Splunk Search

Splunk Search
Community Activity
responsys_cm
Let's say I have a CSV input with the following columns:  _raw,user,src_ipThe _raw event is:  "Accepted public key fo...
by responsys_cm Builder in Splunk Search 02-01-2022
0 1
0
1
96nick
Hey Splunkers. Quick question regarding my lookup. I have the Identity lookup with ES and I'd like to replace the 'pr...
by 96nick Communicator in Splunk Search 02-01-2022
0 5
0
5
khalidpunk
I am doing a CTF that provides logs to filter and work through, one of the questions asks for the time period between...
by khalidpunk New Member in Splunk Search 02-01-2022
0 1
0
1
shaileshransing
I have 2 columns 1 has application name another has number of  instances . I want to remove duplicate application nam...
by shaileshransing Engager in Splunk Search 02-01-2022
0 2
0
2
scarpio
Hello,We recently installed Splunk, we thought we had a free license, however we got a notice that we have exceeded t...
by scarpio Explorer in Splunk Search 02-01-2022
0 5
0
5
crmarley20
Hello,I have a condition when the variable new_tag of the previous row is equal to 1 and the variable test_tag of the...
by crmarley20 Explorer in Splunk Search 02-01-2022
0 2
0
2
Jennifer
Hi, all!Here's my current time format! How could I adjust into the format from 2022-01-20 18:21:19,448 to 2022-01-20 ...
by Jennifer Path Finder in Splunk Search 02-01-2022
0 2
0
2
podegard
After upgrading our environment from 8.1.3 to 8.2.3, some searches return "StatsFileWriterLz4 file open failed". Our ...
by podegard Engager in Splunk Search 02-01-2022
1 1
1
1
jip31
HiI launch a dashboard from another dashboard when I click on the field "Site"/app/spl_pub_dashboard/bib_reg?Site=$cl...
by jip31 Motivator in Splunk Search 02-01-2022
0 2
0
2
bmer
Hi,Iam a newbie and have just started exploring the power of splunk. My below query works fine except that I need the...
by bmer Explorer in Splunk Search 02-01-2022
0 3
0
3
priya1926
hi,i am using the below query to list the bootup time and downtime based on event code.. but if the bootuptime shows ...
by priya1926 Path Finder in Splunk Search 01-31-2022
0 3
0
3
Marco_Develops
Hello All, I am trying to calculate the Average of a column, but i want it to ignore all values that are equal to 0. ...
by Marco_Develops Path Finder in Splunk Search 01-31-2022
0 3
0
3
srivenna
Cisco logs with json format is not extracting properly. I tried from GUI using this kv delims in search and they are ...
by srivenna Engager in Splunk Search 01-31-2022
0 0
0
0
maanick87
I have table like below using my splunk query.Request1_tpsRequest1_avgRequest1_p95Request1_p90Request2_tpsRequest2_av...
by maanick87 Loves-to-Learn Lots in Splunk Search 01-31-2022
0 12
0
12
aditsss
Hi All,I want to extract the following word from sentence:nodeUrl=https://sappbos.aexp.com/odata.svc/v1.0/BlazeoData/...
by aditsss Motivator in Splunk Search 01-31-2022
0 2
0
2
innoce
I want to limit the search that matches the "dest" values which are a part of lookupCurrently I am getting all events...
by innoce Path Finder in Splunk Search 01-31-2022
0 2
0
2
khanlarloo
I want to have a search, the output of which is the next search stream, provided that each occurred at a common time....
by khanlarloo Explorer in Splunk Search 01-31-2022
0 4
0
4
bapun18
Hi Team,I need to use print two values from an index with different earliest values. please find the below example.in...
by bapun18 Communicator in Splunk Search 01-31-2022
0 3
0
3
druid1123
I am trying to find frequently used search filters from my application log.I have written a below query to extract a ...
by druid1123 New Member in Splunk Search 01-31-2022
0 1
0
1
zubairaizatron
Hi guysI'm trying to run a search to the /jobs endpoint. however I get a bash: syntax error near unexpected token `('...
by zubairaizatron Explorer in Splunk Search 01-30-2022
0 2
0
2
zubairaizatron
Hi guysI am definitely a splunk novice. I want to run a search with the splunk REST API. it is a tstats on a datamode...
by zubairaizatron Explorer in Splunk Search 01-30-2022
0 0
0
0
Jamie2Jamie
I'm still new, and struggling with the following. I am looking at a set of data from three probes. If all three probe...
by Jamie2Jamie Loves-to-Learn Lots in Splunk Search 01-30-2022
0 1
0
1
Jennifer
Hi, all!How could I edit my search command in order to filter this table which will display the earliest time of the ...
by Jennifer Path Finder in Splunk Search 01-30-2022
0 1
0
1
indeed_2000
HiI have two field that extract send & rec like this:| rex "S\[(?<SEND>\w+\.\w+)" | rex "R\[(?<REC>\w+\.\w+)" now hav...
by indeed_2000 Motivator in Splunk Search 01-30-2022
0 0
0
0
Raymundo
I have a json raw string from which I have to extract the           "Source device","values":[{"ip":            key a...
by Raymundo Loves-to-Learn in Splunk Search 01-30-2022
0 5
0
5
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...