Splunk Search

Splunk Search
Community Activity
priyangshupal
I have a field "skill" which takes multiple values:I want to extract the count of each of the values of skill and sto...
by priyangshupal Engager in Splunk Search 10-29-2021
0 4
0
4
noman377
Hi, I want to insert Timerange picker value like $time$ in my query for a Dynamic input. Requesting help with the que...
by noman377 Explorer in Splunk Search 10-29-2021
0 2
0
2
_Tom
Hello *,I am looking for an SPL that reads the first part of a string via regex and replaces all occurrences of a cer...
by _Tom Explorer in Splunk Search 10-29-2021
0 3
0
3
neerajs_81
Hello,  We are using ES and we have a lookup file downloaded which has a mix of standalone ip's and CIDRs/Subnets/.  ...
by neerajs_81 Builder in Splunk Search 10-29-2021
0 5
0
5
anapp
OK, this is oddSearch: index=myindexWorks and returns a field "Name", happily listing all values of Name as expectedH...
by anapp Explorer in Splunk Search 10-29-2021
0 2
0
2
André
Hi,I want to extract the following term from this message: (MaRSEPbac, [MaRSEPbac_Old2], [MaRSEPbac])that means the s...
by André Engager in Splunk Search 10-29-2021
0 3
0
3
cheriemilk
hi team, as titled, how to rename 'row1' to 'number' after transpose. I tried rename and replace, but doesn't work. 
by cheriemilk Path Finder in Splunk Search 10-28-2021
0 2
0
2
wkbevill
Oct 28 20:08:57 XXX.XXX.com Microsoft-Windows-Security-Auditing[4]: EventID: 4663 An attempt was made to access an ob...
by wkbevill Engager in Splunk Search 10-28-2021
0 2
0
2
zachsisinst
index=myindex | eval createdepoch = strptime(created, "%Y-%m-%d")| eval _time = createdepoch| search earliest=-90d@d ...
by zachsisinst Explorer in Splunk Search 10-28-2021
0 1
0
1
SplunkNs231
I have the following data. That I am trying to convert to a time series by Type with the last Status brought forward....
by SplunkNs231 Engager in Splunk Search 10-28-2021
0 1
0
1
apalmier
Hi,I'm continuously receiving the error Regex: syntax error in subpattern name (missing terminator) when attempting t...
by apalmier New Member in Splunk Search 10-28-2021
0 2
0
2
ycho1
hello,Can anyone tell me how to exclude the subsearch result from main search?I want to exclude the result that faile...
by ycho1 Explorer in Splunk Search 10-28-2021
0 4
0
4
vgodavarty0116
Hi, I would like to determine a field from different areas of a log. eg see below for my expectations. Note: You can ...
by vgodavarty0116 Engager in Splunk Search 10-28-2021
0 1
0
1
rajkskumar
I have data in the following structure received for every event. Some events have just one or two sub calls and some ...
by rajkskumar Explorer in Splunk Search 10-28-2021
0 0
0
0
zacksoft_wf
My lookUp is a KV Store lookup.  It has three column  'is_active' , 'user', 'robot'.I have a SPL query that gives me ...
by zacksoft_wf Contributor in Splunk Search 10-28-2021
0 3
0
3
cyber_Maddy
| datamodel "Change_Analysis" "Account_Management" search | where 'All_Changes.tag'="delete" AND 'All_Changes.user'!=...
by cyber_Maddy Engager in Splunk Search 10-27-2021
0 1
0
1
jacsilva
Hello,I'm a bit new to Splunk, so I'm still learning.I have created two fields, an opscounter, and a deopcounter. The...
by jacsilva Observer in Splunk Search 10-27-2021
0 4
0
4
cgbsplunk
I have two fields below that show up in our log files.  I used Splunk tool to create the Regex to extract the fields ...
by cgbsplunk Explorer in Splunk Search 10-27-2021
0 5
0
5
khenson
Hi all.  I'm trying to create a table from AWS WAF logs.  There is a section of the log that is called ruleGroupList{...
by khenson Engager in Splunk Search 10-27-2021
0 0
0
0
ys2119
My current search returns a series of events like: {'field1' : {'field2' : [obj1, obj2, obj3]}}{'field1' : {'field2' ...
by ys2119 Loves-to-Learn in Splunk Search 10-27-2021
0 3
0
3
ssoftility
Hi,We have a large amount of data in /opt/app/axtract_fe1/var/log/apache2/main_collector_access-*.log file, and we do...
by ssoftility Loves-to-Learn in Splunk Search 10-27-2021
0 1
0
1
gitingua
the "where" command checks only one condition doesn't work like thatmy search:. . . . | where NOT (id_old = id OR use...
by gitingua Communicator in Splunk Search 10-27-2021
0 9
0
9
jackjack
This question is based on a comment from @woodcock on this post: https://community.splunk.com/t5/Splunk-Search/Why-ar...
by jackjack Path Finder in Splunk Search 10-27-2021
0 1
0
1
GustavMahler
by GustavMahler Explorer in Splunk Search 10-27-2021
0 1
0
1
Prachi_Chatur
Is there any way we can add some filter in subsearch savedsearch so that we wont skip any data/records as its limitin...
by Prachi_Chatur Observer in Splunk Search 10-27-2021
0 1
0
1
Get Updates on the Splunk Community!

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...