Splunk Search

Splunk Search
Community Activity
iyanushkevich
Hi! My task is as follows: I want to compare the increment of a certain type of errors: the average value of each typ...
by iyanushkevich Loves-to-Learn Lots in Splunk Search 07-26-2021
0 4
0
4
dasfx
I am doing the labs for Fundamentals Part 2 and I am not understanding something I have to use the startswith and end...
by dasfx Engager in Splunk Search 07-26-2021
0 2
0
2
VS0909
How to add group widgets/panel in a dashboard with a common border?Eggroup1 :  panel1,  panel 2  - combined border fo...
by VS0909 Communicator in Splunk Search 07-26-2021
0 1
0
1
Rabbit
in search, w/ rex command I can specify which field I want to apply the Regex as following example| rex field=event "...
by Rabbit Loves-to-Learn in Splunk Search 07-25-2021
0 5
0
5
verifi81
Hello friends, Suppose I install Microsoft Sysmon on a Windows server.  I then go install the Universal Forwarder on ...
by verifi81 Path Finder in Splunk Search 07-25-2021
0 2
0
2
SS1
Hi,I have below sources,source =  C:\Stats\user1\Tmpdata\Mappers\Consolesx\start.logsource =  C:\Stats\user2\Tmpdata\...
by SS1 Path Finder in Splunk Search 07-25-2021
0 4
0
4
aag
Hello,Here is the whole context and question:https://community.splunk.com/t5/Splunk-Search/Aggregate-query-help/m-p/5...
by aag Engager in Splunk Search 07-25-2021
0 1
0
1
actionabledata
I have a single algorithm with 2 methods. Each method produces the same type of data but with different fields names ...
by actionabledata Path Finder in Splunk Search 07-24-2021
0 0
0
0
jimhill
Hi, I have data that looks like this (as you can see user_id 9 has filled numerous rows). This is just a csv ingested...
by jimhill Engager in Splunk Search 07-24-2021
0 4
0
4
AdrianH
Hi. First, I've been using this forum for a few months now as I'm new to Splunk.   Thanks to all the contributors on ...
by AdrianH Explorer in Splunk Search 07-24-2021
0 4
0
4
Abhishek_
Hi All, I have a use case to align two stacked graphs side by side. So, there are 4 columns with values for any parti...
by Abhishek_ Observer in Splunk Search 07-24-2021
0 2
0
2
rahul8777
sourcetype=cp_log action!=Drop OR action!=Reject OR action!=dropped I  am socked ,when i am searching with above quer...
by rahul8777 Explorer in Splunk Search 07-24-2021
0 2
0
2
parthou
Hello Experts,I am new to Splunk and trying to build basic queries in Splunk to build use cases. Currently I am worki...
by parthou Explorer in Splunk Search 07-23-2021
0 8
0
8
ASTARS47
There are various event codes like eventID = "123" , eventID ="456", eventID = "789" . There are some "appID"   field...
by ASTARS47 New Member in Splunk Search 07-23-2021
0 1
0
1
aag
Hi Team - I am trying to first search and  then aggregate results from following Splunk logs:Raw format: "buildDimens...
by aag Engager in Splunk Search 07-23-2021
0 2
0
2
mlf
I have a custom generating command that returns events to Splunk, however those events are not parsed, so the kv data...
by mlf Path Finder in Splunk Search 07-23-2021
0 0
0
0
bhavika100
I have a dashboard with multiple inputs. These inputs are like filters on top of basic search. I want1. if phone mdn ...
by bhavika100 Explorer in Splunk Search 07-23-2021
0 4
0
4
martinpugh
Hi all, I'm trying to pull out the MAC addresses from a series of records which is mostly working using the followin...
by martinpugh Explorer in Splunk Search 07-23-2021
0 3
0
3
alexspunkshell
Hi All,I want to join two indexes and get a result. Search Query -1index=Microsoft| eval Event_Date=mvindex('eventDat...
by alexspunkshell Contributor in Splunk Search 07-23-2021
0 9
0
9
lbogle
Hello Splunkers, I've been trying to solve this problem for a while now but I am still not able to NOT the contents o...
by lbogle Contributor in Splunk Search 07-23-2021
0 10
0
10
Rakesh915473
Hello Team, rex field=_raw "string_list=%25(?<new_field1>\w+)%25" Above condition will get a word between %25 to %25,...
by Rakesh915473 Explorer in Splunk Search 07-23-2021
0 4
0
4
Rakesh915473
Hello Team,I'm very new to splunk, I have below two logs"message": "api.main REQ user1 10.10.44.76 \"GET /api/v1/data...
by Rakesh915473 Explorer in Splunk Search 07-23-2021
0 12
0
12
jaysonpryde
HI,As mentioned in the subject, I want to perform operations on a list of values with a single value. To be clearer, ...
by jaysonpryde Path Finder in Splunk Search 07-23-2021
0 5
0
5
sangs8788
Hi,I have a summary index which gets indexed once in a month. I have a query which runs based on current month looks ...
by sangs8788 Communicator in Splunk Search 07-23-2021
0 0
0
0
cindygibbs_08
Hello my loves I have one quick question Lets say I have this two stringsAUJ.UEIEJ.829839.239383033.4788383.27383.8HJ...
by cindygibbs_08 Communicator in Splunk Search 07-22-2021
0 3
0
3
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...