Splunk Search

Splunk Search
Community Activity
VikhyathMaiya
Hello splunk community. I have a search query which i am using to report the daily api stats. I have a requirement wh...
by VikhyathMaiya Explorer in Splunk Search 02-18-2022
0 5
0
5
sundarhcl_2022
Hi,  I have Percentage calculated for Compliance and Non Compliance based on the data .Now i need to segregate it bas...
by sundarhcl_2022 Explorer in Splunk Search 02-18-2022
0 11
0
11
kirrusk
Hi    I'm trying to add a chart by using the below query, in chart lines Date is coming.But in x-axis shows only the ...
by kirrusk Communicator in Splunk Search 02-18-2022
0 6
0
6
michaelnorup
Hey guys.So i have a search which created a bar chart     | rex field=_raw "(.Net Version is)\s+(?<DotNetVersion>.+)"...
by michaelnorup Communicator in Splunk Search 02-18-2022
0 5
0
5
noott211
If you don't put a wild card when searching after extracting the field, you can't search. Field extraction is success...
by noott211 Path Finder in Splunk Search 02-18-2022
0 12
0
12
decenior
Honored Splunkodes, I am trying to keep track of the manpower in each of my legions, so that if any legion loses too ...
by decenior Engager in Splunk Search 02-18-2022
0 1
0
1
EvansB
How can I display _time in my results using stats commandI get this field when I use "table _time" Just like the imag...
by EvansB Path Finder in Splunk Search 02-17-2022
0 2
0
2
bstill
I have an event that looks similar to the following: 2017-10-18 16:59:30.943, MetaDataFoo="ValueFoo", Event_Time="20...
by bstill New Member in Splunk Search 02-17-2022
0 4
0
4
ajscam
I'm missing ALL of the interesting fields. I used to see such things as date_hour, date_minute, etc, etc. If I ma...
by ajscam Engager in Splunk Search 02-17-2022
1 4
1
4
jackin
Can anyone suggest why the logs are coming up like this? I added the monitoring stanza. Could anyone suggest some tro...
by jackin Path Finder in Splunk Search 02-17-2022
0 2
0
2
NewGhost
Hi,I'm struggling with a simple search.I have multiple events for the same username. I need to count the number of us...
by NewGhost Engager in Splunk Search 02-17-2022
0 2
0
2
innoce
I have 3 indexes containing events with IP addresses, index1, index2, and index3. My goal is to return a list of all ...
by innoce Path Finder in Splunk Search 02-17-2022
0 1
0
1
michaelnorup
Hey guys.I have been trying to make a compliance/noncompliance list:I have a big search that will table all the data ...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
michaelnorup
    index="***********" sourcetype="**********" (host="*") | rex field=_raw "(Available Updates)\s+(?<AvailableUpdate...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
shreem
Hello All, I was extracting some volume data for PE testing from prod systems, using following query  I am expecting ...
by shreem Engager in Splunk Search 02-17-2022
0 3
0
3
priya1926
My output format is 20220129054235.496380-300I need to convert the value in bold to normal and find the difference of...
by priya1926 Path Finder in Splunk Search 02-17-2022
0 1
0
1
human96
Hi all, I want a result containing value= '0' in column without using the " chart " commandThank you.  
by human96 Communicator in Splunk Search 02-17-2022
0 3
0
3
mmacalik
Dear Splunk community I need help with a presumably easy task, but it had already cost me quite a while. I'm trying t...
by mmacalik Explorer in Splunk Search 02-17-2022
0 10
0
10
Steve_A200
I would like to list results from two events that are linked via common field (system_id), but searched via value onl...
by Steve_A200 Path Finder in Splunk Search 02-16-2022
0 2
0
2
jaxxsplunk
Summary: When using the table command, values are dropped if { is the first character.     index=someindex hos...
by jaxxsplunk Explorer in Splunk Search 02-16-2022
0 2
0
2
tsheets13
I did this a few weeks ago and now I can't seem figure out how I did it. I need a report listing all UFs, with their ...
by tsheets13 Communicator in Splunk Search 02-16-2022
0 5
0
5
hj9b7Cn
Hello everyone, I'm pretty new to Splunk and mostly learning as I go, so please bear with me if this is a common ques...
by hj9b7Cn Engager in Splunk Search 02-16-2022
0 1
0
1
neerajs_81
Hello,  The below search displays  _time in human readable format when count  of the results =1 but in EPOCH format w...
by neerajs_81 Builder in Splunk Search 02-16-2022
0 8
0
8
icehack
Does anyone know where I can find some already created Splunk use cases for github webhook logs? I am having a really...
by icehack Observer in Splunk Search 02-16-2022
0 0
0
0
mv10
I have two sets of IIS data (two sourcetypes) in a single index. One sourcetype logs web service requests, the other ...
by mv10 Path Finder in Splunk Search 02-16-2022
0 7
0
7
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors