Splunk Search

Splunk Search
Community Activity
vagnet
Hi Splunkers, I have prepared a regex extraction using regex101 site, and now trying to extract "Failure Reason" as p...
by vagnet Explorer in Splunk Search 10-29-2021
0 5
0
5
phamxuantung
Let's say I have this query index = x |stats count as Total, sum(AMMOUNT) as TAmmount BY MERCHANT, SUBMERCHANT I wan...
by phamxuantung Communicator in Splunk Search 10-29-2021
0 2
0
2
priyangshupal
I have a field "skill" which takes multiple values:I want to extract the count of each of the values of skill and sto...
by priyangshupal Engager in Splunk Search 10-29-2021
0 4
0
4
noman377
Hi, I want to insert Timerange picker value like $time$ in my query for a Dynamic input. Requesting help with the que...
by noman377 Explorer in Splunk Search 10-29-2021
0 2
0
2
_Tom
Hello *,I am looking for an SPL that reads the first part of a string via regex and replaces all occurrences of a cer...
by _Tom Explorer in Splunk Search 10-29-2021
0 3
0
3
neerajs_81
Hello,  We are using ES and we have a lookup file downloaded which has a mix of standalone ip's and CIDRs/Subnets/.  ...
by neerajs_81 Builder in Splunk Search 10-29-2021
0 5
0
5
anapp
OK, this is oddSearch: index=myindexWorks and returns a field "Name", happily listing all values of Name as expectedH...
by anapp Explorer in Splunk Search 10-29-2021
0 2
0
2
André
Hi,I want to extract the following term from this message: (MaRSEPbac, [MaRSEPbac_Old2], [MaRSEPbac])that means the s...
by André Engager in Splunk Search 10-29-2021
0 3
0
3
cheriemilk
hi team, as titled, how to rename 'row1' to 'number' after transpose. I tried rename and replace, but doesn't work. 
by cheriemilk Path Finder in Splunk Search 10-28-2021
0 2
0
2
wkbevill
Oct 28 20:08:57 XXX.XXX.com Microsoft-Windows-Security-Auditing[4]: EventID: 4663 An attempt was made to access an ob...
by wkbevill Engager in Splunk Search 10-28-2021
0 2
0
2
zachsisinst
index=myindex | eval createdepoch = strptime(created, "%Y-%m-%d")| eval _time = createdepoch| search earliest=-90d@d ...
by zachsisinst Explorer in Splunk Search 10-28-2021
0 1
0
1
SplunkNs231
I have the following data. That I am trying to convert to a time series by Type with the last Status brought forward....
by SplunkNs231 Engager in Splunk Search 10-28-2021
0 1
0
1
apalmier
Hi,I'm continuously receiving the error Regex: syntax error in subpattern name (missing terminator) when attempting t...
by apalmier New Member in Splunk Search 10-28-2021
0 2
0
2
ycho1
hello,Can anyone tell me how to exclude the subsearch result from main search?I want to exclude the result that faile...
by ycho1 Explorer in Splunk Search 10-28-2021
0 4
0
4
vgodavarty0116
Hi, I would like to determine a field from different areas of a log. eg see below for my expectations. Note: You can ...
by vgodavarty0116 Engager in Splunk Search 10-28-2021
0 1
0
1
rajkskumar
I have data in the following structure received for every event. Some events have just one or two sub calls and some ...
by rajkskumar Explorer in Splunk Search 10-28-2021
0 0
0
0
zacksoft_wf
My lookUp is a KV Store lookup.  It has three column  'is_active' , 'user', 'robot'.I have a SPL query that gives me ...
by zacksoft_wf Contributor in Splunk Search 10-28-2021
0 3
0
3
cyber_Maddy
| datamodel "Change_Analysis" "Account_Management" search | where 'All_Changes.tag'="delete" AND 'All_Changes.user'!=...
by cyber_Maddy Engager in Splunk Search 10-27-2021
0 1
0
1
jacsilva
Hello,I'm a bit new to Splunk, so I'm still learning.I have created two fields, an opscounter, and a deopcounter. The...
by jacsilva Observer in Splunk Search 10-27-2021
0 4
0
4
cgbsplunk
I have two fields below that show up in our log files.  I used Splunk tool to create the Regex to extract the fields ...
by cgbsplunk Explorer in Splunk Search 10-27-2021
0 5
0
5
khenson
Hi all.  I'm trying to create a table from AWS WAF logs.  There is a section of the log that is called ruleGroupList{...
by khenson Engager in Splunk Search 10-27-2021
0 0
0
0
ys2119
My current search returns a series of events like: {'field1' : {'field2' : [obj1, obj2, obj3]}}{'field1' : {'field2' ...
by ys2119 Loves-to-Learn in Splunk Search 10-27-2021
0 3
0
3
ssoftility
Hi,We have a large amount of data in /opt/app/axtract_fe1/var/log/apache2/main_collector_access-*.log file, and we do...
by ssoftility Loves-to-Learn in Splunk Search 10-27-2021
0 1
0
1
gitingua
the "where" command checks only one condition doesn't work like thatmy search:. . . . | where NOT (id_old = id OR use...
by gitingua Communicator in Splunk Search 10-27-2021
0 9
0
9
jackjack
This question is based on a comment from @woodcock on this post: https://community.splunk.com/t5/Splunk-Search/Why-ar...
by jackjack Path Finder in Splunk Search 10-27-2021
0 1
0
1
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors