Splunk Search

Splunk Search
Community Activity
ky129q
Looking for the most efficient way to find 2 way traffic in flow data for a particular set of IP/port/protocol combin...
by ky129q Engager in Splunk Search 09-28-2021
0 0
0
0
Manasi25
hello, I have alert transaction at "ACK" and at "Resolved", i have created table for each value, but unable to edit t...
by Manasi25 Explorer in Splunk Search 09-28-2021
0 15
0
15
kxmorrr
Hi,I am trying to filter out fields from a table based on its content, example:LP. NAME SURNAME STREET CITY1. Bob Smi...
by kxmorrr Engager in Splunk Search 09-28-2021
0 3
0
3
username13
Hey guys. I have multiple events combined to transactions. I'd like to view the duration of each transaction on a tim...
by username13 Explorer in Splunk Search 09-28-2021
0 6
0
6
phamxuantung
So in detail, I have a dashboard that read log files to monitor the list of host's status which is UP or DOWN. But wh...
by phamxuantung Communicator in Splunk Search 09-28-2021
0 1
0
1
corehan
Hello dears,I want to list my search if  "B" total count higher than >3 than list by "A"A and B fields could have var...
by corehan Explorer in Splunk Search 09-28-2021
0 7
0
7
cauhe
Hi Experts,I'm having some difficulties to extract the correct information from a file that was add to splunk.I tried...
by cauhe Explorer in Splunk Search 09-28-2021
0 4
0
4
rhallinan
I have the following search. index=main_index sourcetype="hec:google" operationName=createMobileAuthenticationOutcome...
by rhallinan Engager in Splunk Search 09-27-2021
0 2
0
2
sahana
I have requirement to split the single cell into two columns, in which i need to add different search result data.I n...
by sahana Engager in Splunk Search 09-27-2021
0 1
0
1
vl951f
Our ITSI is showing some "Detected Anomaly" for the kpi "Index Usage".Where and how can I find the notable events for...
by vl951f Path Finder in Splunk Search 09-27-2021
0 0
0
0
splunkuser2127
There are no data on Mondays so my timecharts always dip to 0. {search string} | eval date_wday=lower(strftime(_time,...
by splunkuser2127 Loves-to-Learn in Splunk Search 09-27-2021
0 12
0
12
N-W
Hello!I have been trying to make a base search on a dashboard with a time and environment input as a drop-down.It onl...
by N-W Explorer in Splunk Search 09-27-2021
0 3
0
3
Jochen_Widmaier
Hi, I want to create a dashboard, where a user has a drop down input to select a named time frame ($value$). The star...
by Jochen_Widmaier Engager in Splunk Search 09-26-2021
0 6
0
6
zakura
Hi , I have 2 queries :index="bar_*" sourcetype =foo crm="ser"| dedup uid| stats count as TotalCountand index="bar_*"...
by zakura Explorer in Splunk Search 09-26-2021
0 3
0
3
P_Viz
Hey, I am working towards Slunk Fundamentals 1 and doing the eLearning assignments. Currently on Module5. I have impo...
by P_Viz Engager in Splunk Search 09-26-2021
1 3
1
3
ashvini_mishra
I have an api which has a number of endpoint, e.g., /health, /version, /specification and so on...I have a query whic...
by ashvini_mishra Explorer in Splunk Search 09-26-2021
0 3
0
3
ephemeric
I have a macro that adds a backslash to an existing backslash: [backslash(1)] args = arg definition = replace("$arg$"...
by ephemeric Contributor in Splunk Search 09-25-2021
0 0
0
0
ronsri
index=test sourcetype=test_access tag=prod server_name!="www.test.com" earliest=-4h latest=now | timechart eval(avg(r...
by ronsri Observer in Splunk Search 09-25-2021
0 1
0
1
ilya
Hi, Team!I have a rule:index = example source = "Rule" | fields user, src_time, src_app, src, src_lat, src_long, src_...
by ilya New Member in Splunk Search 09-25-2021
0 1
0
1
yoan
Hello,I'm trying to make a report to count the number of interfaces available and used.I found the query that matches...
by yoan Explorer in Splunk Search 09-25-2021
0 2
0
2
middlemiddle
I have an alert that joins RAW events with a lookup containing thresholds (and yes, it has to be a join).  I would li...
by middlemiddle Explorer in Splunk Search 09-24-2021
0 3
0
3
alexrod559
Hey guys,So I have two look up tables table1 and table 2. Table 1 ID Username Fname Lname Table 2 Username What i w...
by alexrod559 Loves-to-Learn Lots in Splunk Search 09-24-2021
0 3
0
3
graziaedu
I have a log as a belowcod:5678,status:600cod:9012,staus:600cod:1234,status:600cod: 1234,status:900cod:4987,status:60...
by graziaedu Explorer in Splunk Search 09-24-2021
0 7
0
7
aekruse
I have a search that counts the amount of times a user runs a program, and then returns the usernames of the users wh...
by aekruse New Member in Splunk Search 09-24-2021
0 0
0
0
DariusNG
Hi, I am trying to do a Lookup with a calculated field.Details:I have a csv containing three coloumns:DomainName,Thre...
by DariusNG Engager in Splunk Search 09-24-2021
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors