Splunk Search

Splunk Search
Community Activity
kirrusk
Hi, I'm trying to trigger an alert for the below scenarios (one alert).scenario one: when there are no events, trigge...
by kirrusk Communicator in Splunk Search 02-08-2022
0 3
0
3
Jennifer
Hi, all!Here's my log file:- the pattern: raw call progress sequence is: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX- the length...
by Jennifer Path Finder in Splunk Search 02-08-2022
0 1
0
1
kirrusk
Hi, I'm trying to exclude events from the time range.  index = _internal | eval Hour=strftime(_time,"%H") | eval Min...
by kirrusk Communicator in Splunk Search 02-07-2022
0 4
0
4
alastairsin
I am building a dashboard using simple xml. I have a populating search that defines inputs for a dropdown list. The ...
by alastairsin Engager in Splunk Search 02-07-2022
0 11
0
11
Stefanie
I have two lookup files.My first lookup file has the columns: ip, host, dnsName. We will call it List1.csvThe second ...
by Stefanie Builder in Splunk Search 02-07-2022
1 2
1
2
bt149
I have a search that is based on two events types - admin_login and admin_change.  Admin_Login has two fields that th...
by bt149 Path Finder in Splunk Search 02-07-2022
0 2
0
2
paulito
Data:SERVICEPERFDATA::'total 120m'=8%;95;97 SERVICECHECKCOMMAND::check_nrpe3!check_cpu!-a!"warn=load > 95" "crit=load...
by paulito Explorer in Splunk Search 02-07-2022
0 3
0
3
sushantnarula
Hi All,I am running a query and getting limited results in Statistics field (10,000).Earlier I was using the | sort c...
by sushantnarula Observer in Splunk Search 02-07-2022
0 0
0
0
avishni01
HelloI have events that include a field of username ( and of course _time) .I would like to count how many users were...
by avishni01 Explorer in Splunk Search 02-07-2022
0 1
0
1
shruti14
Hi , I have to get the below fields extracted from these three logs to create visulisation: Fields i am interested:Ev...
by shruti14 Explorer in Splunk Search 02-07-2022
0 6
0
6
harshal_chakran
Hi all,I have an authorize.conf located in an application, which is usually deployed via Deployer to SH members.There...
by harshal_chakran Builder in Splunk Search 02-07-2022
0 2
0
2
JosephHobbs
I recently started trying to set up some field extracts for a few of our events.  In this case, the logs are pipe del...
by JosephHobbs Path Finder in Splunk Search 02-07-2022
0 6
0
6
falks405
Hello, I have the next query to get data grouped by month by software version using  condition "where"  index=tst | ...
by falks405 Loves-to-Learn Lots in Splunk Search 02-07-2022
0 0
0
0
kajalchopade071
Can we populate the  primary index logs  to summary index .How to populate the logs from primary index to summary ind...
by kajalchopade071 Path Finder in Splunk Search 02-07-2022
0 1
0
1
anu1729
Below is the query I am  trying to use to get the result but, its giving error  for eval statement. Could anyone plea...
by anu1729 Loves-to-Learn Lots in Splunk Search 02-07-2022
0 2
0
2
balzac13dark
I'm splunk beginner. I want to know which destination IP addresses are used on my enterprise infra by using firewall ...
by balzac13dark Explorer in Splunk Search 02-07-2022
0 8
0
8
satya671
suppose i had data like below field="_raw"afadfadfadfafadsfagafgadfafafastring1 .........afjal;dkfhao ilhafajkf;haldg...
by satya671 Explorer in Splunk Search 02-06-2022
0 2
0
2
kuramesh
Can you pls share the cartToPurchase(%) by productID : purchases/addtocart query 
by kuramesh Loves-to-Learn Lots in Splunk Search 02-06-2022
0 15
0
15
EvansB
Hi folks,What query can I use to sum up my field "viewer.Id" to see how many viewers we have between 01/22/2022 and 0...
by EvansB Path Finder in Splunk Search 02-05-2022
0 6
0
6
Software-Simian
Hello,i am aware that there already is a Question from way back called:"finding peak and low times from timechart"How...
by Software-Simian Path Finder in Splunk Search 02-04-2022
0 2
0
2
np_hwp
Hello experts, If I have only IP address of  hosts from a search, how do I look for its hostname from a lookup table?...
by np_hwp Engager in Splunk Search 02-04-2022
0 3
0
3
pbarna
I have a dataset that looks like: (id, foo, bar, user) that I want to show results for on a dashboard.Given an input ...
by pbarna Explorer in Splunk Search 02-04-2022
0 11
0
11
faaku
I need the results for this question: What if you wanted to find the top product sold and how many people bought it?A...
by faaku Engager in Splunk Search 02-04-2022
0 2
0
2
lmonahan
I have a dashboard and some queries in the panels are taking longer than the allowed 60 seconds to complete.  They ar...
by lmonahan Path Finder in Splunk Search 02-04-2022
0 2
0
2
mdeterville
How do i extract everything after the 3rd / from the left in:WinNT://PSAD/johndoeThe output should be "johndoe"Thanks...
by mdeterville Path Finder in Splunk Search 02-04-2022
0 1
0
1
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...
Top Solution Authors