| Gentlemen,How can i use eval to assign a field values of 2 different fields ?In my events, i have 2 fields: empID ... by neerajs_81 Builder in Splunk Search 03-10-2022 0 6 | 0 | 6 | ||
| I have a log like below: index=login sourcetype=login new_user=1 I also have logs without new_user label index=log... by Minghao Explorer in Splunk Search 03-10-2022 0 9 | 0 | 9 | ||
| I have the following log that Splunk is not recognizing well : msg=id=123342521352 operation=write How can I write ... by yk010123 Path Finder in Splunk Search 03-09-2022 0 1 | 0 | 1 | ||
| Hi,Long time reader, first time poster. I've cobbled together this query that generates a count by status for last w... by mreid2005 Observer in Splunk Search 03-09-2022 0 1 | 0 | 1 | ||
| index=testlab sourcetype=testcsv | rex field="status detail" "(?<message_received_name>Messages Received)\\s*[0-9,... by thaghost99 Path Finder in Splunk Search 03-09-2022 0 1 | 0 | 1 | ||
| SOURCE CODE | eventstats count(eval(errorCount=0)) AS passed, count(shortVIN) AS total | timechart span=1w@w0 eval((p... by wjmaxwe2 New Member in Splunk Search 03-09-2022 0 1 | 0 | 1 | ||
| I'm trying to extract a report for devices in my network. Home assistant sends a log record with a value of 1 when a ... by gtamaki Engager in Splunk Search 03-09-2022 0 2 | 0 | 2 | ||
| hi i am hoping for some help regarding this. basically i would like to compare (subtract current to previous) the val... by thaghost99 Path Finder in Splunk Search 03-09-2022 0 5 | 0 | 5 | ||
| We are having an issue with our new 8.2.2 splunk instance any time there's a subsearch with a lot of data being searc... by rwinkler Loves-to-Learn in Splunk Search 03-09-2022 0 0 | 0 | 0 | ||
| I am looking for “failed login for ADMIN detected” but because the time in Time is two years late it doesn’t alert. M... by Fe-atSplunk Explorer in Splunk Search 03-09-2022 0 4 | 0 | 4 | ||
| Hi Team i have a log message and i want to filter the all log messages which contains the below highlighted text. and... by Bala Explorer in Splunk Search 03-09-2022 0 3 | 0 | 3 | ||
| Hello all, is it possible to call Splunk RestAPI with request in JSON. I am trying in SOAP UI software, media Type = ... by jakubvojacek Loves-to-Learn in Splunk Search 03-09-2022 0 1 | 0 | 1 | ||
| I have an external lookup script that works mostly fine. Given an IP address from an event, it can match the address ... by ave19 Explorer in Splunk Search 03-09-2022 0 7 | 0 | 7 | ||
| Hi, I have this search: | spath | rename object.* as * | spath path=events{} output=events | stats by timestamp, ev... by fpedrosa Engager in Splunk Search 03-09-2022 0 7 | 0 | 7 | ||
| index=Network dest_ip=xx.xx.xx.xx action=allowed Trying to list total allowed connections to destination IP by day, r... by Gurv_Bahad Engager in Splunk Search 03-09-2022 0 6 | 0 | 6 | ||
| I am trying to create a candlestick chart within Splunk 6, but not having much luck finding any options for this with... by mbrown_splunk Splunk Employee 1 7 | 1 | 7 | ||
| Hello community, I have a problem with my research. My searches are then sent to Splunk OnCall to manage alerts.Howev... by Rajaion Path Finder in Splunk Search 03-09-2022 0 8 | 0 | 8 | ||
| Hi All I want to ask if you know how to detect if someone change his mobile number on AD. BR, by khoeld921 New Member in Splunk Search 03-09-2022 0 0 | 0 | 0 | ||
| hi I use the search below in order to display markers on a map As you can see, I use a join command in order to cross... by jip31 Motivator in Splunk Search 03-08-2022 0 4 | 0 | 4 | ||
| We are suddenly receiving the following error every time we do a peer search from one of our index servers. The othe... by SteveQuick New Member in Splunk Search 03-08-2022 0 1 | 0 | 1 | ||
| hi i'm new to splunk. need some help.I have below script: | spath input=message | search env=prod clAppNam="i-app" d... by VasistaI Explorer in Splunk Search 03-08-2022 0 4 | 0 | 4 | ||
| Hi, I'm having no luck getting a filter-n-drop setup... I referenced https://docs.splunk.com/Documentation/Splunk/8.... by Glasses Builder in Splunk Search 03-08-2022 0 8 | 0 | 8 | ||
| how can i create a multivalue field using makeresults command like |makeresults |eval value_1= " one" "two" there ... by venky1544 Builder in Splunk Search 03-08-2022 0 2 | 0 | 2 | ||
| _time=time1, _raw=some contents _time=time2, _raw=some contents _time=time3, _raw=some contents _time=time4, _raw=som... by satya671 Explorer in Splunk Search 03-08-2022 0 5 | 0 | 5 | ||
| my query is <dashboard version="1.1"><label>CCEcolour</label><row><panel><table><search><query>index=*** source=servi... by priya1926 Path Finder in Splunk Search 03-08-2022 0 3 | 0 | 3 |