Splunk Search

Splunk Search
Community Activity
kirrusk
Hi, I'm trying to figure out how to get data for the past few weeks and data will be filtered.week start should be fr...
by kirrusk Communicator in Splunk Search 01-26-2022
0 7
0
7
joe06031990
Hi,I have splunk Waiting for queued job to start getting error for a particular user however no jobs are queued for t...
by joe06031990 Communicator in Splunk Search 01-26-2022
0 3
0
3
thin_air
New to the community so all help is appreciated!RequirementWe have a requirement to filter some network data in a cor...
by thin_air Engager in Splunk Search 01-26-2022
0 5
0
5
Aishanazam
 Need better option to get user id from first search to populate results using the subsearch.  thought join would wor...
by Aishanazam Loves-to-Learn Lots in Splunk Search 01-26-2022
0 3
0
3
klaudiac
Hi folks,Hoping you might be able to help.I've some raw logs coming in and one of the "extracted" fields is a fields ...
by klaudiac Path Finder in Splunk Search 01-26-2022
0 1
0
1
Yadukrishnan
Hi,I have installed and configured Palo Alto Addon which is creating multiple eventtypes , one of which is pan_traffi...
by Yadukrishnan Explorer in Splunk Search 01-26-2022
0 0
0
0
kirrusk
Hi,Splunk search query to get data last two months data.need only every Friday data in the time range for 15 mins (i....
by kirrusk Communicator in Splunk Search 01-26-2022
0 5
0
5
TomohikoHoshino
Splunk search headで以下のクエリとした場合、service毎に2日ごとに合計量が表示されてしまいます。timechart limit=0 useother=false span=2d count by service...
by TomohikoHoshino Observer in Splunk Search 01-26-2022
0 0
0
0
patelmc
Hello, I see following in _raw.  However, when I run search with table or fields it does not display text within doub...
by patelmc Explorer in Splunk Search 01-25-2022
0 3
0
3
zacksoft_wf
My query after finalizing for some time , gives me, The search processs with sid= was forcefully terminated because i...
by zacksoft_wf Contributor in Splunk Search 01-25-2022
0 5
0
5
sarithbabu
I was trying to join multiple lines generated in /var/log/secure. I tried with transaction but looks like that doesn'...
by sarithbabu Engager in Splunk Search 01-25-2022
0 2
0
2
magriii
I found that the format of a sourcetype had changed some time ago.Now I need to extract the data correctly for both c...
by magriii Explorer in Splunk Search 01-25-2022
0 1
0
1
ruman
There are a couple of good answers here for deduping a multivalue field in a search, but how can I dedupe a multivalu...
by ruman Splunk Employee Splunk Employee in Splunk Search 01-25-2022
0 3
0
3
mbasharat
Hi,I am trying to calculate age for a task. Time is in below format. What am I missing?| makeresults| eval Last_Check...
by mbasharat Builder in Splunk Search 01-25-2022
0 5
0
5
Jennifer
Hi, all!Here are the sources that I want to contain at my search:- /appvol/wlp/DIVR01HK-AS01/applogs/appl.log- /appvo...
by Jennifer Path Finder in Splunk Search 01-25-2022
0 2
0
2
joe06031990
Hi,I am trying to calculate the duration of a call from the bellow search however it is appearing blank, the format i...
by joe06031990 Communicator in Splunk Search 01-24-2022
0 6
0
6
kajalchopade071
Supposed if i have huge data off employees Like name department and status (login /logout )One person can login and l...
by kajalchopade071 Path Finder in Splunk Search 01-24-2022
0 4
0
4
SplunkDash
Hello,I am getting some error messages within my PROPS Configuration file to parse timestamp data. The sample file/ev...
by SplunkDash Motivator in Splunk Search 01-24-2022
0 1
0
1
arist0telis
I've been looking around here and on Google but can't find an answer to this specific usecase: I have two sourcetypes...
by arist0telis Explorer in Splunk Search 01-24-2022
0 2
0
2
crlunde
Hello,I'm trying to search Splunk for user activity pertaining to logging into Splunk for X # of days. Everything I'v...
by crlunde Loves-to-Learn Everything in Splunk Search 01-24-2022
0 2
0
2
rkishoreqa
Hi team,  I need to fetch the 'InterfaceName' from the below payload.  I built a regular expression but it is not wor...
by rkishoreqa Communicator in Splunk Search 01-24-2022
0 1
0
1
tkw03
Hello I have some data in a txt file that I am working on extractions for. It extracts fine except that in some of t...
by tkw03 Communicator in Splunk Search 01-24-2022
0 3
0
3
rune_hellem
I have created a search that will trigger if no events from the following search is being returnedindex=ipl_prod sour...
by rune_hellem Contributor in Splunk Search 01-23-2022
0 2
0
2
sjringo
I have a query that returns a set of hosts that have an event string.index=anIndex sourcetype=aSourceType ("aString1"...
by sjringo Contributor in Splunk Search 01-23-2022
0 12
0
12
Itsecuser1
index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > ...
by Itsecuser1 New Member in Splunk Search 01-23-2022
0 3
0
3
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors