Splunk Search

Splunk Search
Community Activity
GustavMahler
Hi! I have a panel in dashboard that uses timechart. I want to make it zoom at highest count or count>0 automatically...
by GustavMahler Explorer in Splunk Search 10-29-2021
0 0
0
0
neerajs_81
Folks,  Need some assistance to understand why Splunk is reporting different IP's for the same hostname ( Active Dir ...
by neerajs_81 Builder in Splunk Search 10-29-2021
0 3
0
3
vagnet
Hi Splunkers, I have prepared a regex extraction using regex101 site, and now trying to extract "Failure Reason" as p...
by vagnet Explorer in Splunk Search 10-29-2021
0 5
0
5
phamxuantung
Let's say I have this query index = x |stats count as Total, sum(AMMOUNT) as TAmmount BY MERCHANT, SUBMERCHANT I wan...
by phamxuantung Communicator in Splunk Search 10-29-2021
0 2
0
2
priyangshupal
I have a field "skill" which takes multiple values:I want to extract the count of each of the values of skill and sto...
by priyangshupal Engager in Splunk Search 10-29-2021
0 4
0
4
noman377
Hi, I want to insert Timerange picker value like $time$ in my query for a Dynamic input. Requesting help with the que...
by noman377 Explorer in Splunk Search 10-29-2021
0 2
0
2
_Tom
Hello *,I am looking for an SPL that reads the first part of a string via regex and replaces all occurrences of a cer...
by _Tom Explorer in Splunk Search 10-29-2021
0 3
0
3
neerajs_81
Hello,  We are using ES and we have a lookup file downloaded which has a mix of standalone ip's and CIDRs/Subnets/.  ...
by neerajs_81 Builder in Splunk Search 10-29-2021
0 5
0
5
anapp
OK, this is oddSearch: index=myindexWorks and returns a field "Name", happily listing all values of Name as expectedH...
by anapp Explorer in Splunk Search 10-29-2021
0 2
0
2
André
Hi,I want to extract the following term from this message: (MaRSEPbac, [MaRSEPbac_Old2], [MaRSEPbac])that means the s...
by André Engager in Splunk Search 10-29-2021
0 3
0
3
cheriemilk
hi team, as titled, how to rename 'row1' to 'number' after transpose. I tried rename and replace, but doesn't work. 
by cheriemilk Path Finder in Splunk Search 10-28-2021
0 2
0
2
wkbevill
Oct 28 20:08:57 XXX.XXX.com Microsoft-Windows-Security-Auditing[4]: EventID: 4663 An attempt was made to access an ob...
by wkbevill Engager in Splunk Search 10-28-2021
0 2
0
2
zachsisinst
index=myindex | eval createdepoch = strptime(created, "%Y-%m-%d")| eval _time = createdepoch| search earliest=-90d@d ...
by zachsisinst Explorer in Splunk Search 10-28-2021
0 1
0
1
SplunkNs231
I have the following data. That I am trying to convert to a time series by Type with the last Status brought forward....
by SplunkNs231 Engager in Splunk Search 10-28-2021
0 1
0
1
apalmier
Hi,I'm continuously receiving the error Regex: syntax error in subpattern name (missing terminator) when attempting t...
by apalmier New Member in Splunk Search 10-28-2021
0 2
0
2
ycho1
hello,Can anyone tell me how to exclude the subsearch result from main search?I want to exclude the result that faile...
by ycho1 Explorer in Splunk Search 10-28-2021
0 4
0
4
vgodavarty0116
Hi, I would like to determine a field from different areas of a log. eg see below for my expectations. Note: You can ...
by vgodavarty0116 Engager in Splunk Search 10-28-2021
0 1
0
1
rajkskumar
I have data in the following structure received for every event. Some events have just one or two sub calls and some ...
by rajkskumar Explorer in Splunk Search 10-28-2021
0 0
0
0
zacksoft_wf
My lookUp is a KV Store lookup.  It has three column  'is_active' , 'user', 'robot'.I have a SPL query that gives me ...
by zacksoft_wf Contributor in Splunk Search 10-28-2021
0 3
0
3
cyber_Maddy
| datamodel "Change_Analysis" "Account_Management" search | where 'All_Changes.tag'="delete" AND 'All_Changes.user'!=...
by cyber_Maddy Engager in Splunk Search 10-27-2021
0 1
0
1
jacsilva
Hello,I'm a bit new to Splunk, so I'm still learning.I have created two fields, an opscounter, and a deopcounter. The...
by jacsilva Observer in Splunk Search 10-27-2021
0 4
0
4
cgbsplunk
I have two fields below that show up in our log files.  I used Splunk tool to create the Regex to extract the fields ...
by cgbsplunk Explorer in Splunk Search 10-27-2021
0 5
0
5
khenson
Hi all.  I'm trying to create a table from AWS WAF logs.  There is a section of the log that is called ruleGroupList{...
by khenson Engager in Splunk Search 10-27-2021
0 0
0
0
ys2119
My current search returns a series of events like: {'field1' : {'field2' : [obj1, obj2, obj3]}}{'field1' : {'field2' ...
by ys2119 Loves-to-Learn in Splunk Search 10-27-2021
0 3
0
3
ssoftility
Hi,We have a large amount of data in /opt/app/axtract_fe1/var/log/apache2/main_collector_access-*.log file, and we do...
by ssoftility Loves-to-Learn in Splunk Search 10-27-2021
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...