Splunk Search

Splunk Search
Community Activity
MesutUgurlu
Hi,I want to copy some logs in one index to another index with the same host information. I use collect command to do...
by MesutUgurlu New Member in Splunk Search 09-17-2021
0 3
0
3
SamHTexas
Also please guide me on how to optimize my Lookups for more efficiency. When does one use Lookups vs KVstores? Thank ...
by SamHTexas Builder in Splunk Search 09-17-2021
0 1
0
1
nadlurinadluri
HI Splunkers,I am using Splunk tables inbuilt color coding to highlight a cell based on certain condition. The proble...
by nadlurinadluri Communicator in Splunk Search 09-16-2021
0 0
0
0
dmtman
Hello - I am new to splunk and am trying to do a search on data that calls out three different fields for duplicates ...
by dmtman New Member in Splunk Search 09-16-2021
0 2
0
2
ezmo1982
Hi,I am looking to compare a field value against the results of an ldapsearch to check whether the value is present o...
by ezmo1982 Path Finder in Splunk Search 09-16-2021
0 3
0
3
vivekmisra
I have this result response[sample]: "{\"meta\":{\"code\":400}},[Content-Type:\"application/json\", Transfer-Encoding...
by vivekmisra Observer in Splunk Search 09-16-2021
0 3
0
3
stavbergen
Hello I have 3 sets of data and I want to join them all but they don't have the same common field, the trouble I'm ha...
by stavbergen Explorer in Splunk Search 09-16-2021
0 1
0
1
shaquibk
My requirement is something like this:Lookup 1 looks like thisName | Avg_CountA          | 3B          |  7D         ...
by shaquibk Explorer in Splunk Search 09-16-2021
0 3
0
3
AlexH
looHi everybody, i hope you can help me with my pb.i want add fields in a lookup with a request that dont use index ....
by AlexH Engager in Splunk Search 09-16-2021
0 2
0
2
Georgi
I am parsing SFTP logs of file downloads and want to count how many bytes a specific user downloaded at what time. Th...
by Georgi Engager in Splunk Search 09-16-2021
0 4
0
4
renuka
Hello "Good Day"   How to add the progress bar inside the cell in dashoard.i need the dashboard panel format in the ...
by renuka Path Finder in Splunk Search 09-16-2021
0 1
0
1
priyangshupal
I have two fields skill1 and skill2skill2:      skill1:     Both these queries are producing results: timechart span=...
by priyangshupal Engager in Splunk Search 09-16-2021
0 10
0
10
renuka
Hello I have table  in my dashboard      IDJan_TargetJan_Actual1506020N/AIn similar way  for all monthsnow i need a f...
by renuka Path Finder in Splunk Search 09-15-2021
0 4
0
4
etoombs
Hi. I know a lookup file can contain wildcards and use them with the WILDCARD(<field>) setting, but is it possible to...
by etoombs Path Finder in Splunk Search 09-15-2021
0 0
0
0
jkwilling
When mean & avg are both present on a "stats" search, the first one in order will be missing so:| makeresults count=1...
by jkwilling Engager in Splunk Search 09-15-2021
0 3
0
3
Rkp_splunk
Hi I have got this log where it shows how much time it takes to load investor page in millisecond(ms)2021-09-15 13:40...
by Rkp_splunk Engager in Splunk Search 09-15-2021
0 1
0
1
djreschke
When I test the regex in both regex101 and using the rex command in the search bar and they parsed out the fields cor...
by djreschke Communicator in Splunk Search 09-15-2021
0 1
0
1
Susha
Hi ,i have 2 queries .(index=abc OR index=def) category= * OR NOT blocked =0 AND NOT blocked =2|rex field=index "(?<L...
by Susha Engager in Splunk Search 09-15-2021
0 2
0
2
srinivas_gowda
Hello all, I am tryin to extract only the highlighted from the below event, however I am failing to extract.Can you p...
by srinivas_gowda Path Finder in Splunk Search 09-15-2021
0 2
0
2
mohdameen81
HI  please tell me how to write the query for the range of the IP ADDRESS Such assrc!=10.0.0.0/8 To src!=10.24.1.3
by mohdameen81 Observer in Splunk Search 09-15-2021
0 2
0
2
priyangshupal
I have a field timeofevent which contains the time at which the event was logged in 24 hour format.Format of timeofev...
by priyangshupal Engager in Splunk Search 09-15-2021
0 5
0
5
rai4shambhavi
so my log lines look something like this<<METRIC-START>>{"A":332,"B":45,"C":67,"D":23,"E":234,"F":435,"G":43,"H":66,"...
by rai4shambhavi Explorer in Splunk Search 09-15-2021
0 1
0
1
apache_strike
Hi everyone, I am trying to remove partial duplicate in the same field, but couldn't find a solution yet.For instance...
by apache_strike Engager in Splunk Search 09-15-2021
0 1
0
1
dbuckley669
My search returns a table of a count of ip addresses that have hit our system in a given search period. I am trying t...
by dbuckley669 Engager in Splunk Search 09-15-2021
0 3
0
3
vsommer
Hello,I have a problem regarding a datamodel search.My datamodel consists of different boolean values with a span of ...
by vsommer Explorer in Splunk Search 09-15-2021
0 6
0
6
Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...