Splunk Search

Splunk Search
Community Activity
MarieHe
Hello,I would like to enter the info from a lookup table into my dashboard search. lookup table name: FIP.csvcontent:...
by MarieHe New Member in Splunk Search 08-17-2021
0 3
0
3
Mahipal456
Hi All,I need to extract  the fields from the below xml data tried xpath and xmlkv but not working as expected.<item>...
by Mahipal456 Loves-to-Learn Lots in Splunk Search 08-17-2021
0 17
0
17
graziaedu
I have the follow queryindex=index |spath output=traceSteps path=traceSteps{}|table traceSteps|mvexpand traceSteps|re...
by graziaedu Explorer in Splunk Search 08-17-2021
0 2
0
2
toontech
How do I get a list of AD groups a specific user was removed from in the last week please. We had a Helpdesk person a...
by toontech New Member in Splunk Search 08-17-2021
0 3
0
3
xindeNokia
Search failed with error msg: Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at tim...
by xindeNokia Path Finder in Splunk Search 08-17-2021
0 3
0
3
joe06031990
Hello,I have the bellow search:index=test sourcetype=Test|stats count by _time|eventstats perc99(count) as p99|eval P...
by joe06031990 Communicator in Splunk Search 08-17-2021
0 2
0
2
mayurr98
Hello, The question is pretty straightforward. I would like to alert if 3 failed logins followed by 1 successful logi...
by mayurr98 Super Champion in Splunk Search 08-17-2021
0 1
0
1
dm1
So I need to run search on a firewall index where I need to look for field values matching from two lookup files, one...
by dm1 Contributor in Splunk Search 08-16-2021
0 5
0
5
szimmer661
I'd like to force consistency across all dashboard charts. For instance, in all charts, I'd like a certain server or...
by szimmer661 Explorer in Splunk Search 08-16-2021
1 5
1
5
shakSplunk
Hi all,I have a field that has a time value such as (_time field):2021-08-12 15:18:42However, when I got to use the r...
by shakSplunk Path Finder in Splunk Search 08-16-2021
0 4
0
4
iamsplunker
I've a query which has column like AccountNO eventType _time and differenceI'm trying to find the time difference of ...
by iamsplunker Communicator in Splunk Search 08-16-2021
0 0
0
0
edwinmae
We are using Splunk Enterprise, using SmartStore (S3).Example: Index A, with frozentimeperiodinsecs = 7776000 (~90 da...
by edwinmae Path Finder in Splunk Search 08-16-2021
0 4
0
4
SailorManDan
Hello, I am trying to only return the values of certain fields to be used in a subsearch. The problem I'm encounterin...
by SailorManDan Explorer in Splunk Search 08-16-2021
1 3
1
3
learningsplunk
Hello Splunk community,When trying to splice multiple events so that it can generate a specific output from a Splunk ...
by learningsplunk Path Finder in Splunk Search 08-16-2021
0 2
0
2
Nauman_Javaid
I have query something like this: index=sample source=test (earliest=-1d@d latest=@d) OR (earliest=-2d@d latest=-1d@d...
by Nauman_Javaid Loves-to-Learn in Splunk Search 08-16-2021
0 1
0
1
shanecifaldi
I need some help with an alert i have been stuck on. I have a DBCONNECT lookup that returns a value once a day. This ...
by shanecifaldi Loves-to-Learn Everything in Splunk Search 08-16-2021
0 0
0
0
shakSplunk
Hi all,I'm trying to dynamically add columns to two fixed columns based on the environment value selected. For instan...
by shakSplunk Path Finder in Splunk Search 08-16-2021
0 13
0
13
moonie
Hello, I'm working on a really complex search where I need to combine results from different lookup tables. One looku...
by moonie Explorer in Splunk Search 08-16-2021
0 3
0
3
analiaeg
Hello everyone. In my team we are investigating how to build a new application that does "Root Cause Analysis" (simi...
by analiaeg Explorer in Splunk Search 08-15-2021
0 5
0
5
SplunkDash
Hello,I wrote a PROPS Configuration file for following csv file but getting error message. Any help will be highly ap...
by SplunkDash Motivator in Splunk Search 08-15-2021
0 4
0
4
indeed_2000
HiI have compress file that contain several files. in source just show compress file. e.g compress files name is log....
by indeed_2000 Motivator in Splunk Search 08-15-2021
0 1
0
1
Shimon81
 I want to run a base query where some fields has a value which is present in inputlookup table For example,  I have ...
by Shimon81 Explorer in Splunk Search 08-15-2021
0 7
0
7
georgear7
I have used the below query to create one table: index=abc sourcetype=xyz source=*.txt host=host1 OR host=host2 | rex...
by georgear7 Communicator in Splunk Search 08-15-2021
0 6
0
6
pir8radio
Search 1 dashboard panel - Search 2 dashboard panel = third dashboard panel difference between two searches. Here is ...
by pir8radio Path Finder in Splunk Search 08-14-2021
0 2
0
2
mpartee
 I am trying to craft a search that uses the most recent source as the basis for my search. The source is a file path...
by mpartee Engager in Splunk Search 08-14-2021
0 4
0
4
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors