Splunk Search

Splunk Search
Community Activity
AlexH
looHi everybody, i hope you can help me with my pb.i want add fields in a lookup with a request that dont use index ....
by AlexH Engager in Splunk Search 09-16-2021
0 2
0
2
Georgi
I am parsing SFTP logs of file downloads and want to count how many bytes a specific user downloaded at what time. Th...
by Georgi Engager in Splunk Search 09-16-2021
0 4
0
4
renuka
Hello "Good Day"   How to add the progress bar inside the cell in dashoard.i need the dashboard panel format in the ...
by renuka Path Finder in Splunk Search 09-16-2021
0 1
0
1
priyangshupal
I have two fields skill1 and skill2skill2:      skill1:     Both these queries are producing results: timechart span=...
by priyangshupal Engager in Splunk Search 09-16-2021
0 10
0
10
renuka
Hello I have table  in my dashboard      IDJan_TargetJan_Actual1506020N/AIn similar way  for all monthsnow i need a f...
by renuka Path Finder in Splunk Search 09-15-2021
0 4
0
4
etoombs
Hi. I know a lookup file can contain wildcards and use them with the WILDCARD(<field>) setting, but is it possible to...
by etoombs Path Finder in Splunk Search 09-15-2021
0 0
0
0
jkwilling
When mean & avg are both present on a "stats" search, the first one in order will be missing so:| makeresults count=1...
by jkwilling Engager in Splunk Search 09-15-2021
0 3
0
3
Rkp_splunk
Hi I have got this log where it shows how much time it takes to load investor page in millisecond(ms)2021-09-15 13:40...
by Rkp_splunk Engager in Splunk Search 09-15-2021
0 1
0
1
djreschke
When I test the regex in both regex101 and using the rex command in the search bar and they parsed out the fields cor...
by djreschke Communicator in Splunk Search 09-15-2021
0 1
0
1
Susha
Hi ,i have 2 queries .(index=abc OR index=def) category= * OR NOT blocked =0 AND NOT blocked =2|rex field=index "(?<L...
by Susha Engager in Splunk Search 09-15-2021
0 2
0
2
srinivas_gowda
Hello all, I am tryin to extract only the highlighted from the below event, however I am failing to extract.Can you p...
by srinivas_gowda Path Finder in Splunk Search 09-15-2021
0 2
0
2
mohdameen81
HI  please tell me how to write the query for the range of the IP ADDRESS Such assrc!=10.0.0.0/8 To src!=10.24.1.3
by mohdameen81 Observer in Splunk Search 09-15-2021
0 2
0
2
priyangshupal
I have a field timeofevent which contains the time at which the event was logged in 24 hour format.Format of timeofev...
by priyangshupal Engager in Splunk Search 09-15-2021
0 5
0
5
rai4shambhavi
so my log lines look something like this<<METRIC-START>>{"A":332,"B":45,"C":67,"D":23,"E":234,"F":435,"G":43,"H":66,"...
by rai4shambhavi Explorer in Splunk Search 09-15-2021
0 1
0
1
apache_strike
Hi everyone, I am trying to remove partial duplicate in the same field, but couldn't find a solution yet.For instance...
by apache_strike Engager in Splunk Search 09-15-2021
0 1
0
1
dbuckley669
My search returns a table of a count of ip addresses that have hit our system in a given search period. I am trying t...
by dbuckley669 Engager in Splunk Search 09-15-2021
0 3
0
3
vsommer
Hello,I have a problem regarding a datamodel search.My datamodel consists of different boolean values with a span of ...
by vsommer Explorer in Splunk Search 09-15-2021
0 6
0
6
charlesmeo
Hi there,I'm seeing a strange problem with version 8.0.8I have a search to build a lookup table one time only, which ...
by charlesmeo Explorer in Splunk Search 09-14-2021
0 0
0
0
epw0rrell
Hello, I currently have a search over index_A that runs a sub-search from index_B looking to match a field (field_B) ...
by epw0rrell Path Finder in Splunk Search 09-14-2021
0 0
0
0
disha
I am having a search in my view code and displaying results in the form of table. small example result: custid Eve...
by disha Contributor in Splunk Search 09-14-2021
1 6
1
6
alexspunkshell
Hi, I am trying to export PDF in Splunk Security Essential App --> Analytics Advisor --> Mitre ATT&CK Framework --> E...
by alexspunkshell Contributor in Splunk Search 09-14-2021
0 0
0
0
oleg106
Hello,I have 2 CSV lookups updating several times a day.  One (A) is from CMDB with the entire list of assets (hostna...
by oleg106 Explorer in Splunk Search 09-14-2021
0 1
0
1
met
I've got some logs I need to join and put on the same row.I've tried a few different ways and searched the community ...
by met Engager in Splunk Search 09-14-2021
0 6
0
6
Martin583
I see the following errors when running a search against data in a vix.We have recently upgraded to 8.1.3 when I assu...
by Martin583 Explorer in Splunk Search 09-14-2021
0 0
0
0
sujith_kumar
Hi All,We have an index indexA, which gets data from multiple agencies agentA, agentB, agentC, and another index inde...
by sujith_kumar New Member in Splunk Search 09-14-2021
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...