Splunk Search

Splunk Search
Community Activity
srinivas_gowda
Hello all, I am trying to extract the below highlighted fields, but the extractions at time is failing to get the req...
by srinivas_gowda Path Finder in Splunk Search 11-11-2021
0 3
0
3
Azwaliyana
I want to extract the field that are on the left which are status, monitoirng status, monitoring mode and so on. Mult...
by Azwaliyana Path Finder in Splunk Search 11-11-2021
0 3
0
3
rafadvega
Hi,I need to join two searchs. For example:Example 1: | inputlookup join_example1.csv countryproductdaystockSpainappl...
by rafadvega Path Finder in Splunk Search 11-10-2021
0 2
0
2
marceloalejandr
For some reason the "Enabled" field is not return "true or false" when running ldapsearch from Splunk.  All the other...
by marceloalejandr Path Finder in Splunk Search 11-10-2021
0 1
0
1
esalesap
We have Splunk 8.0.3 deployed to a private AWS cloud.We use AWS i3.8xlarge instance types for our indexers, recently ...
by esalesap Path Finder in Splunk Search 11-10-2021
0 1
0
1
andrewenstad
I have a user that has asked how to get access/permissions to the "export" button while doing a search in Splunk.  It...
by andrewenstad Engager in Splunk Search 11-10-2021
0 1
0
1
SMM10
I want to find items in one index based on results from another index's search. I have the following but only get a h...
by SMM10 Explorer in Splunk Search 11-10-2021
0 3
0
3
jeck11
This has been asked a million times. I've been digging through the various postings but haven't figured out what I'm ...
by jeck11 Path Finder in Splunk Search 11-10-2021
0 8
0
8
gillockb
Hello Splunksters,I'm new to Splunk and am constructing my first subsearch.  I've read the documentation on subsearch...
by gillockb Explorer in Splunk Search 11-10-2021
0 4
0
4
Vip_Mark
I am currently using an Input token called OS.I have three values for the token:     MAC      Windows     Linux.In my...
by Vip_Mark Explorer in Splunk Search 11-10-2021
0 1
0
1
rkishoreqa
Hi team,  Please help with the regex to fetch the values from below payload -  serverName, HostNumber. "{\n \"process...
by rkishoreqa Communicator in Splunk Search 11-10-2021
0 1
0
1
zubairaizatron
Hi GuysWanted to know if anyone knows if you can populate a summary index from a data model. the summary index query ...
by zubairaizatron Explorer in Splunk Search 11-10-2021
0 2
0
2
jip31
hiI use a lookup in order to do a correspondance between the field web_error_code which is my sourcetype and which is...
by jip31 Motivator in Splunk Search 11-10-2021
0 2
0
2
rohanmiskin
I have extracted two fields in my non prod splunk account. I want to use the same for the prod splunk account as well...
by rohanmiskin Explorer in Splunk Search 11-10-2021
0 2
0
2
Wilfred
Hi,I just started working with Splunk and would ask for some help.I have 3 sources, A, B and C.Source A contains fiel...
by Wilfred Engager in Splunk Search 11-10-2021
0 2
0
2
rel82wi
Hi thereIm trying to filter my search results based on numerical top values of a field.For example. I have 5k events ...
by rel82wi Engager in Splunk Search 11-10-2021
0 4
0
4
spfingst87
HiI want to exclude the path from search results, i.e.:www.testsite.comwww.testsite.com/path1www.testsite.com/path2ww...
by spfingst87 Loves-to-Learn in Splunk Search 11-10-2021
0 4
0
4
febbi
I want to extract the substring: "xenmobile" from string:  "update task to xenmobile-2021-11-08-19-created completed!...
by febbi Explorer in Splunk Search 11-10-2021
0 2
0
2
typicallywrecke
So I'm trying to do something that may or may not be possible. I want to first create a lookup table that maps IP a...
by typicallywrecke Engager in Splunk Search 11-10-2021
0 4
0
4
rnikam1412
I am trying to look for accounts which are not active anywhere in network.(index=network user=*) OR (index=okta SamAc...
by rnikam1412 Loves-to-Learn Everything in Splunk Search 11-09-2021
0 2
0
2
shashank111v
How to extract values from below log file using rex?Log:{Attribute(name=xyz, values={'1'}), Attribute(name=attempts, ...
by shashank111v Explorer in Splunk Search 11-09-2021
0 3
0
3
pm771
We have a relatively small set of devices that emit daily in the vicinity of a million events each.  Each device has ...
by pm771 Communicator in Splunk Search 11-09-2021
0 6
0
6
dlawler1
Hello! I have a lookup table that looks like the following: hosttimestamphost110:33host24:24 What I would like to do ...
by dlawler1 New Member in Splunk Search 11-09-2021
0 4
0
4
kalibaba2021
Does the Lookup cmd allow for Where clause to filter the output of Lookup? Or do I need to have an extra sub search w...
by kalibaba2021 Path Finder in Splunk Search 11-09-2021
0 2
0
2
indeed_2000
Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist...
by indeed_2000 Motivator in Splunk Search 11-09-2021
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...