Splunk Search

Splunk Search
Community Activity
nikhilup
First queryindex = pcf_logs cf_org_name = creorg OR cf_org_name = SvcITDnFAppsOrg cf_app_name=VerifyReviewConsumerSer...
by nikhilup New Member in Splunk Search 01-05-2022
0 2
0
2
Anita
If I use bin _time as time span=15m | stats count by time on 17:20 for the past 1 hour, the result would be like...ti...
by Anita Engager in Splunk Search 01-05-2022
0 3
0
3
kapoorsumit2020
When i convert following timestamp to human readable format i am getting "12/31/9999 23:59:59" instead of '01/04/22 0...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 01-04-2022
0 3
0
3
mah
Hi, I have a table like that :teststate_Astate_Bstate_C1okko- WARNko - ERROR2ko- WARNokok3okokok I would like to crea...
by mah Builder in Splunk Search 01-04-2022
0 4
0
4
Mrig342
Hi All,I have a .csv file  named Master_List.csv added to splunk lookup. It has the values of the fields "Tech Stack"...
by Mrig342 Contributor in Splunk Search 01-04-2022
1 4
1
4
gkanapathy
(Copied from a legacy Splunk Forums post by user bpf) Hello I have the following problem: I have a Name. With this...
by gkanapathy Splunk Employee Splunk Employee in Splunk Search 01-04-2022
4 8
4
8
ashraf_adeelaa
This codeimport splunklib.client as clienthost = "127.0.0.1"port = "8000"username = "---"password = "----"service = c...
by ashraf_adeelaa New Member in Splunk Search 01-04-2022
0 0
0
0
phamxuantung
Hi, I have a list of events span across more than a year, the event will contain type of card, transaction status. I ...
by phamxuantung Communicator in Splunk Search 01-04-2022
0 2
0
2
Atul1507
Hi i am new to splunk.i have splink event like this" system CPU | 6.039 % | system time | 0.009 % |how can i get avg ...
by Atul1507 Loves-to-Learn Lots in Splunk Search 01-03-2022
0 10
0
10
lauMarot
Hello,Suppose I've got the following url among lot of others : (logs come from something close to Squid but not index...
by lauMarot Path Finder in Splunk Search 01-03-2022
0 1
0
1
ASplunkDummy
Dear all, best wishes for 2022.Is it possible to use rtrim to remove all characters out of a search result that come ...
by ASplunkDummy Engager in Splunk Search 01-03-2022
1 3
1
3
dhavamanis
can you please tell us, how to get the last 24 hours event count to schedule the report?
by dhavamanis Builder in Splunk Search 01-03-2022
1 2
1
2
brc55
I have 2 sourcetypes, vpn & winevents, how do you write a single query to get winevents of the top 5 busiest machines...
by brc55 Explorer in Splunk Search 01-03-2022
0 3
0
3
vxroot
Hello guys, Splunk newbie here. Hope someone can assist in my case, so index=*_whatever is expected to be filled with...
by vxroot Loves-to-Learn in Splunk Search 01-03-2022
0 7
0
7
jsmithn
I know similar questions have been asked a number of times but trying to follow the suggestions given I still cannot ...
by jsmithn Path Finder in Splunk Search 01-02-2022
0 9
0
9
DonBaldini
I have a join where there are 2 different SLAs (Active and E2E) that need to be linked to incidents on one row. How c...
by DonBaldini Path Finder in Splunk Search 01-02-2022
0 1
0
1
shrinivaskittur
Hi,I need help in evaluation the csv files under "<Splunk directory>\etc\apps\search\lookups" folder. we have multipl...
by shrinivaskittur Explorer in Splunk Search 01-02-2022
0 4
0
4
splunk_luis12
Hi all, I'm trying to find the specific queries for the SH to create Splunk dashboard of the following info (example)...
by splunk_luis12 Path Finder in Splunk Search 01-02-2022
0 2
0
2
bcanfield83
Hello,I'm attempting to use the regex command to filter out any records on the "user" field that do not match the wri...
by bcanfield83 Engager in Splunk Search 01-02-2022
0 3
0
3
eranhauser
How do I pair events 4778 & 4779 for the same Logon_ID when I have multi 4778 and multi 4779?I would like to pair the...
by eranhauser Path Finder in Splunk Search 12-31-2021
0 1
0
1
sumitp10797
   Provide details about client purchase details          1. Total purchase split by product ID         2. Total Prod...
by sumitp10797 New Member in Splunk Search 12-31-2021
0 2
0
2
incognito
Hello, My Splunk query an API and gets a JSON answer.Here is a sample for 1 Host (the JSON answer is very long ≈ 400 ...
by incognito Explorer in Splunk Search 12-31-2021
0 6
0
6
SplnkUse
HelloI want to feed data directly into Excel but I do not have API access nor I can install custom connectors.Is ther...
by SplnkUse Path Finder in Splunk Search 12-31-2021
0 2
0
2
bazcurtis178
Hi,My search result brings back a GUID in the ID field. The GUID refers to a customer. I would like it to reflect the...
by bazcurtis178 Explorer in Splunk Search 12-31-2021
0 9
0
9
sagar_shubham
Hi Team,  Need your help in creating regex to create a field. "User_Claim":("sub":"qweihaytej"; "login_id":"Abc@domai...
by sagar_shubham Explorer in Splunk Search 12-30-2021
0 4
0
4
Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...