Splunk Search

Splunk Search
Community Activity
POR160893
Hi, I have an index of log events and I have been asked to exclude all events with a certain string in it. The String...
by POR160893 Builder in Splunk Search 04-11-2022
0 4
0
4
vangal_sandeep
I have some data and  I am trying to  extract fields from multi line raw data.   TIMESTAMP=23-12-2021,Eligible_to_be_...
by vangal_sandeep New Member in Splunk Search 04-11-2022
0 2
0
2
Kisame27
2022-04-11 05:46:26 POST /BestMarket.Internal.Market.Transactions/MarketTransactionService  ContractName="BestMarket....
by Kisame27 Explorer in Splunk Search 04-11-2022
0 1
0
1
kiran007
Hi, I need list of all the successful events details in the 'If' condition. For those successful list I need to extra...
by kiran007 Explorer in Splunk Search 04-11-2022
0 4
0
4
KeithH
Hi All,I hope someone can enlighten me with this seemingly simple problem.I have this very simple search return 32 ro...
by KeithH Communicator in Splunk Search 04-11-2022
0 6
0
6
pavanae
Hi Splunkers,  I have defined a filed as follows using eval condition        | eval body = "Sample Example :-" . " -...
by pavanae Builder in Splunk Search 04-10-2022
0 2
0
2
ebs
Hi, I'm trying to round the average of my response_time but still getting undesirable results (all the decimal places...
by ebs Communicator in Splunk Search 04-10-2022
0 7
0
7
usscommunity
Hi Could you please help me with using REX/REGEX inside eval? Here is what I'm trying to do  | makeresults | eval Use...
by usscommunity Loves-to-Learn Lots in Splunk Search 04-09-2022
0 2
0
2
aamer86
I have created a lookup for a threat feed CSV file we are using. After deleting all the Lookup CSV files and removing...
by aamer86 Path Finder in Splunk Search 04-09-2022
0 1
0
1
wcooper003
This search works fine but is slow: host=host1 sourcetype="WinEventLog:Security" EventCode=5156 | timechart span=1d...
by wcooper003 Communicator in Splunk Search 04-08-2022
0 7
0
7
JChris_
I have the following events in splunk:     company,name,email,status Acme,John Doe,john.doe@example.com,inactive Comp...
by JChris_ Path Finder in Splunk Search 04-08-2022
0 4
0
4
dfiore42
I need a query to view disk encryption (DAR) of all my hosts, be it Bit Locker, LUKS, etc.index=* host=* | ???Thank y...
by dfiore42 New Member in Splunk Search 04-08-2022
0 1
0
1
Marco_Develops
Currently I have a field holding a Julian date. I am trying to convert it using strftime but i'm having issues. Date ...
by Marco_Develops Path Finder in Splunk Search 04-08-2022
0 2
0
2
jymmitch
Here's the text string from the log I'm searching: store license for Store 1234562022-04-07 19:17:44,360 ERROR path n...
by jymmitch Path Finder in Splunk Search 04-08-2022
0 12
0
12
Borntowin
Hi Team,    There is a two reports one report(1st report) has timestamp other report(2nd report) doesn't have timesta...
by Borntowin Loves-to-Learn Everything in Splunk Search 04-08-2022
0 3
0
3
ssekar
Hello Expert,Please help me arrive on a regex to extract a xml node in a xml field.I have a field value like below<Re...
by ssekar Engager in Splunk Search 04-08-2022
0 4
0
4
JohnMoeVita
I'm trying to set up a search to return Office 365 role change events for specific roles, such as the Global Administ...
by JohnMoeVita New Member in Splunk Search 04-08-2022
0 1
0
1
Fats120
How do I find the time events have been sent in for the last 3 days. I want to see the time 53 different events came ...
by Fats120 Loves-to-Learn Lots in Splunk Search 04-08-2022
0 10
0
10
KeithH
Hi All, I am doing a very simple search over All Time of:        index=index=orafin sourcetype=ORAFIN2       It retur...
by KeithH Communicator in Splunk Search 04-07-2022
0 1
0
1
michaelsplunk1
_timedevice1_avgdevice2_avgdevice3_avgdevice4_avg2022-04-07 00:0034311222022-04-07 01:00217641872022-04-07 02:0021832...
by michaelsplunk1 Path Finder in Splunk Search 04-07-2022
0 1
0
1
aj_54321
Hi,I have documents similar to the one below:  request_id: 12345 revision: 123 other_field: stuff my_preciou...
by aj_54321 Explorer in Splunk Search 04-07-2022
0 2
0
2
adeshreddy
Hey Community, I am trying to get my head around this query My subsearch below, The query will look for the api path,...
by adeshreddy Engager in Splunk Search 04-07-2022
0 4
0
4
tkerr1357
Hey all ,  just need a little regex help trying to pull an IP address out  and its not working. here is my rex  | rex...
by tkerr1357 Path Finder in Splunk Search 04-07-2022
0 4
0
4
bb10
I'm trying to make a visualization showing our number of signatures, but the data is not very organized because I hav...
by bb10 Engager in Splunk Search 04-07-2022
0 2
0
2
apignata
How would you return the count of only the Reachable devices?In the picture above you would return 8.When using the q...
by apignata Explorer in Splunk Search 04-07-2022
0 6
0
6
Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...