Splunk Search

Splunk Search
Community Activity
staymini
I want to divide different multi-values based on IP.Current results:IPdateeventrisk1.1.1.12022-01-012022-01-02apache ...
by staymini Explorer in Splunk Search 01-07-2022
1 4
1
4
Bleepie
Dear Splunk Community,Every 5 minutes the following event is generated :2022-01-05 21:20:33 : RunningOR2022-01-05 20:...
by Bleepie Communicator in Splunk Search 01-07-2022
0 3
0
3
srinivas_gowda
Hello all, I am trying to extract an field from the below event and using the below add extraction, however this extr...
by srinivas_gowda Path Finder in Splunk Search 01-07-2022
0 2
0
2
leandromatperei
I need to extract the contents of the message field into a json log, but the first strings must be ignored until 'std...
by leandromatperei Path Finder in Splunk Search 01-07-2022
0 4
0
4
whitefang1726
Hello Splunk Answers, How can I remove this duplicate line? See sample below:From: row1     row2       row31.1.1.1  X...
by whitefang1726 Path Finder in Splunk Search 01-06-2022
0 6
0
6
hpaknia
I want to search like:index=whatever "term_1" AND (at least one event in the source of the found record contains term...
by hpaknia Explorer in Splunk Search 01-06-2022
1 4
1
4
apeadape
Hello,I've got a search query where I'm looking for unexpected ssh connections to my instances, but I've got one serv...
by apeadape Explorer in Splunk Search 01-06-2022
0 1
0
1
cyberdiver
TLDR: I'm trying to automate the large 25 day search to break up into 25 separate one day searches.I'm updating a loo...
by cyberdiver Explorer in Splunk Search 01-06-2022
0 6
0
6
cyberdiver
Log4J Query: index=* | regex _raw="(\$|%24)(\{|%7B)([^jJ]*[jJ])([^nN]*[nN])([^dD]*[dD])([^iI]*[iI])(:|%3A|\$|%24|}|%7...
by cyberdiver Explorer in Splunk Search 01-06-2022
0 4
0
4
emcglade
Hi, Wondering if anyone can help. I am trying to create a new field called FS_Owner_Mail using |eval from both the ma...
by emcglade Engager in Splunk Search 01-06-2022
0 4
0
4
PraveenaR
Hello All, 1) I would like to add radio button / any way to select - one of the results of my below REST query search...
by PraveenaR Explorer in Splunk Search 01-05-2022
0 1
0
1
martin61
I have two dropdowns.  I only want to run a single dropdown everytime for a search.Closed Dropdown has token value as...
by martin61 Engager in Splunk Search 01-05-2022
0 1
0
1
amys
..
by amys Engager in Splunk Search 01-05-2022
0 0
0
0
mangaldev
I have 2 type of search messages -Problem #1Problem #5and other one goes like this -Solved problem_id successful: 1So...
by mangaldev Engager in Splunk Search 01-05-2022
0 1
0
1
dantose
I've got some queries I need to do periodically that use the exact same base search, one with teh weekly uniques and ...
by dantose Explorer in Splunk Search 01-05-2022
0 3
0
3
diptij
In Java, I am trying to call a curl command that has a Splunk search to get contents of a lookup file.I've used https...
by diptij Path Finder in Splunk Search 01-05-2022
0 2
0
2
cmckenna
I use a lookup to define alert/SLO specifications. I use the lookups as input filters to my alert searches where I ca...
by cmckenna Explorer in Splunk Search 01-05-2022
1 5
1
5
indeed_2000
Hi, How can I extract pattern of raw data like pattern tab in splunk search?  Thanks
by indeed_2000 Motivator in Splunk Search 01-05-2022
0 6
0
6
mah
Hi,How can I write the name of a field in the value like I have :test_1test_2test_3warnerrorcritical I want :testtest...
by mah Builder in Splunk Search 01-05-2022
0 1
0
1
mah
Hello,I have a table like that :customerprod_1prod_2prod_3customer_1 green customer_2red orange and I would like to c...
by mah Builder in Splunk Search 01-05-2022
0 2
0
2
Fredrik
Hi! I have a summarized field (docsReturned) by customer id that I would like to make a top X pie chart of, while sum...
by Fredrik New Member in Splunk Search 01-05-2022
0 0
0
0
neethan
| savedsearch cbp_inc_base | eval _time=strftime(opened_time, "%Y/%m/%d") || bin _time span=1d here _ time is giving ...
by neethan Path Finder in Splunk Search 01-05-2022
0 10
0
10
nikhilup
First queryindex = pcf_logs cf_org_name = creorg OR cf_org_name = SvcITDnFAppsOrg cf_app_name=VerifyReviewConsumerSer...
by nikhilup New Member in Splunk Search 01-05-2022
0 2
0
2
Anita
If I use bin _time as time span=15m | stats count by time on 17:20 for the past 1 hour, the result would be like...ti...
by Anita Engager in Splunk Search 01-05-2022
0 3
0
3
kapoorsumit2020
When i convert following timestamp to human readable format i am getting "12/31/9999 23:59:59" instead of '01/04/22 0...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 01-04-2022
0 3
0
3
Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...
Top Solution Authors