Splunk Search

Splunk Search
Community Activity
indeed_2000
HiI have log file like this:2021-07-15 00:00:01,869 INFO APP.InEE-p1-1234567 [AppListener] Receive Message[A123]: Q[p...
by indeed_2000 Motivator in Splunk Search 07-19-2021
0 10
0
10
VS0909
Need help with a Splunk query  to display % failures % failures = A1/A2 *100A1= Total number of events returned by th...
by VS0909 Communicator in Splunk Search 07-19-2021
0 5
0
5
5296
actionfeatureversionlocationcount?difference?Af1v1WA1200Af1v1OR11010Af1v1CA1155Bf1v1AZ1200Af1v2WA141Af1v2OR105Bf1v2AZ...
by 5296 Loves-to-Learn Lots in Splunk Search 07-19-2021
0 1
0
1
moinyuso96
I created some of the columns using regex. So all of the codes for the regex needs to be included. I would like to fi...
by moinyuso96 Path Finder in Splunk Search 07-18-2021
0 2
0
2
indeed_2000
Hii have log file like this: 2021-07-15 00:00:01,869 INFO client.InEE-server1-1234567 [AppListener] Receive Message[A...
by indeed_2000 Motivator in Splunk Search 07-17-2021
0 6
0
6
Laurengineer
I have a few sourcetypes, looking something like this:sourcetype=weatherdate, location, temperaturesourcetype=actions...
by Laurengineer Engager in Splunk Search 07-17-2021
0 1
0
1
asing13
Dear Community Members ,In splunk cloud instance :I am trying to get VPN login and logout for users in a single table...
by asing13 Path Finder in Splunk Search 07-17-2021
0 2
0
2
krusty
Hi there, we have an issue with hostname extraction from syslog events. Normaly the extraction works fine, but for ...
by krusty Contributor in Splunk Search 07-17-2021
0 7
0
7
splunkerer
Hi Folks,I am trying to enrich my search with subsearch in the same time bucket/bin. The search can be found below.De...
by splunkerer Path Finder in Splunk Search 07-17-2021
0 1
0
1
Lukas85
Hi AllI'm new on splunk and have following problem.We need data from a table depending on the value of a variable. Fo...
by Lukas85 New Member in Splunk Search 07-17-2021
0 1
0
1
jsturgeon
Hello, I am looking to clean up the result data from a Splunk query.How do I remove all the text prior to the user na...
by jsturgeon New Member in Splunk Search 07-16-2021
0 1
0
1
revanthammineni
Hello Splunkers.I'm working on some of the usecases on ES and one of the request that I've got from my upper manageme...
by revanthammineni Path Finder in Splunk Search 07-16-2021
0 2
0
2
shashi584
We have 3 different (Active,Closed,Resolved) records for same Incident and we need to retrieve only Active incident r...
by shashi584 Explorer in Splunk Search 07-16-2021
0 6
0
6
splunkcol
 I have 3 different indexes and they asked me to search by document number.The structure of the logs is different inc...
by splunkcol Builder in Splunk Search 07-16-2021
0 2
0
2
joshiro
Hi, i need help with some datamodel acceleration issues in CIM.The problem is that i accelerated a datamodel with 1y ...
by joshiro Communicator in Splunk Search 07-16-2021
0 3
0
3
radalliance
Hey all, I'm trying to separate out the IP address (Source Network Address:) from the Windows event Message field. I'...
by radalliance Engager in Splunk Search 07-16-2021
0 3
0
3
bhavika100
Our event log has request and response. Request and response body can either be a json object or json array. I need t...
by bhavika100 Explorer in Splunk Search 07-16-2021
0 5
0
5
mdzmuran
Hi Splunk Community.I have an alert, which runs a query regularly, for example hourly 24*7*365. If the alert is trigg...
by mdzmuran Observer in Splunk Search 07-16-2021
0 3
0
3
kronite13
I need to do an analysis on API calls using logs, like avg, min, max, percentile99, percentil95, percentile99 respons...
by kronite13 Explorer in Splunk Search 07-16-2021
1 6
1
6
JChris_
I have an index where one of the relevant fields is a domain. This index is used in a search in a dashboard, where I ...
by JChris_ Path Finder in Splunk Search 07-16-2021
0 5
0
5
bosseres
Hello, communityWhat's skipped search? Do I understand correctly that it's a search which finished with error?How can...
by bosseres Contributor in Splunk Search 07-16-2021
0 2
0
2
joe06031990
Hello,I am trying to get the Perc99 and Perc95 from the total transaction in IIS which the bellow search: source="C:\...
by joe06031990 Communicator in Splunk Search 07-15-2021
0 3
0
3
joe06031990
Good morning,I am looking on generating a search to find the 1% slowest requests from IIS logs however I am not sure ...
by joe06031990 Communicator in Splunk Search 07-15-2021
0 0
0
0
dipocket_org
Every time I search, I get errors:Could not load lookup=LOOKUP-cisco_asa_change_analysisCould not load lookup=LOOKUP-...
by dipocket_org Engager in Splunk Search 07-15-2021
0 2
0
2
indeed_2000
HiHere is my log, what is the rex for extract "0000A0@#0000" and "mymodulename" 2021-07-14 23:59:05,185 INFO [APP] Us...
by indeed_2000 Motivator in Splunk Search 07-15-2021
0 8
0
8
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...