Splunk Search

Splunk Search
Community Activity
Megz
Hi - I am a relatively novice Splunk user. I am looking at implict vs explicit audit events and looking to do a calcu...
by Megz Explorer in Splunk Search 05-18-2022
0 5
0
5
Aqawelska
Hi ,I need to find the time difference between two events, these events are when a job on our server starts running a...
by Aqawelska Observer in Splunk Search 05-18-2022
0 1
0
1
gszabo
Hello, Help me please. I'd like to define multiple search or subsearch to merge all relevant information about alerts...
by gszabo Explorer in Splunk Search 05-18-2022
0 6
0
6
cecilia_cheng1
Hi Community,I dealt with csv files before, splunk would auto extracted so many fields, shown as figure 1.But today, ...
by cecilia_cheng1 Explorer in Splunk Search 05-18-2022
0 3
0
3
onthakur
below is the data which has multiple features for a single item. I want to write a regex which could search all occur...
by onthakur Explorer in Splunk Search 05-18-2022
0 2
0
2
crucifier_0
My current Splunk regex query10.66.189.62 -- -- -[17/May/2022:05:59:16--0400]--502- "POST /astra/sliceHTTP/1.1" req_l...
by crucifier_0 Explorer in Splunk Search 05-18-2022
0 4
0
4
jip31
hello I count events in a single panel from a relative time like below As you can see, I search only events between 7...
by jip31 Motivator in Splunk Search 05-17-2022
0 5
0
5
sunilr8
i am trying to search over REST API, seeing "All Time searches don't adhere to Splunk best practices" Error.  Any pol...
by sunilr8 New Member in Splunk Search 05-17-2022
0 1
0
1
SMM10
I am working on something to return our alerts from rest functions. What I want to do is allow users to historically ...
by SMM10 Explorer in Splunk Search 05-17-2022
0 5
0
5
Italy1358
I am trying to pull two fields from the lookup_ims lookup table and depending on the user entered I want to populate ...
by Italy1358 Path Finder in Splunk Search 05-17-2022
0 3
0
3
Italy1358
I have created a dashboard that allows you to enter a user and their information then write all of it to a lookup tab...
by Italy1358 Path Finder in Splunk Search 05-17-2022
0 2
0
2
tgmvt03
Hello Everyone. I wonder if anyone could help me with a report I'm trying to make. Below is my sample logs format. lo...
by tgmvt03 Engager in Splunk Search 05-17-2022
0 2
0
2
jip31
hello I try to do a regex for break an url after the fourth slash https://xxxx/yyyy/test could you help please?
by jip31 Motivator in Splunk Search 05-17-2022
0 17
0
17
srujana96
Say suppose we have data for the below date and time range, i want to pick only sunday's date and display the last 3 ...
by srujana96 Explorer in Splunk Search 05-17-2022
0 4
0
4
alexspunkshell
In my splunk logs, i have 2 IPs in 1 field name. I want to extract both IPs create a new field as IP1 & IP2. Please h...
by alexspunkshell Contributor in Splunk Search 05-16-2022
0 2
0
2
tehong
Hi experts, Could you please advise me about SPL? Given the data below, I would like to rewrite the id with a type va...
by tehong Explorer in Splunk Search 05-16-2022
0 2
0
2
jregexsaurus
This search will display port numbers from the Endpoint datamodel | tstats 'summariesonly ' count from datamodel=EndP...
by jregexsaurus Engager in Splunk Search 05-16-2022
0 2
0
2
Julia1231
Hi, I have a chart to display value by time. Then I calculate the average of the value. I want to display the avg nex...
by Julia1231 Communicator in Splunk Search 05-16-2022
0 8
0
8
vikram1583
I have a field properties.policies  in json format  field value: [{"fieldname":"fieldvalue","fieldname":"fieldvalue",...
by vikram1583 Explorer in Splunk Search 05-16-2022
0 2
0
2
SMM10
I want to get an alert and run it but there are items I wanted to remove.   | rest "/servicesNS/-/-/saved/searches" |...
by SMM10 Explorer in Splunk Search 05-16-2022
0 1
0
1
gwalford
How can I pull 3 tokens from a single dropdown search? - I would like our users to select the case_idz, and have the ...
by gwalford Path Finder in Splunk Search 05-16-2022
0 1
0
1
Italy1358
I am trying to create a dashboard for an allowlist. Basically the user should be able to fill in the required fields ...
by Italy1358 Path Finder in Splunk Search 05-16-2022
0 1
0
1
jakeoftrades
Hi,Can anyone help me how can I change the field of my query to exclude those with PRODUCED labelsquery: index="hcg_p...
by jakeoftrades Explorer in Splunk Search 05-16-2022
0 1
0
1
jip31
helloI stats events after 2 eventstats command like this  | eventstats sum(netp) as "netp1" by site | eventstats sum...
by jip31 Motivator in Splunk Search 05-16-2022
0 21
0
21
greekleo89
Hi All,   I've stumbled on a very frustrating problem.  I've created a HEC token to use in Zendesk so that Zendesk ca...
by greekleo89 Loves-to-Learn Everything in Splunk Search 05-16-2022
0 0
0
0
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors