Splunk Search

Splunk Search
Community Activity
joe06031990
Hi,I am trying to calculate the duration of a call from the bellow search however it is appearing blank, the format i...
by joe06031990 Communicator in Splunk Search 01-24-2022
0 6
0
6
kajalchopade071
Supposed if i have huge data off employees Like name department and status (login /logout )One person can login and l...
by kajalchopade071 Path Finder in Splunk Search 01-24-2022
0 4
0
4
SplunkDash
Hello,I am getting some error messages within my PROPS Configuration file to parse timestamp data. The sample file/ev...
by SplunkDash Motivator in Splunk Search 01-24-2022
0 1
0
1
arist0telis
I've been looking around here and on Google but can't find an answer to this specific usecase: I have two sourcetypes...
by arist0telis Explorer in Splunk Search 01-24-2022
0 2
0
2
crlunde
Hello,I'm trying to search Splunk for user activity pertaining to logging into Splunk for X # of days. Everything I'v...
by crlunde Loves-to-Learn Everything in Splunk Search 01-24-2022
0 2
0
2
rkishoreqa
Hi team,  I need to fetch the 'InterfaceName' from the below payload.  I built a regular expression but it is not wor...
by rkishoreqa Communicator in Splunk Search 01-24-2022
0 1
0
1
tkw03
Hello I have some data in a txt file that I am working on extractions for. It extracts fine except that in some of t...
by tkw03 Communicator in Splunk Search 01-24-2022
0 3
0
3
rune_hellem
I have created a search that will trigger if no events from the following search is being returnedindex=ipl_prod sour...
by rune_hellem Contributor in Splunk Search 01-23-2022
0 2
0
2
sjringo
I have a query that returns a set of hosts that have an event string.index=anIndex sourcetype=aSourceType ("aString1"...
by sjringo Contributor in Splunk Search 01-23-2022
0 12
0
12
Itsecuser1
index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > ...
by Itsecuser1 New Member in Splunk Search 01-23-2022
0 3
0
3
chongdong
I am trying to add 2 new fields into a chart, which is calculated by the exisiting columns in the following chart. Ba...
by chongdong Explorer in Splunk Search 01-23-2022
0 6
0
6
LolabhattuA
My file contains a line at the last where it mentions the return code. The format look like below mentioned. If the j...
by LolabhattuA Loves-to-Learn in Splunk Search 01-23-2022
0 4
0
4
feelcool
Hello,everyone!At first, sorry for my bad English.I have a problem to join two result.The raw data is a reg file, lik...
by feelcool Explorer in Splunk Search 01-22-2022
0 7
0
7
jbrenner
I have a Splunk query that does a lot of computation and eventually returns only two calculated fields:  _time and ST...
by jbrenner Path Finder in Splunk Search 01-22-2022
0 3
0
3
roopeshetty
Hi Guys I have a query like this <query>| stats avg(CurrentConnections) as CC by host  And the output is as below wit...
by roopeshetty Path Finder in Splunk Search 01-22-2022
0 3
0
3
dsmith
I'm trying to get a new sourcetype (NetApp user-level audit logs, exported as XML) to work, and I think my fields.con...
by dsmith Path Finder in Splunk Search 01-22-2022
0 12
0
12
dasaed
I have a JSON with a field containing another object, but this object varies depending on type. For example, you may ...
by dasaed Explorer in Splunk Search 01-22-2022
0 3
0
3
jbrenner
I have a transaction command which correlates two log entries. If I pipe this result into a timechart command, which ...
by jbrenner Path Finder in Splunk Search 01-21-2022
0 2
0
2
Razziq
Hello,I have a script gathering the last updated timestamp of three different files and I'm ingesting that data into ...
by Razziq Explorer in Splunk Search 01-21-2022
0 1
0
1
steen
Hi,In the past (Splunk Enterprise v 7.x.x) I used the below search to run a report every few min. There were so many ...
by steen Explorer in Splunk Search 01-21-2022
0 5
0
5
parkertctr
I am trying to use the case match command with more than one option. I keep getting an error message regarding the pa...
by parkertctr Path Finder in Splunk Search 01-21-2022
0 2
0
2
andres
I have a raw where each event looks like this (simplified for this exampel):{"time": "2022-01-20 16:40:02.325216", "n...
by andres Loves-to-Learn Lots in Splunk Search 01-21-2022
0 2
0
2
Ashwini_5
I would like to count the multifield in the table where it has similar values. For Ex:  I need output like below for ...
by Ashwini_5 Explorer in Splunk Search 01-21-2022
0 2
0
2
nate_washburn
Hi, in my index I have a couple time fields that are returned via a simple search_time = 1/20/2022 1:38:55.000 PM (th...
by nate_washburn Engager in Splunk Search 01-21-2022
0 2
0
2
danielbb
We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.H...
by danielbb Motivator in Splunk Search 01-21-2022
0 2
0
2
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...