Splunk Search

Splunk Search
Community Activity
Becherer
I have events from a device sent to splunk every day seen in the example below. Here is an example of that I want to ...
by Becherer Explorer in Splunk Search 05-20-2022
0 5
0
5
ak9092
Hey Splunkers, I am not sure if this is possible or not but what i was trying to do is something like passing the val...
by ak9092 Path Finder in Splunk Search 05-20-2022
0 3
0
3
jeffh2022
I've got a query I want to run on a daily basis, and write the results to a lookup (# of results once per day) then, ...
by jeffh2022 New Member in Splunk Search 05-20-2022
0 2
0
2
the_rains
We have just started using the IT Essentials App, we are generating alarms based on thresholds being breached, the th...
by the_rains Engager in Splunk Search 05-20-2022
0 0
0
0
Mattjj
Hi all,We are trying to show the bytes/s, averaged over 15 mins.  I'm getting far lower results if I use per_second t...
by Mattjj Explorer in Splunk Search 05-20-2022
0 0
0
0
asdinesh
I want to convert the result from https://community.splunk.com/t5/Splunk-Search/Find-users-who-have-done-an-event-A-b...
by asdinesh Engager in Splunk Search 05-20-2022
0 3
0
3
girtsgr
Hi, I seem to be stuck with something pretty trivial. I have events with users and corresponding hostnames, eg: UserH...
by girtsgr Explorer in Splunk Search 05-20-2022
0 2
0
2
nicolass
Hello! Splunk newbie here - I was hoping to get some advice on how to condense this search query I have. Is there ano...
by nicolass Engager in Splunk Search 05-20-2022
0 2
0
2
Khanu89
Hello - Thank you in advance for the help. I am getting following raw data in Splunk events which I'd like to pull in...
by Khanu89 Path Finder in Splunk Search 05-19-2022
0 9
0
9
dezmadi
Hi,   I am using below query in my Dashboard index="deng03-cis-dev-audit" | spath PATH=data.labels.verbose_message ou...
by dezmadi Path Finder in Splunk Search 05-19-2022
0 2
0
2
dzyfer
Hi, I have a timechart that is currently split into 8-hour shift bins, however as it is a timechart, the x-axis only ...
by dzyfer Path Finder in Splunk Search 05-19-2022
0 1
0
1
manojntr
Here is the example of the search looks like : index=x* OR index=y* OR index=z* Iabcd 12_* ( earliest=05/09/2022:00:0...
by manojntr Observer in Splunk Search 05-19-2022
0 4
0
4
ritesh14
|>TYPE|2022-04-25 18:38:40|2d7e908bo82cb8|1725357403659|HERE|TYPE/272|1,856|1.2.0|ABC|351c481f2de|NONE<||>TYPE|2022-0...
by ritesh14 Explorer in Splunk Search 05-19-2022
0 2
0
2
kpavan
Hi, am trying to find list of ip's from search1 which are missing in search2 and get all the ip from search1 and calc...
by kpavan Path Finder in Splunk Search 05-19-2022
0 3
0
3
khayamgondal
I have a field with the following values. How can I calculate the product i.e multiply all values with each other? Th...
by khayamgondal Engager in Splunk Search 05-19-2022
0 1
0
1
ahadalioglu
Hi there,I want to filter out some records if they match multiple criteria, for example:host   service  state========...
by ahadalioglu Explorer in Splunk Search 05-19-2022
0 11
0
11
nalagito
Hello, I have this query:     | mstats avg(_value) as packets WHERE index=metrics_index sourcetype=network_metrics (m...
by nalagito Loves-to-Learn Lots in Splunk Search 05-19-2022
0 3
0
3
Italy1358
Here is my xml code so far:<form version="1.1" theme="dark"><init><set token="none">None</set><set token="tokTypeInpu...
by Italy1358 Path Finder in Splunk Search 05-19-2022
0 0
0
0
Julia1231
Hi,I have a table like this:id       value1            122             10I want to do this calculation by splunk: (10...
by Julia1231 Communicator in Splunk Search 05-19-2022
0 6
0
6
flo_cognosec
I could then populate a dropdown list with indices  Somehow I could not get this done, would be cool if somebody cou...
by flo_cognosec Communicator in Splunk Search 05-19-2022
15 32
15
32
shashaikhhh
Hi,This is splunk query and it returns nested JSON object  Query:sourcetype=_json_fluentd source="***" | search messa...
by shashaikhhh Explorer in Splunk Search 05-19-2022
0 4
0
4
badrinath
I am unable to use time picker in real time in classic dashboard is it not supported or am I having this problem.  so...
by badrinath Path Finder in Splunk Search 05-19-2022
0 5
0
5
ashidhingra
search Items NOT present in Indexfor exampleif day = Mon,tues,wedoutput query1 and query3 (as two separate  tables)if...
by ashidhingra Path Finder in Splunk Search 05-18-2022
0 1
0
1
ajdyer2000
Hi. Has any one come across  hidden Double Quotes (") in a field and how to remove it? (maybe a "sed" regex) The doub...
by ajdyer2000 Path Finder in Splunk Search 05-18-2022
0 3
0
3
ankurborah
Getting below error message on SH message box:  Search peer <Indexer_host> has the following message: Problem replica...
by ankurborah Path Finder in Splunk Search 05-18-2022
0 7
0
7
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...