Splunk Search

Splunk Search
Community Activity
Borntowin
Hi Team,    There is a two reports one report(1st report) has timestamp other report(2nd report) doesn't have timesta...
by Borntowin Loves-to-Learn Everything in Splunk Search 04-08-2022
0 3
0
3
ssekar
Hello Expert,Please help me arrive on a regex to extract a xml node in a xml field.I have a field value like below<Re...
by ssekar Engager in Splunk Search 04-08-2022
0 4
0
4
JohnMoeVita
I'm trying to set up a search to return Office 365 role change events for specific roles, such as the Global Administ...
by JohnMoeVita New Member in Splunk Search 04-08-2022
0 1
0
1
Fats120
How do I find the time events have been sent in for the last 3 days. I want to see the time 53 different events came ...
by Fats120 Loves-to-Learn Lots in Splunk Search 04-08-2022
0 10
0
10
KeithH
Hi All, I am doing a very simple search over All Time of:        index=index=orafin sourcetype=ORAFIN2       It retur...
by KeithH Communicator in Splunk Search 04-07-2022
0 1
0
1
michaelsplunk1
_timedevice1_avgdevice2_avgdevice3_avgdevice4_avg2022-04-07 00:0034311222022-04-07 01:00217641872022-04-07 02:0021832...
by michaelsplunk1 Path Finder in Splunk Search 04-07-2022
0 1
0
1
aj_54321
Hi,I have documents similar to the one below:  request_id: 12345 revision: 123 other_field: stuff my_preciou...
by aj_54321 Explorer in Splunk Search 04-07-2022
0 2
0
2
adeshreddy
Hey Community, I am trying to get my head around this query My subsearch below, The query will look for the api path,...
by adeshreddy Engager in Splunk Search 04-07-2022
0 4
0
4
tkerr1357
Hey all ,  just need a little regex help trying to pull an IP address out  and its not working. here is my rex  | rex...
by tkerr1357 Path Finder in Splunk Search 04-07-2022
0 4
0
4
bb10
I'm trying to make a visualization showing our number of signatures, but the data is not very organized because I hav...
by bb10 Engager in Splunk Search 04-07-2022
0 2
0
2
apignata
How would you return the count of only the Reachable devices?In the picture above you would return 8.When using the q...
by apignata Explorer in Splunk Search 04-07-2022
0 6
0
6
HWalk1
Hi All! The data I am pulling is coming from nodes in multiple time zones. I want to use that time zone instead of Sp...
by HWalk1 Explorer in Splunk Search 04-07-2022
0 4
0
4
aberkow
Thought there was an answer on this already but can't find it, but for something like this, which is the most perform...
by aberkow Builder in Splunk Search 04-07-2022
1 3
1
3
sbatino
HelloHelloI have the following Splunk search syntax which returns me detailed log connection for a all user to the VP...
by sbatino Observer in Splunk Search 04-07-2022
0 3
0
3
rajbeerdhatt
Context: New Search View.  I am not referring to Dashboards (which have many auto-run posts). I often develop searche...
by rajbeerdhatt Explorer in Splunk Search 04-07-2022
2 1
2
1
vrmandadi
Hello Splunkers,I have data where the index time is different from the actual file.The source has the correct date an...
by vrmandadi Builder in Splunk Search 04-07-2022
0 6
0
6
jip31
hello I use a transpose command in a table panel     | eval time=strftime(_time,"%H:%M") | sort time | fields - _ti...
by jip31 Motivator in Splunk Search 04-07-2022
0 3
0
3
Thomas19
Hi, I am encountering issue with 1 particular index. I am unable to use index!= to exclude the results from that part...
by Thomas19 New Member in Splunk Search 04-07-2022
0 3
0
3
innoce
I need to exclude the field values if it is less than or equal to 8 characters. For eg: In the field abc, I have the ...
by innoce Path Finder in Splunk Search 04-07-2022
1 2
1
2
mfshravan
Hi All, I would like to extract more logs after searching for particular string. Eg., I want to search with string "M...
by mfshravan New Member in Splunk Search 04-06-2022
0 0
0
0
Woodpecker
Hi all,I have some value under src fields as below, but it has some problems. For example, actually <1b5a.4.d576d0e8-...
by Woodpecker Path Finder in Splunk Search 04-06-2022
0 3
0
3
phamxuantung
I have a csv file that I upload through Lookup Editor which have a Time column in this format15/06/2021 14:35:00I wan...
by phamxuantung Communicator in Splunk Search 04-06-2022
0 4
0
4
jprovenzale
Hello, I have 3 fields from which I need to build a line chart on a Time series.   ServerTime Endpoint ResponseTime  ...
by jprovenzale Explorer in Splunk Search 04-06-2022
0 4
0
4
kapoorsumit2020
Team, Time difference between end_task_date and start_task_date is coming null. Could you please take a look below an...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 04-06-2022
0 1
0
1
yk010123
I have the following data :  query="select field  from table where (status!="Y")  and ids.id IN ["123","145"] limit 5...
by yk010123 Path Finder in Splunk Search 04-06-2022
0 1
0
1
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Solution Authors