Splunk Search

Splunk Search
Community Activity
crlunde
Hello,I'm trying to search Splunk for user activity pertaining to logging into Splunk for X # of days. Everything I'v...
by crlunde Loves-to-Learn Everything in Splunk Search 01-24-2022
0 2
0
2
rkishoreqa
Hi team,  I need to fetch the 'InterfaceName' from the below payload.  I built a regular expression but it is not wor...
by rkishoreqa Communicator in Splunk Search 01-24-2022
0 1
0
1
tkw03
Hello I have some data in a txt file that I am working on extractions for. It extracts fine except that in some of t...
by tkw03 Communicator in Splunk Search 01-24-2022
0 3
0
3
rune_hellem
I have created a search that will trigger if no events from the following search is being returnedindex=ipl_prod sour...
by rune_hellem Contributor in Splunk Search 01-23-2022
0 2
0
2
sjringo
I have a query that returns a set of hosts that have an event string.index=anIndex sourcetype=aSourceType ("aString1"...
by sjringo Contributor in Splunk Search 01-23-2022
0 12
0
12
Itsecuser1
index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > ...
by Itsecuser1 New Member in Splunk Search 01-23-2022
0 3
0
3
chongdong
I am trying to add 2 new fields into a chart, which is calculated by the exisiting columns in the following chart. Ba...
by chongdong Explorer in Splunk Search 01-23-2022
0 6
0
6
LolabhattuA
My file contains a line at the last where it mentions the return code. The format look like below mentioned. If the j...
by LolabhattuA Loves-to-Learn in Splunk Search 01-23-2022
0 4
0
4
feelcool
Hello,everyone!At first, sorry for my bad English.I have a problem to join two result.The raw data is a reg file, lik...
by feelcool Explorer in Splunk Search 01-22-2022
0 7
0
7
jbrenner
I have a Splunk query that does a lot of computation and eventually returns only two calculated fields:  _time and ST...
by jbrenner Path Finder in Splunk Search 01-22-2022
0 3
0
3
roopeshetty
Hi Guys I have a query like this <query>| stats avg(CurrentConnections) as CC by host  And the output is as below wit...
by roopeshetty Path Finder in Splunk Search 01-22-2022
0 3
0
3
dsmith
I'm trying to get a new sourcetype (NetApp user-level audit logs, exported as XML) to work, and I think my fields.con...
by dsmith Path Finder in Splunk Search 01-22-2022
0 12
0
12
dasaed
I have a JSON with a field containing another object, but this object varies depending on type. For example, you may ...
by dasaed Explorer in Splunk Search 01-22-2022
0 3
0
3
jbrenner
I have a transaction command which correlates two log entries. If I pipe this result into a timechart command, which ...
by jbrenner Path Finder in Splunk Search 01-21-2022
0 2
0
2
Razziq
Hello,I have a script gathering the last updated timestamp of three different files and I'm ingesting that data into ...
by Razziq Explorer in Splunk Search 01-21-2022
0 1
0
1
steen
Hi,In the past (Splunk Enterprise v 7.x.x) I used the below search to run a report every few min. There were so many ...
by steen Explorer in Splunk Search 01-21-2022
0 5
0
5
parkertctr
I am trying to use the case match command with more than one option. I keep getting an error message regarding the pa...
by parkertctr Path Finder in Splunk Search 01-21-2022
0 2
0
2
andres
I have a raw where each event looks like this (simplified for this exampel):{"time": "2022-01-20 16:40:02.325216", "n...
by andres Loves-to-Learn Lots in Splunk Search 01-21-2022
0 2
0
2
Ashwini_5
I would like to count the multifield in the table where it has similar values. For Ex:  I need output like below for ...
by Ashwini_5 Explorer in Splunk Search 01-21-2022
0 2
0
2
nate_washburn
Hi, in my index I have a couple time fields that are returned via a simple search_time = 1/20/2022 1:38:55.000 PM (th...
by nate_washburn Engager in Splunk Search 01-21-2022
0 2
0
2
danielbb
We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.H...
by danielbb Motivator in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log entries, I wanted to extract uri in a specific format:log: a_level="INFO", a_time="null", a_t...
by nbhat Explorer in Splunk Search 01-21-2022
0 1
0
1
alexandrebas
I need help regarding comparise a ISO 8601 date field with a specific date.Below is a simple example:index=devices | ...
by alexandrebas Explorer in Splunk Search 01-21-2022
0 1
0
1
zacksoft_wf
I have,sourcetype_A  (fields : ID, age, city, state)sourcetype_B  (fields : ID, job, salary, gender)The fields "ID" i...
by zacksoft_wf Contributor in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log, I wanted to extract Url, Method, ResponseTimeMs, StatusCode as a table:log: a_level="INFO", ...
by nbhat Explorer in Splunk Search 01-21-2022
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...