Splunk Search

Splunk Search
Community Activity
johnlzy0408
Hi,  i am trying to search for host that are sending logs over the last 7 days. Anything more than 7 days i will like...
by johnlzy0408 Loves-to-Learn Everything in Splunk Search 02-03-2022
0 1
0
1
srinivas_gowda
Hello all, I am trying to exclude an specific value within a field while retaining others. Can you please let me know...
by srinivas_gowda Path Finder in Splunk Search 02-03-2022
0 2
0
2
fdi01
i have these events: status | host | comments | ticket_number ... inprogress ...
by fdi01 Motivator in Splunk Search 02-03-2022
2 6
2
6
frbuser
I am trying to match a directory path including the string "\Users" but Splunk is throwing an error: | rex field=Targ...
by frbuser Path Finder in Splunk Search 02-03-2022
0 6
0
6
BradenFTL
I have an automated script that creates a log file that marks the beginning and end of specific events during a web p...
by BradenFTL Explorer in Splunk Search 02-03-2022
0 6
0
6
HelloItsMe76
I have an index which searches across 10 hosts. I am comparing 2 strings and evaluating the results to see if there i...
by HelloItsMe76 Explorer in Splunk Search 02-03-2022
0 4
0
4
Dhana
Hello,So the requirement was to find gaps of data unavailability(start time & end time)  in the  given time range, co...
by Dhana Explorer in Splunk Search 02-03-2022
0 0
0
0
andyd
Hello,I have a field 'narrative' which contains long strings describing what happened to a piece of equipment.  Withi...
by andyd Engager in Splunk Search 02-03-2022
0 3
0
3
sm1tty
I am coming across an interesting problem where notables are being generated for each event in Splunk with unique not...
by sm1tty Loves-to-Learn Lots in Splunk Search 02-03-2022
0 0
0
0
bijodev1
I need to run three different queries based on the each respective results. for example :1) In the first one query : ...
by bijodev1 Communicator in Splunk Search 02-03-2022
0 2
0
2
madhav_dholakia
Hello,I have got 2 data sets resides in same index but with different source/host: index="tickets" host="RMM_DATA" i...
by madhav_dholakia Contributor in Splunk Search 02-03-2022
0 11
0
11
kajalchopade071
How can i populate data from primary index to summary index using collect command. By using collect command can we po...
by kajalchopade071 Path Finder in Splunk Search 02-03-2022
0 2
0
2
robnewman666
So I have a particular number of important csv files that I need to ensure have no errors - which I can lookup using ...
by robnewman666 Path Finder in Splunk Search 02-03-2022
0 4
0
4
yatyat
Hi All,I have below splunk data:"new request: 127.0.0.1;url=login.jsp"which contains the IPADDRESS (EX:127.0.0.1) and...
by yatyat Observer in Splunk Search 02-03-2022
0 3
0
3
rboya_splunk
I am trying to identify the values that are in the logs not matching with content in the lookup file. But i am not ge...
by rboya_splunk Loves-to-Learn in Splunk Search 02-03-2022
0 4
0
4
kajalchopade071
Username status User1       loginUser2       loginUser3       login User1     logout User1     loginUser1    logout N...
by kajalchopade071 Path Finder in Splunk Search 02-03-2022
0 5
0
5
jenkinsta
I have a json data from file generated from the okla speedtest -f json command. I have tried to cast it or eval in di...
by jenkinsta Path Finder in Splunk Search 02-02-2022
0 2
0
2
SMM10
I have the following query that I am working to establish a prediction for. I am able to be the volume to predict but...
by SMM10 Explorer in Splunk Search 02-02-2022
0 0
0
0
bapun18
I want to provide read permission for only one app not all apps to a particular role and in my environment under apps...
by bapun18 Communicator in Splunk Search 02-02-2022
0 1
0
1
andres91302
Hello Everyone I hope you are having a great day,This new dashboaard studio feature is GREAT 10/10 but I'm having a l...
by andres91302 Communicator in Splunk Search 02-02-2022
0 1
0
1
mjones414
I'm trying to set a new dashboard token on click of a country in a choropleth that would populate with the iso2 value...
by mjones414 Contributor in Splunk Search 02-02-2022
0 1
0
1
parkertctr
Good Day, I am trying to come up with ideas to translate a Sumo Trasactional search with (States) Conditions to a Spl...
by parkertctr Path Finder in Splunk Search 02-02-2022
0 0
0
0
weidertc
I have a lookup table with a field that contains a macro name. the rows returned from the lookup table dictate which...
by weidertc Contributor in Splunk Search 02-02-2022
0 3
0
3
kajalchopade071
I have One primary index which contains 30 days logs, but i want from one year for this purpose i created One more sp...
by kajalchopade071 Path Finder in Splunk Search 02-02-2022
0 3
0
3
haist
Hi,I'm new to Splunk and I would like to get top errors on a table, but the external API returns a stack tracing maki...
by haist Explorer in Splunk Search 02-02-2022
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...