Splunk Search

Splunk Search
Community Activity
LynneEss
I have a working search that we use to give a list of the members of admin groups in Active Directory:| inputlookup A...
by LynneEss Engager in Splunk Search 06-10-2021
1 1
1
1
middlemiddle
I have a search pulling back fields "file_type" and "host", I have set "event_hour" and doing a stats so I know the n...
by middlemiddle Explorer in Splunk Search 06-10-2021
0 2
0
2
HMIPowell
How can the following 2 searches be used in a single Pie Chart?SEARCH ONEindex=security host=THAT* OR host=THIS* Sour...
by HMIPowell Explorer in Splunk Search 06-10-2021
0 3
0
3
daymar23
Hello Community! I am trying to get the record count by index that I am getting per month in Splunk. I am using this ...
by daymar23 Observer in Splunk Search 06-10-2021
0 4
0
4
FaridHamidi
  | eval Alert_Message_DISK = status_disk.": Disk utilization for ".host." is ".total_disk_utilization."%" | eval Ale...
by FaridHamidi Engager in Splunk Search 06-10-2021
0 1
0
1
rajasplunk89
How to use Rex command to show Value in between 'Id' and `language` for example 0827ce61-e07c-4b51-a052-681dcc94fa2f ...
by rajasplunk89 Engager in Splunk Search 06-10-2021
0 15
0
15
jpillai
Im not seeing any way Splunk will notify regarding automatic detention, which usually happens because of disk space i...
by jpillai Path Finder in Splunk Search 06-10-2021
0 5
0
5
TheBravoSierra
Hi, I'm trying to create a field extraction(extension) that goes off an existing field(TargetFilename) but it isn't w...
by TheBravoSierra Path Finder in Splunk Search 06-09-2021
0 8
0
8
yuanliu
I have some data with flip-flop values akin to the following simulation | makeresults count=20 | eval id = "id" . (ra...
by SplunkTrust SplunkTrust in Splunk Search 06-09-2021
0 3
0
3
TheBravoSierra
I'm trying to get this extraction for the filename to work via transforms.conf but it isn't working. Any ideas?[My_so...
by TheBravoSierra Path Finder in Splunk Search 06-09-2021
0 2
0
2
william_choo
Hi,I was able to do a search using this SPLindex="myapp_index" source="d:\\splunk\\test.json" | spath input=payload |...
by william_choo Explorer in Splunk Search 06-09-2021
0 4
0
4
Saikat001
How to get all the csv names present in Splunk environment ? Lets say, i have 1000+ csv and i want to get all csv nam...
by Saikat001 Explorer in Splunk Search 06-09-2021
0 2
0
2
Augustine_Vijay
Need a table to show top 5 URL as given below in splunk. Is this possible in splunk? I tried many ways but I cant get...
by Augustine_Vijay Explorer in Splunk Search 06-09-2021
0 16
0
16
Saikat001
Lets say, i have 1000+ csv and i want to find a host that might be present in multiple csv's. i want to find and retu...
by Saikat001 Explorer in Splunk Search 06-09-2021
0 1
0
1
harry_123
Any idea what this error is. I am getting the desired results with the query but it throws below error while executin...
by harry_123 Loves-to-Learn Lots in Splunk Search 06-09-2021
0 1
0
1
jpawloski
Attempting to run a tstats search that excludes a collection of IPv6 ranges from the results as follows:| tstats summ...
by jpawloski Path Finder in Splunk Search 06-09-2021
0 0
0
0
tommasoscarpa
Hi all, I have a situation like the following:I have some events with a start and end time that tell me when there ha...
by tommasoscarpa Explorer in Splunk Search 06-09-2021
0 3
0
3
sbollam
I have created a time input and also two text boxes to pass earliest and latest values to the searches.When I select ...
by sbollam Explorer in Splunk Search 06-09-2021
0 4
0
4
husse_wl
Hello,I'm designing some searches from O365 logs that have a complicated field called "Data", depending on the worklo...
by husse_wl Loves-to-Learn in Splunk Search 06-09-2021
0 2
0
2
jeffcui134
Environment: splunk8.0 python3 splunk python SDK 1.6.11 When I write a customized command with python: #!/usr/bin/e...
by jeffcui134 Engager in Splunk Search 06-09-2021
1 3
1
3
jbanAtSplunk
Hi,Strange behavior with Automatic lookup (same with manual lookup).I have csv file that contains codes, example:1 - ...
by jbanAtSplunk Communicator in Splunk Search 06-09-2021
0 2
0
2
Laxman24
Hi All,I need some help in searching,so I have 1 index but it has multiple sources,Index = Index1and within the index...
by Laxman24 Explorer in Splunk Search 06-09-2021
0 2
0
2
avikc100
 Am getting data in this format now.but i need to show only those row where sum of all column values are > 500am tryi...
by avikc100 Path Finder in Splunk Search 06-09-2021
0 3
0
3
sSiDs
Hi team!Couldn't find any info about it....but how make a proper search string to see what MAC address was on flappin...
by sSiDs New Member in Splunk Search 06-08-2021
0 1
0
1
Traer001
Hello,I have events like this:2021-06-07 17:53:01 UserId:123 Session complete2021-06-07 17:25:01 UserId:123 Start ses...
by Traer001 Path Finder in Splunk Search 06-08-2021
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...