Splunk Search

Splunk Search
Community Activity
michaelnorup
Hey guys.So i have a search which created a bar chart     | rex field=_raw "(.Net Version is)\s+(?<DotNetVersion>.+)"...
by michaelnorup Communicator in Splunk Search 02-18-2022
0 5
0
5
noott211
If you don't put a wild card when searching after extracting the field, you can't search. Field extraction is success...
by noott211 Path Finder in Splunk Search 02-18-2022
0 12
0
12
decenior
Honored Splunkodes, I am trying to keep track of the manpower in each of my legions, so that if any legion loses too ...
by decenior Engager in Splunk Search 02-18-2022
0 1
0
1
EvansB
How can I display _time in my results using stats commandI get this field when I use "table _time" Just like the imag...
by EvansB Path Finder in Splunk Search 02-17-2022
0 2
0
2
bstill
I have an event that looks similar to the following: 2017-10-18 16:59:30.943, MetaDataFoo="ValueFoo", Event_Time="20...
by bstill New Member in Splunk Search 02-17-2022
0 4
0
4
ajscam
I'm missing ALL of the interesting fields. I used to see such things as date_hour, date_minute, etc, etc. If I ma...
by ajscam Engager in Splunk Search 02-17-2022
1 4
1
4
jackin
Can anyone suggest why the logs are coming up like this? I added the monitoring stanza. Could anyone suggest some tro...
by jackin Path Finder in Splunk Search 02-17-2022
0 2
0
2
NewGhost
Hi,I'm struggling with a simple search.I have multiple events for the same username. I need to count the number of us...
by NewGhost Engager in Splunk Search 02-17-2022
0 2
0
2
innoce
I have 3 indexes containing events with IP addresses, index1, index2, and index3. My goal is to return a list of all ...
by innoce Path Finder in Splunk Search 02-17-2022
0 1
0
1
michaelnorup
Hey guys.I have been trying to make a compliance/noncompliance list:I have a big search that will table all the data ...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
michaelnorup
    index="***********" sourcetype="**********" (host="*") | rex field=_raw "(Available Updates)\s+(?<AvailableUpdate...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
shreem
Hello All, I was extracting some volume data for PE testing from prod systems, using following query  I am expecting ...
by shreem Engager in Splunk Search 02-17-2022
0 3
0
3
priya1926
My output format is 20220129054235.496380-300I need to convert the value in bold to normal and find the difference of...
by priya1926 Path Finder in Splunk Search 02-17-2022
0 1
0
1
human96
Hi all, I want a result containing value= '0' in column without using the " chart " commandThank you.  
by human96 Communicator in Splunk Search 02-17-2022
0 3
0
3
mmacalik
Dear Splunk community I need help with a presumably easy task, but it had already cost me quite a while. I'm trying t...
by mmacalik Explorer in Splunk Search 02-17-2022
0 10
0
10
Steve_A200
I would like to list results from two events that are linked via common field (system_id), but searched via value onl...
by Steve_A200 Path Finder in Splunk Search 02-16-2022
0 2
0
2
jaxxsplunk
Summary: When using the table command, values are dropped if { is the first character.     index=someindex hos...
by jaxxsplunk Explorer in Splunk Search 02-16-2022
0 2
0
2
tsheets13
I did this a few weeks ago and now I can't seem figure out how I did it. I need a report listing all UFs, with their ...
by tsheets13 Communicator in Splunk Search 02-16-2022
0 5
0
5
hj9b7Cn
Hello everyone, I'm pretty new to Splunk and mostly learning as I go, so please bear with me if this is a common ques...
by hj9b7Cn Engager in Splunk Search 02-16-2022
0 1
0
1
neerajs_81
Hello,  The below search displays  _time in human readable format when count  of the results =1 but in EPOCH format w...
by neerajs_81 Builder in Splunk Search 02-16-2022
0 8
0
8
icehack
Does anyone know where I can find some already created Splunk use cases for github webhook logs? I am having a really...
by icehack Observer in Splunk Search 02-16-2022
0 0
0
0
mv10
I have two sets of IIS data (two sourcetypes) in a single index. One sourcetype logs web service requests, the other ...
by mv10 Path Finder in Splunk Search 02-16-2022
0 7
0
7
mark_chuman
This search: index=perfstats host=hostname | chart max(System_Up_Time) as "System Uptime" by host Outputs a value suc...
by mark_chuman Path Finder in Splunk Search 02-16-2022
0 10
0
10
bijodev1
Hi Everyone,So the goal here is to auto increment / decrement a value based on the position of character present in a...
by bijodev1 Communicator in Splunk Search 02-16-2022
0 5
0
5
chrisboy68
Hi, struggling trying to count objects in a big json doc. I'm on version 8.0.5, so function json_keys is not availabl...
by chrisboy68 Contributor in Splunk Search 02-16-2022
0 8
0
8
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors