Splunk Search

Splunk Search
Community Activity
ericvdhout
Hi, Am quite new to splunk, and coming from Elasticsearch, so my knowledge is biased. However I did notice that Elast...
by ericvdhout Path Finder in Splunk Search 05-06-2022
0 14
0
14
jip31
hi i add a + or a - sign before a percent result like this   | eval perc=if(s<2,"-","+").round((s/2)*100,1). "% "   ...
by jip31 Motivator in Splunk Search 05-06-2022
0 1
0
1
lost_alex
Dear community, I am using this community since years, so far I've found everything I needed. Now I am stuck!!! I am ...
by lost_alex Observer in Splunk Search 05-06-2022
0 2
0
2
spl10
Hi Team,I am trying to take the backup of lookups using search head console and for the same I have tried two ways.a)...
by spl10 Explorer in Splunk Search 05-06-2022
0 2
0
2
BT
2 events : request and response and unique id which binds this transaction. I have  issue where i have to calculate t...
by BT Path Finder in Splunk Search 05-06-2022
0 5
0
5
morgantay96
Hi all need help getting the trailing number from a field in a search. Examples of the fieldid = bdf73ad5-4499-4f70-b...
by morgantay96 Path Finder in Splunk Search 05-05-2022
0 3
0
3
trengginas
hi am newbie I have a duration time value with the format "1d hh:mm:ss"but I haven't gotten a thread that discusses s...
by trengginas Engager in Splunk Search 05-05-2022
0 2
0
2
jakeoftrades
hi,Can someone help to correct the query provided below which will send alert if detected a STOPPED status for 3 cons...
by jakeoftrades Explorer in Splunk Search 05-05-2022
0 11
0
11
cybersecnutant
We have a 3rd party pulling AWS logs as far back as AWS holds onto logs. However, we want to be able to go back furth...
by cybersecnutant Explorer in Splunk Search 05-05-2022
0 1
0
1
PatelAshish83
Is there a way to create a report using metadata or any other data to list all the fields that are available by index...
by PatelAshish83 Engager in Splunk Search 05-05-2022
0 5
0
5
p4085f9
Hi allI have a riddle. Query A and query B does not collect the same events and I don’t understand why.Query A) resul...
by p4085f9 Engager in Splunk Search 05-05-2022
0 2
0
2
secphilomath
Is there a way to do a search like this; If Eventid=1111     only do these  statements elseif Eventid=2222     only d...
by secphilomath New Member in Splunk Search 05-05-2022
0 3
0
3
Newser703
Hello I have data that looks like this :  Name | Type | Value ------------------------------------------ Name1 | Type...
by Newser703 Explorer in Splunk Search 05-05-2022
0 1
0
1
swengroeneveld
We are working to enhance our potential bot-traffic blocking and would like to see every IP that has hit AWS cloudfro...
by swengroeneveld Explorer in Splunk Search 05-05-2022
0 2
0
2
VijaySrrie
I have 2 events 1) request event 2) response event I need response time to be calculated (i.e) request event time - r...
by VijaySrrie Builder in Splunk Search 05-05-2022
0 6
0
6
doniv
Hi, I want to compare the count of calls obtained in a day with the target in lookup csv, for example: input csv: hea...
by doniv Loves-to-Learn Lots in Splunk Search 05-05-2022
0 6
0
6
srujana96
i have the 2 values let's sayexpected time= 6:00:00completion time= 08:32:44and the expected output should be the dif...
by srujana96 Explorer in Splunk Search 05-04-2022
0 2
0
2
sanjubaba
I am preparing a SNOW incident trend which should showcase the percentage of tickets reduced/increased in current mon...
by sanjubaba Path Finder in Splunk Search 05-04-2022
0 1
0
1
martin61
I want to get QID list from yesterday’s published data.  For that I'm using PUBLISHED_DATETIME field with yesterday’s...
by martin61 Engager in Splunk Search 05-04-2022
0 1
0
1
gfisbeck
I have a lookup table that lists all users along with their department like so:   email department -----...
by gfisbeck Explorer in Splunk Search 05-04-2022
0 7
0
7
bogdan_nicolesc
So i have this:     (index=* OR index=_*) (index="GA2014" EventCode=4625) | dedup RecordNumber | rename Account_Name ...
by bogdan_nicolesc Communicator in Splunk Search 05-04-2022
0 0
0
0
manhalmoussa
Hello my fellow Splunkers,i am trying to use a second index as a lookup for a field in the first index index=products...
by manhalmoussa Explorer in Splunk Search 05-04-2022
0 3
0
3
XJabs
Hello,So I have been working on this for a few days, looking at numerous Splunk responses but have yet to find someth...
by XJabs Explorer in Splunk Search 05-04-2022
0 6
0
6
cesar_tomas
Hi everyone, I am new to Splunk and  I have been trying to do a complex report that I haven't been able to solve so p...
by cesar_tomas Explorer in Splunk Search 05-04-2022
0 1
0
1
joe06031990
Hi, I have a dashboard with multiple table views from different indexes and just wondered if it is possible to combin...
by joe06031990 Communicator in Splunk Search 05-04-2022
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...