Splunk Search

Splunk Search
Community Activity
Woodpecker
Hello,I am trying to join two searches for see, same hash exists on the other index as well. Below is my search, the ...
by Woodpecker Path Finder in Splunk Search 05-04-2022
0 3
0
3
nvwls
Given json with hashes     | makeresults | eval _raw="{\"yes\":true,\"no\":false,\"a\":{\"x\":0,\"y\":0,\"z\":0},\"c...
by nvwls New Member in Splunk Search 05-03-2022
0 2
0
2
Glasses
Scenario:We have a data source of interest that we wish to analyze.The data source is hourly host activity events.An ...
by Glasses Builder in Splunk Search 05-03-2022
1 4
1
4
Kislac
Hello! I would like to count from a field based on another field.I have a events with following  2 fields (Doors_Orde...
by Kislac Engager in Splunk Search 05-03-2022
0 1
0
1
rpecka
I would like to narrow down my results and rename a few fields using an initial search, let's call these results A.Th...
by rpecka Explorer in Splunk Search 05-03-2022
0 3
0
3
charbaugh77
I have a .net core application that logs various events with properties (WorkItem, EventName, etc).I need to query Wo...
by charbaugh77 Explorer in Splunk Search 05-03-2022
0 9
0
9
zapping575
Hi everybody, I have the following problem and cannot seem to be able to wrap my head around it: I have a bunch of ev...
by zapping575 Communicator in Splunk Search 05-03-2022
0 4
0
4
JeffPoretsky
User of splunk attempted a search of index="os" It returns nothing after Dec 23. (Yes this went unnoticed for this lo...
by JeffPoretsky Loves-to-Learn in Splunk Search 05-03-2022
0 13
0
13
Software-Simian
Hello,   i was actually hoping that would be rather straight forward. I can set width for panels, inputs, single char...
by Software-Simian Path Finder in Splunk Search 05-03-2022
0 0
0
0
jonaclough
Is there a way of showing a warning to the user based on their SPL. My use case is that users should not generally se...
by jonaclough Path Finder in Splunk Search 05-03-2022
0 2
0
2
dkssingh2005
while searching through all time  in filter  drop down, i am getting NaN value for "$tokLatest$", I don't know why it...
by dkssingh2005 Explorer in Splunk Search 05-03-2022
0 2
0
2
vijay_k
I have column with Multiple Values separated by new line character Type is the column  ID     Type          Type_A 01...
by vijay_k Engager in Splunk Search 05-03-2022
0 1
0
1
woodams
I have several fields I want to lump into 1 multivalue field and remove blanks. At the start of an event, there are u...
by woodams Explorer in Splunk Search 05-03-2022
0 1
0
1
neerajs_81
Hi All,I need to correlate data from 2 different Indexes wherein the field name is common.  Index=idx1  ( This index ...
by neerajs_81 Builder in Splunk Search 05-02-2022
0 7
0
7
chrisboy68
Hi, have  SPL that generates months of data. I want subtract just the last two columns. The fields will change month ...
by chrisboy68 Contributor in Splunk Search 05-02-2022
0 2
0
2
manimuthu
Hi all, My query has, .... | stats latest(time) as recent_event,latest(key) as recent_key, count by field1,field2 and...
by manimuthu Loves-to-Learn Everything in Splunk Search 05-02-2022
0 5
0
5
miberecz
Hello Everyone,I'm trying to analyze data from a jboss server, http request and respons dumps.  An "event" in the Jbo...
by miberecz Loves-to-Learn in Splunk Search 05-02-2022
0 2
0
2
gilbert3
Can not find main app search
by gilbert3 Engager in Splunk Search 05-02-2022
0 4
0
4
anitha123gnana
Block: 2022-02-14 02:30:00,046 [Worker-3] DEBUG User job started2022-02-14 02:30:00,063 [Worker-3] DEBUG Calling impo...
by anitha123gnana Loves-to-Learn Lots in Splunk Search 05-02-2022
0 12
0
12
AHAD_ABDULLAH
Hi this is what appears to me when I try to complete the training:Denied PersonDue to U.S. export compliance requirem...
by AHAD_ABDULLAH Observer in Splunk Search 05-02-2022
0 2
0
2
Anud
Team,I am having a query which would result as below. _timeHostNameversion3/2/2022  15:22:04 PM3car2483/1/2022  15:21...
by Anud Path Finder in Splunk Search 05-01-2022
0 6
0
6
jip31
hello I transpose events like this     | eval time=strftime(_time,"%H:%M") | sort time | fields - _time _span _orig...
by jip31 Motivator in Splunk Search 05-01-2022
0 12
0
12
alval
Hi, as I create an extraction field with regex, the field match is shown correct. I can check the regex on https://re...
by alval New Member in Splunk Search 05-01-2022
0 1
0
1
BlueTeam77
Hello,My SPL expertise are limited. I'm trying to write a search which matches a sequence of events.I'm working with ...
by BlueTeam77 New Member in Splunk Search 05-01-2022
0 1
0
1
bhavyajain
I have to prepare reporting dashboards in Splunk for which I used this query until now:   field1=GTIN_RECEIVED field2...
by bhavyajain Engager in Splunk Search 04-30-2022
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...