Splunk Search

Splunk Search
Community Activity
Sheela
I'm attempting to extract statistics of user logins from a custom log format and create a bar chart. I have users A, ...
by Sheela Path Finder in Splunk Search 03-03-2022
2 7
2
7
zacksoft_wf
I have 2 Splunk SPLs=====================index=computer_admin source=admin_priv sourcetype=prive:db account_name=admi...
by zacksoft_wf Contributor in Splunk Search 03-03-2022
0 5
0
5
AK89
New to splunk and been struggling manipulating search results into a final result that I am looking for. In powershel...
by AK89 Explorer in Splunk Search 03-03-2022
0 3
0
3
mjuestel2
All, I need some help on a problem I am trying to solve. Problem: I need to calculate the average user events per uni...
by mjuestel2 Path Finder in Splunk Search 03-03-2022
0 3
0
3
Tika
I have two separate searches that provides me the same data field in two different fieldds. I want to identify the co...
by Tika Explorer in Splunk Search 03-03-2022
0 1
0
1
SplunkDash
Hello, are there any queries we can use to find the Total Number of Events, Total Size/Volume (in GB) of Data, Freque...
by SplunkDash Motivator in Splunk Search 03-02-2022
0 9
0
9
srinivasiyer
If col A contains a b c d e f, I want a separate link to be opened for each value. E.g If the user click on "a", it ...
by srinivasiyer New Member in Splunk Search 03-02-2022
0 2
0
2
sdee1013
hi everyone, i'm trying to parse json inline.  i'm using kv mode= json already but i'm trying to achieve selective gr...
by sdee1013 Loves-to-Learn in Splunk Search 03-02-2022
0 5
0
5
FcwfCW76
Hello I have a table I want this I am not sure which tool (chart, table anything else) and arguments would be best ...
by FcwfCW76 Explorer in Splunk Search 03-02-2022
0 2
0
2
sphiwee
I have this table and I'm trying to send it as a report/alert every morning to our teams chat group   This is how it...
by sphiwee Contributor in Splunk Search 03-02-2022
0 0
0
0
jip31
HiI use this CSS code in order to enlarge the size of the data values in the bars chartNow I also need to enlarge the...
by jip31 Motivator in Splunk Search 03-02-2022
0 4
0
4
bijodev1
Hi There, I am looking to produce an output where the field with maximum count is display based on another field. for...
by bijodev1 Communicator in Splunk Search 03-02-2022
0 3
0
3
msmith58
Here is the SPL:   index=name reqHost="host" | rex field=cookie "care_did=(?<care_did>[a-z0-9-]+)" | rex field=cookie...
by msmith58 Explorer in Splunk Search 03-02-2022
0 5
0
5
jip31
hiI use a lookup with a field corresponding to a site name| inputlookup site.csv | search site=*paris* In this lookup...
by jip31 Motivator in Splunk Search 03-02-2022
0 2
0
2
mscomms
Hi All, Splunk Enterprise 8.2.4 Clustered I have an issue where I have an existing app with a lookup listing all devi...
by mscomms Path Finder in Splunk Search 03-02-2022
0 12
0
12
tazzvon
is there anyway to create a file with a list of IP's that i can use in the search field? i am trying to search for IP...
by tazzvon Engager in Splunk Search 03-02-2022
0 3
0
3
saravana22
Hi Experts, my SPL query, ...| eval elapse_range=case(TOTAL_ELAPSE>0 AND TOTAL_ELAPSE<4, "Green",TOTAL_ELAPSE>4 AND T...
by saravana22 Explorer in Splunk Search 03-02-2022
0 3
0
3
jip31
hello   I use this timechart   index=tutu sourcetype=titi | timechart span=15min dc(s) as "Uniq"    Now i would like...
by jip31 Motivator in Splunk Search 03-02-2022
0 10
0
10
gaishi
Hello all,I'd like to compare events in the same log files, amusing the format of the events are the same. For exampl...
by gaishi New Member in Splunk Search 03-02-2022
0 2
0
2
bijodev1
Hi There,I have got some results in after running the below commandmy search | | bucket _time span=1h| stats count by...
by bijodev1 Communicator in Splunk Search 03-02-2022
0 2
0
2
rip_leroi
I'm attempting to build a search around Okta authentication logs.  I want to run a query to check for any Multi facto...
by rip_leroi Explorer in Splunk Search 03-02-2022
0 1
0
1
7ryota
hi, i a total newbiei need to do a search in splunk matching the domain in my lookup table (master_lookup.csv)my tabl...
by 7ryota Explorer in Splunk Search 03-02-2022
0 5
0
5
auzark
My dilemma. index=prod_s3  sourcetype=My_Sourcetype earliest=-30m(host=2016) OR (host=2018) OR(host=2015) OR (host=20...
by auzark Communicator in Splunk Search 03-02-2022
0 12
0
12
Stuartb_
Hello, I have a search that runs in the web application interface (Splunk Enterprise). It returns results as and when...
by Stuartb_ New Member in Splunk Search 03-01-2022
0 0
0
0
ejwade
I'm trying to create a calculated field (eval) that will coalesce a bunch of username fields, then perform match() an...
by ejwade Contributor in Splunk Search 03-01-2022
0 0
0
0
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...