Splunk Search

Splunk Search
Community Activity
neerajs_81
Gentlemen,How can i use eval  to assign a field  values of 2 different fields ?In my events, i have 2 fields:  empID ...
by neerajs_81 Builder in Splunk Search 03-10-2022
0 6
0
6
Minghao
I have a log like below:  index=login sourcetype=login new_user=1  I also have logs without new_user label  index=log...
by Minghao Explorer in Splunk Search 03-10-2022
0 9
0
9
yk010123
I have the following log that Splunk is not recognizing well : msg=id=123342521352 operation=write   How can I write ...
by yk010123 Path Finder in Splunk Search 03-09-2022
0 1
0
1
mreid2005
Hi,Long time reader, first time poster.  I've cobbled together this query that generates a count by status for last w...
by mreid2005 Observer in Splunk Search 03-09-2022
0 1
0
1
thaghost99
  index=testlab sourcetype=testcsv | rex field="status detail" "(?<message_received_name>Messages Received)\\s*[0-9,...
by thaghost99 Path Finder in Splunk Search 03-09-2022
0 1
0
1
wjmaxwe2
SOURCE CODE | eventstats count(eval(errorCount=0)) AS passed, count(shortVIN) AS total | timechart span=1w@w0 eval((p...
by wjmaxwe2 New Member in Splunk Search 03-09-2022
0 1
0
1
gtamaki
I'm trying to extract a report for devices in my network. Home assistant sends a log record with a value of 1 when a ...
by gtamaki Engager in Splunk Search 03-09-2022
0 2
0
2
thaghost99
hi i am hoping for some help regarding this. basically i would like to compare (subtract current to previous) the val...
by thaghost99 Path Finder in Splunk Search 03-09-2022
0 5
0
5
rwinkler
We are having an issue with our new 8.2.2 splunk instance any time there's a subsearch with a lot of data being searc...
by rwinkler Loves-to-Learn in Splunk Search 03-09-2022
0 0
0
0
Fe-atSplunk
I am looking for “failed login for ADMIN detected” but because the time in Time is two years late it doesn’t alert. M...
by Fe-atSplunk Explorer in Splunk Search 03-09-2022
0 4
0
4
Bala
Hi Team i have a log message and i want to filter the all log messages which contains the below highlighted text. and...
by Bala Explorer in Splunk Search 03-09-2022
0 3
0
3
jakubvojacek
Hello all, is it possible to call Splunk RestAPI with request in JSON. I am trying in SOAP UI software, media Type = ...
by jakubvojacek Loves-to-Learn in Splunk Search 03-09-2022
0 1
0
1
ave19
I have an external lookup script that works mostly fine. Given an IP address from an event, it can match the address ...
by ave19 Explorer in Splunk Search 03-09-2022
0 7
0
7
fpedrosa
Hi, I have this search:  | spath | rename object.* as * | spath path=events{} output=events | stats by timestamp, ev...
by fpedrosa Engager in Splunk Search 03-09-2022
0 7
0
7
Gurv_Bahad
index=Network dest_ip=xx.xx.xx.xx action=allowed Trying to list total allowed connections to destination IP by day, r...
by Gurv_Bahad Engager in Splunk Search 03-09-2022
0 6
0
6
mbrown_splunk
I am trying to create a candlestick chart within Splunk 6, but not having much luck finding any options for this with...
by mbrown_splunk Splunk Employee Splunk Employee in Splunk Search 03-09-2022
1 7
1
7
Rajaion
Hello community, I have a problem with my research. My searches are then sent to Splunk OnCall to manage alerts.Howev...
by Rajaion Path Finder in Splunk Search 03-09-2022
0 8
0
8
khoeld921
Hi All   I want to ask if you know how to detect if someone change his mobile number on AD.   BR,
by khoeld921 New Member in Splunk Search 03-09-2022
0 0
0
0
jip31
hi I use the search below in order to display markers on a map As you can see, I use a join command in order to cross...
by jip31 Motivator in Splunk Search 03-08-2022
0 4
0
4
SteveQuick
We are suddenly receiving the following error every time we do a peer search from one of our index servers.  The othe...
by SteveQuick New Member in Splunk Search 03-08-2022
0 1
0
1
VasistaI
hi i'm new to splunk. need some help.I have below script:  | spath input=message | search env=prod clAppNam="i-app" d...
by VasistaI Explorer in Splunk Search 03-08-2022
0 4
0
4
Glasses
Hi, I'm having no luck getting a filter-n-drop setup... I referenced  https://docs.splunk.com/Documentation/Splunk/8....
by Glasses Builder in Splunk Search 03-08-2022
0 8
0
8
venky1544
how can i create a multivalue field using makeresults command like   |makeresults |eval value_1= " one"  "two" there ...
by venky1544 Builder in Splunk Search 03-08-2022
0 2
0
2
satya671
_time=time1, _raw=some contents _time=time2, _raw=some contents _time=time3, _raw=some contents _time=time4, _raw=som...
by satya671 Explorer in Splunk Search 03-08-2022
0 5
0
5
priya1926
my query is <dashboard version="1.1"><label>CCEcolour</label><row><panel><table><search><query>index=*** source=servi...
by priya1926 Path Finder in Splunk Search 03-08-2022
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...