Splunk Search

Splunk Search
Community Activity
sarithbabu
I was trying to join multiple lines generated in /var/log/secure. I tried with transaction but looks like that doesn'...
by sarithbabu Engager in Splunk Search 01-25-2022
0 2
0
2
magriii
I found that the format of a sourcetype had changed some time ago.Now I need to extract the data correctly for both c...
by magriii Explorer in Splunk Search 01-25-2022
0 1
0
1
ruman
There are a couple of good answers here for deduping a multivalue field in a search, but how can I dedupe a multivalu...
by ruman Splunk Employee Splunk Employee in Splunk Search 01-25-2022
0 3
0
3
mbasharat
Hi,I am trying to calculate age for a task. Time is in below format. What am I missing?| makeresults| eval Last_Check...
by mbasharat Builder in Splunk Search 01-25-2022
0 5
0
5
Jennifer
Hi, all!Here are the sources that I want to contain at my search:- /appvol/wlp/DIVR01HK-AS01/applogs/appl.log- /appvo...
by Jennifer Path Finder in Splunk Search 01-25-2022
0 2
0
2
joe06031990
Hi,I am trying to calculate the duration of a call from the bellow search however it is appearing blank, the format i...
by joe06031990 Communicator in Splunk Search 01-24-2022
0 6
0
6
kajalchopade071
Supposed if i have huge data off employees Like name department and status (login /logout )One person can login and l...
by kajalchopade071 Path Finder in Splunk Search 01-24-2022
0 4
0
4
SplunkDash
Hello,I am getting some error messages within my PROPS Configuration file to parse timestamp data. The sample file/ev...
by SplunkDash Motivator in Splunk Search 01-24-2022
0 1
0
1
arist0telis
I've been looking around here and on Google but can't find an answer to this specific usecase: I have two sourcetypes...
by arist0telis Explorer in Splunk Search 01-24-2022
0 2
0
2
crlunde
Hello,I'm trying to search Splunk for user activity pertaining to logging into Splunk for X # of days. Everything I'v...
by crlunde Loves-to-Learn Everything in Splunk Search 01-24-2022
0 2
0
2
rkishoreqa
Hi team,  I need to fetch the 'InterfaceName' from the below payload.  I built a regular expression but it is not wor...
by rkishoreqa Communicator in Splunk Search 01-24-2022
0 1
0
1
tkw03
Hello I have some data in a txt file that I am working on extractions for. It extracts fine except that in some of t...
by tkw03 Communicator in Splunk Search 01-24-2022
0 3
0
3
rune_hellem
I have created a search that will trigger if no events from the following search is being returnedindex=ipl_prod sour...
by rune_hellem Contributor in Splunk Search 01-23-2022
0 2
0
2
sjringo
I have a query that returns a set of hosts that have an event string.index=anIndex sourcetype=aSourceType ("aString1"...
by sjringo Contributor in Splunk Search 01-23-2022
0 12
0
12
Itsecuser1
index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > ...
by Itsecuser1 New Member in Splunk Search 01-23-2022
0 3
0
3
chongdong
I am trying to add 2 new fields into a chart, which is calculated by the exisiting columns in the following chart. Ba...
by chongdong Explorer in Splunk Search 01-23-2022
0 6
0
6
LolabhattuA
My file contains a line at the last where it mentions the return code. The format look like below mentioned. If the j...
by LolabhattuA Loves-to-Learn in Splunk Search 01-23-2022
0 4
0
4
feelcool
Hello,everyone!At first, sorry for my bad English.I have a problem to join two result.The raw data is a reg file, lik...
by feelcool Explorer in Splunk Search 01-22-2022
0 7
0
7
jbrenner
I have a Splunk query that does a lot of computation and eventually returns only two calculated fields:  _time and ST...
by jbrenner Path Finder in Splunk Search 01-22-2022
0 3
0
3
roopeshetty
Hi Guys I have a query like this <query>| stats avg(CurrentConnections) as CC by host  And the output is as below wit...
by roopeshetty Path Finder in Splunk Search 01-22-2022
0 3
0
3
dsmith
I'm trying to get a new sourcetype (NetApp user-level audit logs, exported as XML) to work, and I think my fields.con...
by dsmith Path Finder in Splunk Search 01-22-2022
0 12
0
12
dasaed
I have a JSON with a field containing another object, but this object varies depending on type. For example, you may ...
by dasaed Explorer in Splunk Search 01-22-2022
0 3
0
3
jbrenner
I have a transaction command which correlates two log entries. If I pipe this result into a timechart command, which ...
by jbrenner Path Finder in Splunk Search 01-21-2022
0 2
0
2
Razziq
Hello,I have a script gathering the last updated timestamp of three different files and I'm ingesting that data into ...
by Razziq Explorer in Splunk Search 01-21-2022
0 1
0
1
steen
Hi,In the past (Splunk Enterprise v 7.x.x) I used the below search to run a report every few min. There were so many ...
by steen Explorer in Splunk Search 01-21-2022
0 5
0
5
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors