Splunk Search

Splunk Search
Community Activity
randy_moore
Hi - I have some data that looks like this, which ingests into splunk with no issues at all   11/24/2021 08:47:21.321...
by randy_moore Path Finder in Splunk Search 11-24-2021
1 3
1
3
crazymonkey
Sample JSON  { message: { application: hello deploy: { X: { A: { QPY: 14...
by crazymonkey Observer in Splunk Search 11-24-2021
0 6
0
6
ycho1
hello,I would like to ask a question on how to assign the value to another variable and set an alert.I have a this da...
by ycho1 Explorer in Splunk Search 11-24-2021
0 4
0
4
Glasses
Hi I am trying to speed up a query.When I run >>> index=foo | stats values(host) as F_host It take less than a minute...
by Glasses Builder in Splunk Search 11-24-2021
0 3
0
3
giulio
Hi all, I have two indexes with the following fields:index=sofwaresw                        version       authorsoftw...
by giulio Engager in Splunk Search 11-24-2021
0 3
0
3
cfloquet
Hello, thank you for taking the time to consider my question. I currently have a working SPL search that retrieves IP...
by cfloquet Path Finder in Splunk Search 11-24-2021
0 0
0
0
djreschke
I am trying to correlate 2 different logs one is in EST and the is in UTC. The UTC logs, I have tried to specific the...
by djreschke Communicator in Splunk Search 11-24-2021
0 10
0
10
SplnkUse
Hello, Can you tell me please why the below does not work?| rest splunk_server=local servicesNS/-/-/data/ui/views/| w...
by SplnkUse Path Finder in Splunk Search 11-24-2021
0 1
0
1
pradeepkumarg
I do not want to run through _audit logs to find when the initial schedule kicked in. Rest call for the list of save...
by pradeepkumarg Influencer in Splunk Search 11-24-2021
0 2
0
2
luuken
Hi,The following is my search:index=pace ERROR OR FATAL OUI=* Number=*| stats count by OUI Number| sort -count After ...
by luuken New Member in Splunk Search 11-24-2021
0 2
0
2
Rob
How can I avoid having lines that are commented within my files from being indexed by Splunk? Lets say I have a log ...
by Rob Splunk Employee Splunk Employee in Splunk Search 11-24-2021
1 6
1
6
deruvara
Hi I am trying to filter data using week data using 2 dropdowns. Please find info below snippet. the below code throw...
by deruvara Explorer in Splunk Search 11-23-2021
0 2
0
2
Stefanie
Hey all,I have the Splunk add on for unix/linux deployed to about ~70 servers. All was working fine (and has been for...
by Stefanie Builder in Splunk Search 11-23-2021
0 1
0
1
indeed_2000
Hi How can I tune this spl command?this spl execute daily, and return something like this:servername send            ...
by indeed_2000 Motivator in Splunk Search 11-23-2021
0 2
0
2
ekucevic
I have a log sample: | LRU Config Message from RMQ: {"endpoint":"lru/ config", "data":{"timestamp":1637322539.953,"ve...
by ekucevic Loves-to-Learn Everything in Splunk Search 11-23-2021
0 6
0
6
butsch100
All, I have 2 separate queries working from AWS Description data that we collect on a regular basis.The ask from one ...
by butsch100 Engager in Splunk Search 11-23-2021
0 1
0
1
CMartinRuiz
Hello Community.I am trying to solve a problem and I can't see a solution. Hope you can help me!I am working with a m...
by CMartinRuiz Loves-to-Learn Everything in Splunk Search 11-23-2021
0 0
0
0
zacksoft_wf
I have a lookup | inputlookup citizen_data , it has fields ID, Name, State.I have another sourcetype | index=bayseian...
by zacksoft_wf Contributor in Splunk Search 11-23-2021
0 3
0
3
dtccsundar
I have a field( version) which is available in different position in different events of same sourcetype,Since the pr...
by dtccsundar Path Finder in Splunk Search 11-23-2021
0 4
0
4
brennson90
Hi everyone,i got two URLs which i want to represent in one regex group. The dest Port (443) will be in a seperate gr...
by brennson90 Path Finder in Splunk Search 11-23-2021
0 5
0
5
indeed_2000
HiI need to show id1,id2 on timecharthave table with these columns:index="myindex" | table duration servername id1 id...
by indeed_2000 Motivator in Splunk Search 11-22-2021
0 1
0
1
kajolsharma
Hi, I have a query below with a join condition .The issue is if I am hardcoding name value I am getting the result bu...
by kajolsharma Path Finder in Splunk Search 11-22-2021
0 6
0
6
MeMilo09
Hello All, How can I remove words and characters from a multivalued field without using REX?I have a filed named OSOS...
by MeMilo09 Path Finder in Splunk Search 11-22-2021
0 3
0
3
My
Hi there,I am new to splunk. I and was wondering how to find the difference in time from the last time a forwarder se...
by My Engager in Splunk Search 11-22-2021
0 3
0
3
sanjum01
Hi Folks,I am facing the issue where I am not able to see red bar in the below panel. The count is for each hour and ...
by sanjum01 Explorer in Splunk Search 11-22-2021
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...