Splunk Search

Splunk Search
Community Activity
Steve_A200
Hi,Currently, my query produces the correct results but they are all aggregated into single cells, and I would like t...
by Steve_A200 Path Finder in Splunk Search 12-21-2021
0 2
0
2
rayar
I want to search for "index=*" ....what is the best way to run it  ?I tried to run "index=\*" but it's not working 
by rayar Contributor in Splunk Search 12-21-2021
0 5
0
5
wolfgangs
Hi,I have events which contain 3 Fields: "StartDate", "Value_per_month" and "Nr_of_Month". They basically disclose so...
by wolfgangs Engager in Splunk Search 12-20-2021
0 2
0
2
martin61
I'm looking to convert the results for these fields  in PST time zone, so that I can fetch the events based on these ...
by martin61 Engager in Splunk Search 12-20-2021
0 1
0
1
chuck_life09
I have an Index B  which has job_name and job_status details and another index A which has ticket number and job_name...
by chuck_life09 Path Finder in Splunk Search 12-20-2021
0 3
0
3
pavanbmishra
We have below CEF logs coming in from the device where few field doesn't have any value like cs2 below CEF:0|vendor|p...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
pavanbmishra
We need to capture field value for the below CEF log pattern CEF:0|vendor|product|1.1.0.15361|6099|DirectoryAssetSync...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
splunkxorsplunk
Hi,Need help to get following results from the search.  all helps will be appreciated. On the image below, same color...
by splunkxorsplunk Explorer in Splunk Search 12-20-2021
0 4
0
4
nanoo1
Hi,I need a help with a query to display the count based on a particular message. For example, "Failed project on ABC...
by nanoo1 Loves-to-Learn Everything in Splunk Search 12-20-2021
0 5
0
5
mah
Hi,I have a table like this : part_of_urlcount/test11/test22/test33 I want to drilldown with a link which open a new ...
by mah Builder in Splunk Search 12-20-2021
0 6
0
6
mah
Hi,I have a table like this : testcounttest AA1test AB2test C3 I want to merge "test AA" and "test AB" which will giv...
by mah Builder in Splunk Search 12-20-2021
0 1
0
1
priya1926
Hi, I am trying this cmd  index="wineventlog" host IN (*) EventCode=6006 OR EventCode="6005" Type=Information| transa...
by priya1926 Path Finder in Splunk Search 12-20-2021
0 2
0
2
g_paternicola
HelloI'm trying to injest event from this Microsoft event viewer:[WinEventLog://Microsoft-Windows-TerminalServices-Cl...
by g_paternicola Path Finder in Splunk Search 12-20-2021
0 7
0
7
jackin
Hi,Search 1: It is used to findout the server healthindex=win sourcetype="xmlwineventlog" host=Prod_UI_*| eval Status...
by jackin Path Finder in Splunk Search 12-19-2021
0 1
0
1
bosseres
Hello,Is it possible to user OR with regex?For example i have search | regex something="", and I need | regex somethi...
by bosseres Contributor in Splunk Search 12-19-2021
0 2
0
2
nanoo1
Hi,I need an help with splunk search query where in an incident need to be generated for a log backup failure after 3...
by nanoo1 Loves-to-Learn Everything in Splunk Search 12-19-2021
0 13
0
13
einars
Playing around to find a way to gather IP-Addresses from one type of search, to gather other type of information abou...
by einars Engager in Splunk Search 12-19-2021
0 2
0
2
mah
Hi,I want to find specific strings in all event in order to classify them into two values, like "if there is "A" or "...
by mah Builder in Splunk Search 12-19-2021
0 1
0
1
limalbert
 I could retrieve the list of the transactions as a single event below. Transactions start with "Dashboard Load:" and...
by limalbert Path Finder in Splunk Search 12-18-2021
0 3
0
3
martin61
I would like to create an alert when new QID from qualys is published.  For that I'm using FIRST_FOUND_DATETIME field...
by martin61 Engager in Splunk Search 12-17-2021
0 1
0
1
Mmilaham
Hello,I am trying to write a query that will display failed logins (Account_Name, Host, Count).First Queryindex=winev...
by Mmilaham Loves-to-Learn in Splunk Search 12-17-2021
0 3
0
3
alex_collins_in
I'm trying to plot the following as a scatter chart:The y-axis should be the namespace. Namespace is a small set of s...
by alex_collins_in New Member in Splunk Search 12-17-2021
0 1
0
1
rajg369
e.ghow to get sum of below in single querysum(val_2) by applicationsum(val_2) by val_1Query Result(single query)colum...
by rajg369 Explorer in Splunk Search 12-17-2021
0 3
0
3
jdepp
I have tried multiple ways to do this including join, append but in each case all I get is one column result being di...
by jdepp Path Finder in Splunk Search 12-17-2021
2 6
2
6
yuanliu
How to perform calculations on a given day of week?  Specifically, I want to compare a given time value, say given_da...
by SplunkTrust SplunkTrust in Splunk Search 12-17-2021
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...