Splunk Search

Splunk Search
Community Activity
innoce
I have 3 indexes containing events with IP addresses, index1, index2, and index3. My goal is to return a list of all ...
by innoce Path Finder in Splunk Search 02-17-2022
0 1
0
1
michaelnorup
Hey guys.I have been trying to make a compliance/noncompliance list:I have a big search that will table all the data ...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
michaelnorup
    index="***********" sourcetype="**********" (host="*") | rex field=_raw "(Available Updates)\s+(?<AvailableUpdate...
by michaelnorup Communicator in Splunk Search 02-17-2022
0 4
0
4
shreem
Hello All, I was extracting some volume data for PE testing from prod systems, using following query  I am expecting ...
by shreem Engager in Splunk Search 02-17-2022
0 3
0
3
priya1926
My output format is 20220129054235.496380-300I need to convert the value in bold to normal and find the difference of...
by priya1926 Path Finder in Splunk Search 02-17-2022
0 1
0
1
human96
Hi all, I want a result containing value= '0' in column without using the " chart " commandThank you.  
by human96 Communicator in Splunk Search 02-17-2022
0 3
0
3
mmacalik
Dear Splunk community I need help with a presumably easy task, but it had already cost me quite a while. I'm trying t...
by mmacalik Explorer in Splunk Search 02-17-2022
0 10
0
10
Steve_A200
I would like to list results from two events that are linked via common field (system_id), but searched via value onl...
by Steve_A200 Path Finder in Splunk Search 02-16-2022
0 2
0
2
jaxxsplunk
Summary: When using the table command, values are dropped if { is the first character.     index=someindex hos...
by jaxxsplunk Explorer in Splunk Search 02-16-2022
0 2
0
2
tsheets13
I did this a few weeks ago and now I can't seem figure out how I did it. I need a report listing all UFs, with their ...
by tsheets13 Communicator in Splunk Search 02-16-2022
0 5
0
5
hj9b7Cn
Hello everyone, I'm pretty new to Splunk and mostly learning as I go, so please bear with me if this is a common ques...
by hj9b7Cn Engager in Splunk Search 02-16-2022
0 1
0
1
neerajs_81
Hello,  The below search displays  _time in human readable format when count  of the results =1 but in EPOCH format w...
by neerajs_81 Builder in Splunk Search 02-16-2022
0 8
0
8
icehack
Does anyone know where I can find some already created Splunk use cases for github webhook logs? I am having a really...
by icehack Observer in Splunk Search 02-16-2022
0 0
0
0
mv10
I have two sets of IIS data (two sourcetypes) in a single index. One sourcetype logs web service requests, the other ...
by mv10 Path Finder in Splunk Search 02-16-2022
0 7
0
7
mark_chuman
This search: index=perfstats host=hostname | chart max(System_Up_Time) as "System Uptime" by host Outputs a value suc...
by mark_chuman Path Finder in Splunk Search 02-16-2022
0 10
0
10
bijodev1
Hi Everyone,So the goal here is to auto increment / decrement a value based on the position of character present in a...
by bijodev1 Communicator in Splunk Search 02-16-2022
0 5
0
5
chrisboy68
Hi, struggling trying to count objects in a big json doc. I'm on version 8.0.5, so function json_keys is not availabl...
by chrisboy68 Contributor in Splunk Search 02-16-2022
0 8
0
8
jeffbat
I am running into an issue when I am trying to get a chart to populate with the data as I am expecting. I am running ...
by jeffbat Path Finder in Splunk Search 02-16-2022
0 6
0
6
kc_prane
Hi All,  Can someone please help me in masking data and regex? currently, we have an event where I need to mask certa...
by kc_prane Communicator in Splunk Search 02-16-2022
0 4
0
4
anooshac
Hi all, I have a query which gives this kind of table. Name        Date              Status           Task          S...
by anooshac Communicator in Splunk Search 02-16-2022
0 18
0
18
Jennifer
Here is the original log file: Host availabilty Hashmap is {<!-- -->HKL20167984SIT_13_8225&#61;true, HKL20167984SIT_7_82FB&#61;true, ...
by Jennifer Path Finder in Splunk Search 02-16-2022
0 15
0
15
JudgeLaw
Hello, I am looking for some guidance please with regards to a CSV input I have that is automatically updated daily a...
by JudgeLaw Engager in Splunk Search 02-16-2022
0 3
0
3
zacksoft_wf
My events are in json format.The  json path where my data is , is here  "alert.smtp-message.smtp-header"And with in "...
by zacksoft_wf Contributor in Splunk Search 02-16-2022
0 3
0
3
Jennifer
Hi, all! How could I make this pattern "HKL20167991SIT_7_8299&#61;true" from my log files into 'XXXX'(the last four digit...
by Jennifer Path Finder in Splunk Search 02-16-2022
0 4
0
4
Gian89
Hello Splunkers,for a project I'm working on, I would need to store different IDs in a variable after evaluating them...
by Gian89 Explorer in Splunk Search 02-16-2022
0 2
0
2
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...