Splunk Search

Splunk Search
Community Activity
Borntowin
Hi Team,    I have indexed the file as current timestamp but would like to execute the query by taking the filename t...
by Borntowin Loves-to-Learn Everything in Splunk Search 03-28-2022
0 3
0
3
HWalk1
So I am looking for the number of a specific event (sign-ins)  deduped by a user, which is simple. The challenge I am...
by HWalk1 Explorer in Splunk Search 03-28-2022
0 3
0
3
BME1
Following the override documentation, I am confused... When creating an override, and the pop up box appears, do you ...
by BME1 Explorer in Splunk Search 03-28-2022
0 4
0
4
zacksoft
My query essentially goes thru every event and picks a field with response_time. And then calculates the average val...
by zacksoft Contributor in Splunk Search 03-28-2022
0 5
0
5
innoce
Hi,I need to extract host values from one index (index=1) and see if there are similar matches that exists in other i...
by innoce Path Finder in Splunk Search 03-28-2022
0 4
0
4
sh254087
The predefined table names in the add-on doesn't list the service ticket related table name, hence wanted to know the...
by sh254087 Communicator in Splunk Search 03-28-2022
0 0
0
0
tehong
Hi Experts When using the following eval, I would like to declare a variable in macro as in create_var(3). | eval var...
by tehong Explorer in Splunk Search 03-27-2022
0 3
0
3
jip31
Hello I use an input text token in my search like this town=$town$ By defaut, town = * The problem is that sometimes ...
by jip31 Motivator in Splunk Search 03-27-2022
0 2
0
2
jakeoftrades
hi,can anyone help me how should I query the counts of kafka_datatype  of those stream_type which Im going to set an ...
by jakeoftrades Explorer in Splunk Search 03-27-2022
0 0
0
0
ravi1234
I want a if else condition in which i need to pass address(path) . Suppose: If (condition==something) {Go to this pa...
by ravi1234 New Member in Splunk Search 03-27-2022
0 1
0
1
elijahputz
Hello, I am trying to setup a search where we look for single source IP's hitting multiple destination IP's on our fi...
by elijahputz Explorer in Splunk Search 03-26-2022
0 11
0
11
hasegawaarte
If I want to use a field(alarm_time) from the main search as a search criteria for a sub-search, what code should I w...
by hasegawaarte Explorer in Splunk Search 03-26-2022
0 1
0
1
alexspunkshell
Can someone help with Splunk Placeholder? What is Placeholder? How to create it? How does it work in lookup? How to m...
by alexspunkshell Contributor in Splunk Search 03-26-2022
0 6
0
6
fredv44
Hello. Given these logs: 2022-03-16 16:08:43.991 traceId="7890" svc="Service1" duration=1322022-03-16 16:10:43.279 tr...
by fredv44 Explorer in Splunk Search 03-26-2022
0 4
0
4
rsahoo
I have a data set from where I am trying to apply the group by function on multiple columns. I tried stats with list ...
by rsahoo Engager in Splunk Search 03-25-2022
0 1
0
1
aj_54321
Hi! I have unstructured log in the following format, and I can't seem to figure out how I can count the number of occ...
by aj_54321 Explorer in Splunk Search 03-25-2022
0 1
0
1
JoeHubner
I am looking to search in one Index for a specific field name and then use a second field from that Index to search a...
by JoeHubner Explorer in Splunk Search 03-25-2022
0 2
0
2
kr5345
Hey there, pretty new to Splunk searching. I am trying to get a table created that will combine search results based ...
by kr5345 Engager in Splunk Search 03-25-2022
0 2
0
2
anthonyb90
I'm looking to set a variable (customerLabel) depending on whether the user selects "framework" or "team" from a drop...
by anthonyb90 New Member in Splunk Search 03-25-2022
0 1
0
1
Woodpecker
Hi,I have 3 indexes. I need to extract hash_values from index 3 and do a search to see if similar files exists in ind...
by Woodpecker Path Finder in Splunk Search 03-25-2022
0 1
0
1
troy44112
What do I need to add to this search, to make this search  | where Need >= 60min | tstats max(_indextime) AS Late whe...
by troy44112 Explorer in Splunk Search 03-25-2022
0 8
0
8
BenWilliamson1
My data consists of individual messages, tagged with the userID of the user who sent them. I want to count the number...
by BenWilliamson1 New Member in Splunk Search 03-25-2022
0 2
0
2
dex31337
I want to create alert when user approve MFA from different IP than the one he used prior to connection to VPN. So I'...
by dex31337 Loves-to-Learn Lots in Splunk Search 03-25-2022
0 8
0
8
raduand
Hi guys, I have a Splunk scheduled search which is producing a list of URLs that need to be used by another system. T...
by raduand Explorer in Splunk Search 03-25-2022
1 4
1
4
Mattjj
Hi all, We have events in a single index for flows into and out of a gateway, I’m trying to link an incoming event wi...
by Mattjj Explorer in Splunk Search 03-25-2022
0 2
0
2
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...