Splunk Search

Splunk Search
Community Activity
yuanliu
I have a lookup that can return multivalue for two fields, one of them a timestamp, like thiskeytextdatekey1abc|def20...
by SplunkTrust SplunkTrust in Splunk Search 06-20-2021
0 10
0
10
indeed_2000
HiI install forwarder on a server.it work perfectly and forward anything on this path /data/app/log to splunk server,...
by indeed_2000 Motivator in Splunk Search 06-20-2021
0 2
0
2
moayadalghamdi
Hello Splunkers in my firewall logs, i have three numerical fields, (out_packet, in_packet, bytes) i want to sum thes...
by moayadalghamdi Path Finder in Splunk Search 06-20-2021
0 6
0
6
xisura
Hi Newbie here, Im exploring right now the map on splunk 6, Now my question is,is it possible to add a rangemap in g...
by xisura Communicator in Splunk Search 06-19-2021
0 9
0
9
vschrodda
 With a search I would like a result that does NOT match an element in a listFor instance:   index=myindex source="my...
by vschrodda Explorer in Splunk Search 06-18-2021
0 5
0
5
token1
I've seen the TA Unified2 do this, one single line of regex pulling all relevant fields from snort logs.  I'm wanting...
by token1 Explorer in Splunk Search 06-18-2021
0 1
0
1
actionabledata
How do I search for all apps and dashboards on a server and yield a table with author, app name, description, actual ...
by actionabledata Path Finder in Splunk Search 06-18-2021
0 2
0
2
LionelHutz
Hello Hello,Trying to make this search work:| tstats allow_old_summaries=true dc(Malware_Attacks.signature) as "infec...
by LionelHutz Engager in Splunk Search 06-18-2021
0 1
0
1
Traer001
Hi all,I am trying to get the duration of the starting found error based on the affected users and the last fail/succ...
by Traer001 Path Finder in Splunk Search 06-18-2021
0 2
0
2
rendie
Hi folks,Just a quick question. For example, a have a dataset_timefield_xfield_y14:010014:020114:030214:041314:051014...
by rendie Path Finder in Splunk Search 06-18-2021
0 4
0
4
alexeysharkov
Hello im newbie with Splunk searchCan you please help meI have HF request which return:-AAA  datetime_of_change-BBB d...
by alexeysharkov Path Finder in Splunk Search 06-18-2021
0 9
0
9
rbal_splunk
After Smartstore was enabled for deployment the indexer's log's are flooded with messages like"INFO CacheManagerHandl...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 06-18-2021
0 2
0
2
moinyuso96
After using transactions my "raw" field looks something like this. I want to limit the amount of rows captured  by tr...
by moinyuso96 Path Finder in Splunk Search 06-17-2021
0 1
0
1
kashnburn
I'm trying to use SEDCMD to remove some text from a logfile. example data below, data to be removed in bold. Tried so...
by kashnburn Engager in Splunk Search 06-17-2021
0 1
0
1
munisb
Hi,I have two csv files where I am trying to cidrmatch between ip and subnet - but it doesn't appear to be workingtes...
by munisb Explorer in Splunk Search 06-17-2021
0 4
0
4
KongJian
the Scenario like this: I want to pick up 5% minimum  value from thousands of data, Example:1,2,3 ,4 5,6,7,8,9,10   I...
by KongJian Engager in Splunk Search 06-17-2021
0 3
0
3
gdavid
is there a way to alert when json data changes? i want to track changes for a variety of apis results/output that sho...
by gdavid Path Finder in Splunk Search 06-17-2021
0 1
0
1
karthik_y
Hello,I am having values of a particular application as below.Looking to get the maximum version value or sorting the...
by karthik_y Engager in Splunk Search 06-17-2021
1 4
1
4
iamuser
What search criteria should I include to only get these logs?D:\Applications\Windows.App.0001\app1\logs\log-06-17-202...
by iamuser Engager in Splunk Search 06-17-2021
0 2
0
2
msage
A bit ago I submitted a question regarding how to get the average alarms per reader. So for example we have 100 alarm...
by msage Path Finder in Splunk Search 06-17-2021
0 2
0
2
Traer001
Hello,I have a search that is joining two searches (one for cart details and one for items that have been brought to ...
by Traer001 Path Finder in Splunk Search 06-17-2021
0 2
0
2
Bettynet
Hi,I would like to have a dashboard panel with just a number, which should be the substraction of two values obtained...
by Bettynet Engager in Splunk Search 06-17-2021
0 5
0
5
kashnburn
I'm fairly new to splunk so please bare with me. I have a logfile that has multiple lines of data. However when I do ...
by kashnburn Engager in Splunk Search 06-17-2021
0 2
0
2
aquinojason
Hi,I am making a report that needs to identify how long long since a user launch an application. Can I use splunk to ...
by aquinojason Path Finder in Splunk Search 06-17-2021
0 2
0
2
dauren_akilbeko
I'm working with Windows events, and want to make following report/search:process1                                   ...
by dauren_akilbeko Communicator in Splunk Search 06-17-2021
0 3
0
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...