Splunk Search

Splunk Search
Community Activity
paritoshs24
Hi Team, Following is my data: SSTTDTDALTLATOTAaxxx432376ayyy222345bxxx111133byyy111111   following is the graph i ca...
by paritoshs24 Path Finder in Splunk Search 05-12-2022
0 2
0
2
jip31
hello From the dropdown list below, I need to update search events with an eval case command     <input type="dro...
by jip31 Motivator in Splunk Search 05-12-2022
0 12
0
12
mistydennis
Hello Splunkers - I am struggling to create a table that shows distinct events that sometimes have the same timestamp...
by mistydennis Communicator in Splunk Search 05-12-2022
0 4
0
4
kevinjacks
I need help reformatting a MAC address field which doesn't have colons to add them. MAC=123456781122desired format = ...
by kevinjacks Explorer in Splunk Search 05-12-2022
0 6
0
6
nicolocervo
I am importing in splunk many tables of data of 500 to 10000 events each and I need to use them to enrich events with...
by nicolocervo Engager in Splunk Search 05-12-2022
0 1
0
1
mjemi
I want to filter eventcode 4624 and user_type=computer using transforms and props.conf Transforms.conf [setnule]REGEX...
by mjemi Loves-to-Learn Everything in Splunk Search 05-12-2022
0 0
0
0
uagraw01
How to use spath command for the below logs i have attached in the screenshot.
by uagraw01 Motivator in Splunk Search 05-12-2022
0 6
0
6
prateedshetty
I've uploaded the same log twice(using drag and drop option in add data) and now when I query I see duplicate results...
by prateedshetty Path Finder in Splunk Search 05-12-2022
0 6
0
6
johanhakim
Hi,I have 2 separate queries as below:Query1: (normal splunk search e.g. index=* host=abcde | table Message1,Message2...
by johanhakim Explorer in Splunk Search 05-12-2022
0 6
0
6
HattrickNZ
Can you do conditional formatting, like in Excel, in Splunk? For example, can I have conditional formatting on the p...
by HattrickNZ Motivator in Splunk Search 05-12-2022
0 4
0
4
greekleo89
Hi,   I receive data from a particular product that is installed on various customers, that data is received every 5 ...
by greekleo89 Loves-to-Learn Everything in Splunk Search 05-12-2022
0 16
0
16
sanket4147
Hi Team, We are using Splunk Enterprise SIEM tool. we want to check all the source type which is configured for all a...
by sanket4147 Loves-to-Learn Lots in Splunk Search 05-11-2022
0 1
0
1
snandaku
Sample Data: {<!-- -->{"device_id":"a1c842ef8c0545f48e8e61d3e03c68bb","ip":"192.168.193.162","topic":"DEVICE","event":"device...
by snandaku Engager in Splunk Search 05-11-2022
0 10
0
10
k31453
Hi, I have following data which I use search to find from last 30 days and save it into lookup: CustomersOld Acquired...
by k31453 Explorer in Splunk Search 05-11-2022
0 3
0
3
amarmnrao
Hi - I want to list API's and its latencies / response times and want to compare the latencies in a table like below,...
by amarmnrao New Member in Splunk Search 05-11-2022
0 3
0
3
XOJ
I have a sourcetype the provides results for dst if it has one result or dst{} with multiple results. I am attempting...
by XOJ Path Finder in Splunk Search 05-11-2022
0 0
0
0
XOJ
I'm trying to extract fields out of the winevent IIS logs. My regex works in regex101 perfectly. Also I can do someth...
by XOJ Path Finder in Splunk Search 05-11-2022
0 8
0
8
doweaver
I have a dataset where each event summarizes a workflow, using the fields Foo-&gt;Bar-&gt;Baz, and I'm looking to create a ...
by doweaver Path Finder in Splunk Search 05-11-2022
1 15
1
15
splunk_thunk
Hello Experts, I have a transaction query that I am displaying in a table. I am able to get results in a table, howev...
by splunk_thunk Explorer in Splunk Search 05-11-2022
0 6
0
6
cesarbmx
Could someone help me with the Splunk configuration so that the following events show independently in the Splunk sea...
by cesarbmx Engager in Splunk Search 05-11-2022
0 2
0
2
Italy1358
Would like a way to create a drop down with add and remove choices that will then remove or add the user from the loo...
by Italy1358 Path Finder in Splunk Search 05-11-2022
0 6
0
6
tfilip
I'm completely stuck here. I'm trying to extract the "Path" from a logfile with this format:  Time: 05/10/2022 11:26...
by tfilip Engager in Splunk Search 05-11-2022
0 2
0
2
sneha03
Hi Team, We are trying below search:   index&#61;index_123 host&#61;xyz source&#61;"/sys_apps_01/pqr/logs/xyz/mapper_xyz.log" Con...
by sneha03 New Member in Splunk Search 05-11-2022
0 2
0
2
nick_currie
Hi there - I am trying to filter out some noisy rules in a specific firewall (FWCL01) from being ingested into splunk...
by nick_currie Path Finder in Splunk Search 05-11-2022
0 6
0
6
varadack
We have Splunk setup in our firm and our application logs writes TLS connections information that span across multipl...
by varadack Engager in Splunk Search 05-11-2022
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...