Splunk Search

Splunk Search
Community Activity
klaudiac
Hi folks,Hoping you might be able to help.I've some raw logs coming in and one of the "extracted" fields is a fields ...
by klaudiac Path Finder in Splunk Search 01-26-2022
0 1
0
1
Yadukrishnan
Hi,I have installed and configured Palo Alto Addon which is creating multiple eventtypes , one of which is pan_traffi...
by Yadukrishnan Explorer in Splunk Search 01-26-2022
0 0
0
0
kirrusk
Hi,Splunk search query to get data last two months data.need only every Friday data in the time range for 15 mins (i....
by kirrusk Communicator in Splunk Search 01-26-2022
0 5
0
5
TomohikoHoshino
Splunk search headで以下のクエリとした場合、service毎に2日ごとに合計量が表示されてしまいます。timechart limit=0 useother=false span=2d count by service...
by TomohikoHoshino Observer in Splunk Search 01-26-2022
0 0
0
0
patelmc
Hello, I see following in _raw.  However, when I run search with table or fields it does not display text within doub...
by patelmc Explorer in Splunk Search 01-25-2022
0 3
0
3
zacksoft_wf
My query after finalizing for some time , gives me, The search processs with sid= was forcefully terminated because i...
by zacksoft_wf Contributor in Splunk Search 01-25-2022
0 5
0
5
sarithbabu
I was trying to join multiple lines generated in /var/log/secure. I tried with transaction but looks like that doesn'...
by sarithbabu Engager in Splunk Search 01-25-2022
0 2
0
2
magriii
I found that the format of a sourcetype had changed some time ago.Now I need to extract the data correctly for both c...
by magriii Explorer in Splunk Search 01-25-2022
0 1
0
1
ruman
There are a couple of good answers here for deduping a multivalue field in a search, but how can I dedupe a multivalu...
by ruman Splunk Employee Splunk Employee in Splunk Search 01-25-2022
0 3
0
3
mbasharat
Hi,I am trying to calculate age for a task. Time is in below format. What am I missing?| makeresults| eval Last_Check...
by mbasharat Builder in Splunk Search 01-25-2022
0 5
0
5
Jennifer
Hi, all!Here are the sources that I want to contain at my search:- /appvol/wlp/DIVR01HK-AS01/applogs/appl.log- /appvo...
by Jennifer Path Finder in Splunk Search 01-25-2022
0 2
0
2
joe06031990
Hi,I am trying to calculate the duration of a call from the bellow search however it is appearing blank, the format i...
by joe06031990 Communicator in Splunk Search 01-24-2022
0 6
0
6
kajalchopade071
Supposed if i have huge data off employees Like name department and status (login /logout )One person can login and l...
by kajalchopade071 Path Finder in Splunk Search 01-24-2022
0 4
0
4
SplunkDash
Hello,I am getting some error messages within my PROPS Configuration file to parse timestamp data. The sample file/ev...
by SplunkDash Motivator in Splunk Search 01-24-2022
0 1
0
1
arist0telis
I've been looking around here and on Google but can't find an answer to this specific usecase: I have two sourcetypes...
by arist0telis Explorer in Splunk Search 01-24-2022
0 2
0
2
crlunde
Hello,I'm trying to search Splunk for user activity pertaining to logging into Splunk for X # of days. Everything I'v...
by crlunde Loves-to-Learn Everything in Splunk Search 01-24-2022
0 2
0
2
rkishoreqa
Hi team,  I need to fetch the 'InterfaceName' from the below payload.  I built a regular expression but it is not wor...
by rkishoreqa Communicator in Splunk Search 01-24-2022
0 1
0
1
tkw03
Hello I have some data in a txt file that I am working on extractions for. It extracts fine except that in some of t...
by tkw03 Communicator in Splunk Search 01-24-2022
0 3
0
3
rune_hellem
I have created a search that will trigger if no events from the following search is being returnedindex=ipl_prod sour...
by rune_hellem Contributor in Splunk Search 01-23-2022
0 2
0
2
sjringo
I have a query that returns a set of hosts that have an event string.index=anIndex sourcetype=aSourceType ("aString1"...
by sjringo Contributor in Splunk Search 01-23-2022
0 12
0
12
Itsecuser1
index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > ...
by Itsecuser1 New Member in Splunk Search 01-23-2022
0 3
0
3
chongdong
I am trying to add 2 new fields into a chart, which is calculated by the exisiting columns in the following chart. Ba...
by chongdong Explorer in Splunk Search 01-23-2022
0 6
0
6
LolabhattuA
My file contains a line at the last where it mentions the return code. The format look like below mentioned. If the j...
by LolabhattuA Loves-to-Learn in Splunk Search 01-23-2022
0 4
0
4
feelcool
Hello,everyone!At first, sorry for my bad English.I have a problem to join two result.The raw data is a reg file, lik...
by feelcool Explorer in Splunk Search 01-22-2022
0 7
0
7
jbrenner
I have a Splunk query that does a lot of computation and eventually returns only two calculated fields:  _time and ST...
by jbrenner Path Finder in Splunk Search 01-22-2022
0 3
0
3
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...