Splunk Search

Splunk Search
Community Activity
jlvix1
Plenty of people struggle with this and with no definitive answer either... Unless someone cares to point something ...
by jlvix1 Communicator in Splunk Search 05-09-2022
0 18
0
18
denissotoacc
Hello all, We receive the "splunkd.log" from every Universal Forwarder into our "_internal" index.  There are some ev...
by denissotoacc Path Finder in Splunk Search 05-09-2022
0 4
0
4
el666nino
hello , i want to detect foreign ip at first step, then search in traffic for connections between foreign ip and othe...
by el666nino Loves-to-Learn Everything in Splunk Search 05-09-2022
0 0
0
0
Midge87
Hi, I have a very basic timechart from the below search. Just counts the number of events=40 (event ID). The issue is...
by Midge87 Explorer in Splunk Search 05-09-2022
0 6
0
6
DS904458
Hi all,I'm not a English native speaker, but I will do my best to explain ther question.To be clear, I need done this...
by DS904458 Explorer in Splunk Search 05-09-2022
0 4
0
4
neerajs_81
Hello,I have the below search   <base search>.. |stats values(Source) as Source count min(_time) as firstTime max(_ti...
by neerajs_81 Builder in Splunk Search 05-08-2022
0 3
0
3
ednk
Hi  I have for each event the open_time and update_time, I want to calculate the age of the event, like:  open_time  ...
by ednk Explorer in Splunk Search 05-08-2022
0 3
0
3
indeed_2000
hi how exactly cluster commad work?I have lots of unstructured data that has different key and value, how splunk dete...
by indeed_2000 Motivator in Splunk Search 05-07-2022
0 0
0
0
jugarugabi
Hi,  I am having the following query:  index=* sourcetype=CustomAccessLog | table "host", "source"   The output is: h...
by jugarugabi Path Finder in Splunk Search 05-06-2022
0 2
0
2
bosseres
Hello, everyone! I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any...
by bosseres Contributor in Splunk Search 05-06-2022
0 1
0
1
sarahnazzar
Hello Splunkers! Initially I added the monitor stanza for all the inputs from various time zones and then when I had ...
by sarahnazzar Explorer in Splunk Search 05-06-2022
0 4
0
4
ericvdhout
Hi, Am quite new to splunk, and coming from Elasticsearch, so my knowledge is biased. However I did notice that Elast...
by ericvdhout Path Finder in Splunk Search 05-06-2022
0 14
0
14
jip31
hi i add a + or a - sign before a percent result like this   | eval perc=if(s<2,"-","+").round((s/2)*100,1). "% "   ...
by jip31 Motivator in Splunk Search 05-06-2022
0 1
0
1
lost_alex
Dear community, I am using this community since years, so far I've found everything I needed. Now I am stuck!!! I am ...
by lost_alex Observer in Splunk Search 05-06-2022
0 2
0
2
spl10
Hi Team,I am trying to take the backup of lookups using search head console and for the same I have tried two ways.a)...
by spl10 Explorer in Splunk Search 05-06-2022
0 2
0
2
BT
2 events : request and response and unique id which binds this transaction. I have  issue where i have to calculate t...
by BT Path Finder in Splunk Search 05-06-2022
0 5
0
5
morgantay96
Hi all need help getting the trailing number from a field in a search. Examples of the fieldid = bdf73ad5-4499-4f70-b...
by morgantay96 Path Finder in Splunk Search 05-05-2022
0 3
0
3
trengginas
hi am newbie I have a duration time value with the format "1d hh:mm:ss"but I haven't gotten a thread that discusses s...
by trengginas Engager in Splunk Search 05-05-2022
0 2
0
2
jakeoftrades
hi,Can someone help to correct the query provided below which will send alert if detected a STOPPED status for 3 cons...
by jakeoftrades Explorer in Splunk Search 05-05-2022
0 11
0
11
cybersecnutant
We have a 3rd party pulling AWS logs as far back as AWS holds onto logs. However, we want to be able to go back furth...
by cybersecnutant Explorer in Splunk Search 05-05-2022
0 1
0
1
PatelAshish83
Is there a way to create a report using metadata or any other data to list all the fields that are available by index...
by PatelAshish83 Engager in Splunk Search 05-05-2022
0 5
0
5
p4085f9
Hi allI have a riddle. Query A and query B does not collect the same events and I don’t understand why.Query A) resul...
by p4085f9 Engager in Splunk Search 05-05-2022
0 2
0
2
secphilomath
Is there a way to do a search like this; If Eventid=1111     only do these  statements elseif Eventid=2222     only d...
by secphilomath New Member in Splunk Search 05-05-2022
0 3
0
3
Newser703
Hello I have data that looks like this :  Name | Type | Value ------------------------------------------ Name1 | Type...
by Newser703 Explorer in Splunk Search 05-05-2022
0 1
0
1
swengroeneveld
We are working to enhance our potential bot-traffic blocking and would like to see every IP that has hit AWS cloudfro...
by swengroeneveld Explorer in Splunk Search 05-05-2022
0 2
0
2
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...