Splunk Search

Splunk Search
Community Activity
boopaljothi
Splunk Web doesn't show the events at times. If I restart and log in, it will show the events, but after some time, e...
by boopaljothi Explorer in Splunk Search 11-17-2021
1 24
1
24
kirti_gupta12
I have a Splunk query: index=my_index cf_app_name=$app_name$ msg!="*Hikari*" $log_type$ | sort -_time | table msg It ...
by kirti_gupta12 Path Finder in Splunk Search 11-17-2021
0 1
0
1
manjunath_0208
|eval SNOW_Description=case(EMGC_ADMINSERVER_Status!="k1","Java Process EMGC_ADMINSERVER data not available in splunk...
by manjunath_0208 Loves-to-Learn Everything in Splunk Search 11-17-2021
0 3
0
3
dalmaua
Hi,I am trying to convert the result of applying the CorrelationMatrix algorithm which is given in a confusion matrix...
by dalmaua Explorer in Splunk Search 11-17-2021
0 2
0
2
sbattista
what's the best way to set a sedcmd in props to remove spaces and add a " _ " in just the a cvs header line? for exam...
by sbattista Explorer in Splunk Search 11-17-2021
0 2
0
2
leftrightleft
Hey ,I'm trying to get the time difference between when an event was received and a string representation of the tim...
by leftrightleft Explorer in Splunk Search 11-17-2021
0 2
0
2
elad
I have this query: my search | rex field=line ".*customerId\":(?<customer_id>[0-9]+)" | dedup customer_id | table ...
by elad Engager in Splunk Search 11-17-2021
0 8
0
8
splunkbn00bie
Here is my query - I'm doing two searches that are independent of each other. In both searches, I'm restricting the t...
by splunkbn00bie Engager in Splunk Search 11-17-2021
0 2
0
2
noman377
Hello, I am trying to timechart two event types ONLY: heartbeat and start. However, every event in our Splunk is also...
by noman377 Explorer in Splunk Search 11-17-2021
0 5
0
5
thierryazandegb
Hello,We have a problem with the monitoring of a simple file with five fields.The problem is on the date field that S...
by thierryazandegb Observer in Splunk Search 11-17-2021
0 2
0
2
srinivas_gowda
Hello all, I have been facing problem with the below extraction where the extraction is working on a few events and n...
by srinivas_gowda Path Finder in Splunk Search 11-17-2021
0 1
0
1
lamnguyentt1
HiI write the Splunk query below to monitor server logindex="abc" sourcetype="abc" login "response.status"=200 source...
by lamnguyentt1 Explorer in Splunk Search 11-17-2021
0 1
0
1
jabez2092
I need help for extracting the below fields. can someone help..reference = 205, \"sample\":12345678, \"logic\":\"AB00...
by jabez2092 Loves-to-Learn in Splunk Search 11-17-2021
0 3
0
3
srinivas_gowda
Hello all, I have been getting the data and time format in the below way. How do I convert it to the given readable f...
by srinivas_gowda Path Finder in Splunk Search 11-17-2021
0 1
0
1
grundsch
Hi, It looks like a table view of an embedded report is limited to the first 20 results. I couldn't find any place w...
by grundsch Communicator in Splunk Search 11-16-2021
7 8
7
8
MeMilo09
Howdy,Been researching on how to give time for the next sequential event to occur, but have not found a way. Lets say...
by MeMilo09 Path Finder in Splunk Search 11-16-2021
0 2
0
2
kirti_gupta12
I have a Splunk query that parses the msg field, fetches the fields from the result and displays them in a table. PFA...
by kirti_gupta12 Path Finder in Splunk Search 11-16-2021
0 1
0
1
kirti_gupta12
I have Splunk results in following format: 2021-11-13 01:02:50.127 ERROR 23 --- [ taskExecutor-2] c.c.p.r.service.Red...
by kirti_gupta12 Path Finder in Splunk Search 11-16-2021
0 12
0
12
oliverpeloton23
Hi Splunk Community,It's been a while since I've last used Splunk and regex, and now I'm struggling with both Fields...
by oliverpeloton23 Engager in Splunk Search 11-16-2021
0 2
0
2
PickleRick
Hello.I've noticed that in many solutions when there is a need for a value from previous row, streamstats with window...
by SplunkTrust SplunkTrust in Splunk Search 11-16-2021
0 2
0
2
keezy713
I am trying to create a Timechart that will list out the TotalHours of that day and then subtract the previous days T...
by keezy713 Loves-to-Learn in Splunk Search 11-16-2021
0 5
0
5
dtccsundar
Hi,I have 2 sourcetypes with same index like ( index=A sourcetype= compare and index=A sourcetype= Fire)i am doing ou...
by dtccsundar Path Finder in Splunk Search 11-16-2021
0 2
0
2
miberecz
Hello Everyone, I'm trying to extract usernames from the logs of a proftpd.An event looks like this:2021-11-16 16:17:...
by miberecz Loves-to-Learn in Splunk Search 11-16-2021
0 4
0
4
SIEMStudent
Hi all,I have a doubt regarding the datamodel use.In Splunk Foundamentals 2 course, I got what Data Models is and how...
by SIEMStudent Path Finder in Splunk Search 11-16-2021
0 1
0
1
manpreetsingh29
Hi All,I have query which return all the events for two Hybris pods. When I am using stats it shows the number of eve...
by manpreetsingh29 Loves-to-Learn Lots in Splunk Search 11-16-2021
0 3
0
3
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors