Splunk Search

Splunk Search
Community Activity
gkochner1
I want to check in some strings are exist in a column and if they are I want to add another column with the type of t...
by gkochner1 Observer in Splunk Search 01-19-2022
0 1
0
1
Bleepie
Dear Splunk Community,I have the following query. The main query looks for errors in certain log files. If they are f...
by Bleepie Communicator in Splunk Search 01-19-2022
0 1
0
1
hank72
Please help!I have a lookup table and some data in two different indexes. Please help with a search that will produce...
by hank72 Path Finder in Splunk Search 01-19-2022
0 2
0
2
Ab_Splunk
Good Afternoon, So I've recently been hired on as a Splunk admin/analyst.  The scope of my job really relies on my be...
by Ab_Splunk Engager in Splunk Search 01-18-2022
0 5
0
5
websplunk01
Hi , I am trying to figure out how to write a query to create an alert that will alert me whenever a user is logged o...
by websplunk01 Engager in Splunk Search 01-18-2022
0 18
0
18
eranhauser
My main query looks like:...| stats min(_time) AS SESSION_START_TIME max(Source_Network_Address) AS EMP_SRC_IP...| ev...
by eranhauser Path Finder in Splunk Search 01-18-2022
0 12
0
12
Veeru
In above image i couldn’t able to access the date input,It’s actually a client server as user I couldn’t able access...
by Veeru Path Finder in Splunk Search 01-18-2022
0 1
0
1
jenkinsta
My data is like this illustration purposes only:LocalIp aip10.10.10.1192.168.1.110.10.10.2172.58.100.4110.10.12.38.8....
by jenkinsta Path Finder in Splunk Search 01-18-2022
0 4
0
4
scc00
I have been asked to ensure that the DOD CAC can be used to log into the Splunk Search Heads. Does anyone know how to...
by scc00 Contributor in Splunk Search 01-18-2022
0 5
0
5
Wojt3k
Hello, I would like change bare host name to host name with a domain name. According to all articles I have changed t...
by Wojt3k Engager in Splunk Search 01-18-2022
0 0
0
0
ManfredGrill
Hi,various tables from a database are read by Splunk. I need to combine fields from all 3 datasources. The ID-fields ...
by ManfredGrill Explorer in Splunk Search 01-18-2022
0 2
0
2
nunoaragao
While most Warn and Errors show up on the Job dropdown (1) some are also displayed in an area right below the search ...
by nunoaragao Path Finder in Splunk Search 01-18-2022
0 0
0
0
BigShak
Hello there,I want to make a top 10 of applications based on top 10 of categories.Here is an example:CategoryNb of al...
by BigShak Explorer in Splunk Search 01-18-2022
0 4
0
4
just_me
Hi all, I have been using a subsearch in a timechart command to dynamically select the correct span. The query looks ...
by just_me New Member in Splunk Search 01-18-2022
0 0
0
0
i_am_manish
If i have n numbers of router in my index  and i want to know the current status of router if its connected or failed...
by i_am_manish New Member in Splunk Search 01-18-2022
0 2
0
2
innoce
Hello,Can someone please help me with a query to find who deleted the files of users (user=x, y, z) from a folder. in...
by innoce Path Finder in Splunk Search 01-18-2022
0 1
0
1
armahalma
Is there a way to add a field to an event from a different event assuming they have a common key using a simple searc...
by armahalma New Member in Splunk Search 01-17-2022
0 3
0
3
bwgates
I've been able to configure SSO for CAC via Apache proxy and everything works fine. I'm trying to figure out how to d...
by bwgates Explorer in Splunk Search 01-17-2022
0 3
0
3
timgren
Can a search time limit be applied differently by index rather than by role? Currently, we have a search roll limit o...
by timgren Path Finder in Splunk Search 01-17-2022
0 1
0
1
Veeru
index IN (A,B) sourcetype IN (A,B) earliest=-12h latest=@m| transaction UUID keepevicted=true| eval ReportKey="Today"...
by Veeru Path Finder in Splunk Search 01-17-2022
0 6
0
6
ravinayan_acc
Hi All,I have done a index search for disk data and then lookup to the CSV to check as per the Application which serv...
by ravinayan_acc Loves-to-Learn Lots in Splunk Search 01-17-2022
0 1
0
1
srivenna
recently we onboarded these logs but most of the fields are not extracted though these values are mentioned with =. I...
by srivenna Engager in Splunk Search 01-17-2022
0 5
0
5
Ctpelster
Hi, I want to create the following excel table using splunk. The first 3 columns are based on the output of a query, ...
by Ctpelster Engager in Splunk Search 01-17-2022
0 2
0
2
plcd63
Dear Splunk Community,I'm trying to extract a list of changed fields, but they should only be listed if they have a v...
by plcd63 Explorer in Splunk Search 01-17-2022
0 4
0
4
indeed_2000
HiI have events like this: 1900/10/26|1900/10/25|333|CHECKOUT |U |2222|000|00 |14|111111 |000000000 |0000 | |12345678...
by indeed_2000 Motivator in Splunk Search 01-17-2022
0 3
0
3
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...