Splunk Search

Splunk Search
Community Activity
amitru
I want to get an API usage report per user and I am struggling with the Splunk Query for this, can someone please hel...
by amitru Engager in Splunk Search 04-20-2022
0 1
0
1
Software-Simian
Hi All,the topic might sound very mystic but is actually rather straight forward.I have a timechart displaying the cu...
by Software-Simian Path Finder in Splunk Search 04-20-2022
0 7
0
7
neerajs_81
Hi All,In my raw events, there is a field called "dv_last_login_time" ( already indexed)  as shown below that shows t...
by neerajs_81 Builder in Splunk Search 04-20-2022
0 3
0
3
Liran
I'm attempting to run a query and I've run into a really weird situation where if I run a query with "head 10 | field...
by Liran Observer in Splunk Search 04-19-2022
0 3
0
3
SammyDavis
I am trying to display a duration result to a dashboard and when I try to use the function to convert seconds to HH:M...
by SammyDavis Explorer in Splunk Search 04-19-2022
3 13
3
13
dfurtaw
Good day all,I come to seek guidance from the experts My team and I have been tasked with creating an alert that wil...
by dfurtaw Path Finder in Splunk Search 04-19-2022
0 1
0
1
vrmandadi
Hello Splunkers, I have a query where I did a  |stats values(abc) as abc command over time .I got the below results ....
by vrmandadi Builder in Splunk Search 04-19-2022
0 13
0
13
SplunkDash
Hello, I have events with complex/inconsistence data structure. Need to extract field 2 values under 2 different fiel...
by SplunkDash Motivator in Splunk Search 04-19-2022
0 1
0
1
PavanSeerapu
To get the percentage increase of threshold value and to build a dashboard out of it to show as red if it is increase...
by PavanSeerapu Explorer in Splunk Search 04-19-2022
0 2
0
2
BernardEAI
We are trying to create a data model with a custom _time field. We created the data model, and added a calculated fie...
by BernardEAI Communicator in Splunk Search 04-19-2022
0 1
0
1
jbrenner
I have two Splunk queries, each of which uses the _rex command to extract the join field. Example:       QUERY 1 inde...
by jbrenner Path Finder in Splunk Search 04-19-2022
0 3
0
3
indeed_2000
Hi How can I monitor java applications with splunk, I try nmon but it only give whole java process, not specific pid!...
by indeed_2000 Motivator in Splunk Search 04-19-2022
0 3
0
3
arnavkumarsaxen
My logs are in the format: My-Application Log: Some-Key= 99, SomeOtherKey= 231, SomeOtherKey2= 1231, Some Different K...
by arnavkumarsaxen Explorer in Splunk Search 04-19-2022
0 6
0
6
jinishshah
Hello, so I have an input on my dashboard page of either month"01-2022,02-2022" and also quarter"Q1-2022". So dependi...
by jinishshah Explorer in Splunk Search 04-19-2022
0 9
0
9
gheribhai1234
Hey Team,I have Million records to search for.Record Structure is given below.My requirement is to get length of aVal...
by gheribhai1234 Engager in Splunk Search 04-19-2022
0 13
0
13
msg4sunil
index=app1 [search index=app1 "orderid"| fields id] How do I modify the above query wherein "search index=app1 "order...
by msg4sunil Path Finder in Splunk Search 04-18-2022
0 8
0
8
bapun18
I want to specify a field that contains time as earliest and another field as latest so that my spl will be executed ...
by bapun18 Communicator in Splunk Search 04-18-2022
0 2
0
2
neerajs_81
Gentlemen,We are on Splunk Cloud.In my raw events coming from AWS , splunk by default shows a field called "category"...
by neerajs_81 Builder in Splunk Search 04-18-2022
0 4
0
4
jking81
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1...
by jking81 Explorer in Splunk Search 04-18-2022
0 2
0
2
bcwlk
Does anyone know of a way to reverse the order of the automatic start/end values used for bucket creation when workin...
by bcwlk Explorer in Splunk Search 04-18-2022
0 7
0
7
humblelearner
Hi all, I want to set a condition "credential.helper= ", notice there is a trailing space after the "=".  What I want...
by humblelearner Observer in Splunk Search 04-18-2022
0 2
0
2
ddrillic
I have a lookup table from which I need to remove a couple of lines. How can I do it?
by ddrillic Ultra Champion in Splunk Search 04-18-2022
0 3
0
3
Qerro
Don't show a result where the src_ip is X and dest_ip is Y  index=test    host=test  source=test conn_state=sf   | ev...
by Qerro Loves-to-Learn in Splunk Search 04-18-2022
0 2
0
2
POR160893
Hi, I need to use Linear Regression to predict network volumes at the moment.The index I am using has a number of cat...
by POR160893 Builder in Splunk Search 04-18-2022
0 0
0
0
danielbb
We have the following command that works well -    | transaction job_name startswith=STARTING keeporphans=true   Is i...
by danielbb Motivator in Splunk Search 04-18-2022
0 2
0
2
Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...