTable 1 AA 1...
by ashidhingra Path Finder in Splunk Search 05-18-2022
0 5
0
5
chambooca
I'm an intermediate Splunk user.  I have a query that has 3 fields i want to turn into a chart:1. mySearchTerm (strin...
by chambooca Observer in Splunk Search 05-18-2022
0 1
0
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...