Splunk Search

Splunk Search
Community Activity
GRC
Hi Team,I am pulling hair to figure out a query to extract data into a table with following information. stopping sys...
by GRC Path Finder in Splunk Search 10-22-2021
0 6
0
6
neerajs_81
Hello All,I have a query that searches the Windows Security Logs and shows results in the following format using a st...
by neerajs_81 Builder in Splunk Search 10-22-2021
0 1
0
1
anooshac
Hi all, I have a xml file as below.<?xml version="1.0" encoding="UTF-8"?><suite name="abc" timestamp="20.08.2021 15:4...
by anooshac Communicator in Splunk Search 10-21-2021
0 0
0
0
PickleRick
Hello thereI'm trying to prepare a dashboard that will query indexes for latest events during a given period (let's s...
by SplunkTrust SplunkTrust in Splunk Search 10-21-2021
0 4
0
4
jbuddy24
Hi All,I'm trying to get data tied together into one matrix from Jira (API fed) that utilizes two source types (shown...
by jbuddy24 Explorer in Splunk Search 10-21-2021
0 8
0
8
jackjack
Hi all,I am trying to setup some sort of dashboard to view a list of sudo commands by server. I started with the IT E...
by jackjack Path Finder in Splunk Search 10-21-2021
0 8
0
8
MikeB
I have a field named failcode with numerous fail code names structured like this:datefailcodecount2021-10-01g-ab12320...
by MikeB Path Finder in Splunk Search 10-21-2021
0 7
0
7
weidertc
I have an input text and input dropdown that both need to allow blank value.  They cannot be null since the token mus...
by weidertc Contributor in Splunk Search 10-21-2021
0 2
0
2
sleepingKoala
Hi all, new user here. I was getting started on the tutorial and using the start searching page that came up after ad...
by sleepingKoala Engager in Splunk Search 10-21-2021
0 3
0
3
willadams
I have a search similar to the following (Index=myindex) or (index=otherindex)| eval user=coalesce(accountname, id)| ...
by willadams Contributor in Splunk Search 10-21-2021
0 1
0
1
tmurray3
I am trying to figure out how to calculate the highest number of transaction per second for a given day. I would lik...
by tmurray3 Path Finder in Splunk Search 10-21-2021
0 4
0
4
gitingua
Now working lookup On a local server on my computer, I got the result But when I did exactly the same actions on the ...
by gitingua Communicator in Splunk Search 10-21-2021
0 2
0
2
reedamjain123
I want to display the heading of my panel which include time from time peaker field 
by reedamjain123 New Member in Splunk Search 10-21-2021
0 1
0
1
venky1544
i want to show the count from host as zero if the process is not found however not able to find 0 count the host disa...
by venky1544 Builder in Splunk Search 10-21-2021
0 1
0
1
Software-Simian
Hello,i am trying to create a dependency map without the external creation of tokens that are being fed to the append...
by Software-Simian Path Finder in Splunk Search 10-21-2021
0 2
0
2
dtccsundar
Hi,My requirement is to take each week monday data alone for a month in trending chart .This need to be showed for st...
by dtccsundar Path Finder in Splunk Search 10-21-2021
0 8
0
8
ezpc98
Hi,Our systems have multiple order records as XML transactions and each order can have multiple events on different d...
by ezpc98 New Member in Splunk Search 10-21-2021
0 1
0
1
kuma
Hello, I would like to change table cell background color of  top 3 value of each column's search result .For example...
by kuma New Member in Splunk Search 10-21-2021
0 1
0
1
ecanmaster
I want to group certain values within a certain time frame, lets say 10 minutes, the values are just fail or success,...
by ecanmaster Explorer in Splunk Search 10-21-2021
0 16
0
16
tumapath
I am trying to filter out null values from the result of stats. Query looks like below.  index=someindex* some ((s...
by tumapath New Member in Splunk Search 10-20-2021
0 1
0
1
gitingua
Need help writing a requestfile1.csv usernamesrc_ipJohn192.168.16.35Smith172.167.3.43Aram132.56.23.3 file2.csvIP addr...
by gitingua Communicator in Splunk Search 10-20-2021
0 3
0
3
vadlamudi
HI There, Can i please know how make the REQUEST_ID clickable from the below query. i want pass the REQUEST_ID from q...
by vadlamudi Explorer in Splunk Search 10-20-2021
0 1
0
1
kishan2356
I have a field called alphabet that stores multiple values. I want to create a search that only returns events that h...
by kishan2356 Explorer in Splunk Search 10-20-2021
0 2
0
2
indeed_2000
Hi how can i extract table like this: (“myserver” is a field that already extracted)source        destination   durat...
by indeed_2000 Motivator in Splunk Search 10-20-2021
0 5
0
5
SplunkDash
Hello,I have some SQL trc binary files need to be ingested into SPLUNK from SQL server where UF has already been inst...
by SplunkDash Motivator in Splunk Search 10-20-2021
0 0
0
0
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...