Splunk Search

Splunk Search
Community Activity
mani9059
Hi Team, I am trying to extract complete URL from the below splunk search i tried many ways can you please help me on...
by mani9059 Engager in Splunk Search 06-07-2021
0 3
0
3
mani9059
0
1
Splunk_Ryan
I would like to extract user name, source IP, source port and access protocol from the following 2 events from /var/l...
by Splunk_Ryan Explorer in Splunk Search 06-06-2021
0 6
0
6
tkdguq0110
How can I use abstract command?My query is| makeresults| eval test = " 123456789123456"| abstract maxlines=1 This que...
by tkdguq0110 Path Finder in Splunk Search 06-06-2021
0 0
0
0
ebs
This is my base search:| datamodel Test summariesonly=true search| search "TEST.date"=2021-05-23 | rename "TEST.date"...
by ebs Communicator in Splunk Search 06-06-2021
0 10
0
10
ebs
Hi,I want to create a search that is able to grab both the start and end times of a specific action, but to create th...
by ebs Communicator in Splunk Search 06-06-2021
0 1
0
1
new2splunk1
Hi Splunk experts, I'm generating stats from 3 indexes (System A, B, C) and the results look like this:Table 1:The to...
by new2splunk1 Engager in Splunk Search 06-05-2021
0 4
0
4
harry_123
Hello, I have alerts that look like belowMay 13 17:15:30 11.2.3.22 0000017768: NOXXXXXX10A: May 13 2021 17:15:30.467 ...
by harry_123 Loves-to-Learn Lots in Splunk Search 06-04-2021
0 13
0
13
vijaykuma
  index=_internal host="ip" source=*license_usage.log* type="Usage"     [| inputlookup all_cs_indexes.csv     | renam...
by vijaykuma New Member in Splunk Search 06-04-2021
0 1
0
1
splunkerer
Hello,I am creating a dashboard, no matter which input can be used, but need is to paste multiple input into dashboar...
by splunkerer Path Finder in Splunk Search 06-04-2021
0 6
0
6
shrogers
Can I please get some assistance on the below?I'm trying to add a filter TRAN_CLASS!=6 to the below query. When I add...
by shrogers Loves-to-Learn Everything in Splunk Search 06-04-2021
0 4
0
4
vijaykuma
We have requirement to Integrate Oracle Unified Directory(Authentication and OS logs) with splunk. Action points: Pre...
by vijaykuma New Member in Splunk Search 06-04-2021
0 0
0
0
ivana27
Hello Splunkers,please help.I have two types of search result and i want to make alert only when 1.) occured:1.) 2021...
by ivana27 Path Finder in Splunk Search 06-04-2021
0 1
0
1
renuka
Hello All"Good Day"index="aedc"| rex field=source "-_(?<source>\S+)"| rex "(?<ModuleID>MY\d+)"| rex "(?<Path>/F.\s\S+...
by renuka Path Finder in Splunk Search 06-04-2021
0 3
0
3
Atif
Hi,I'am sending some events each minute to Splunk : TIMEIDINOUT08:00A1008:00B00    08:01A2108:01B2208:01C40    08:02A...
by Atif Explorer in Splunk Search 06-04-2021
0 3
0
3
RmDok
`base search | stats values(zipcode), count(zipcode) as c by country | sort -c | head 10`which gives me most appeared...
by RmDok Loves-to-Learn Lots in Splunk Search 06-04-2021
0 3
0
3
a_n
Hello,I have a dashboard with Choropleth map presenting events from various countries (categorical Color mode).In the...
by a_n Path Finder in Splunk Search 06-04-2021
0 0
0
0
junier16
im looking for the field "is_prohibited=true". This is field is located in one of lookup table, event type, or tag. H...
by junier16 Explorer in Splunk Search 06-03-2021
0 1
0
1
dojiepreji
I need to compare my timepicker values (timePicker token) to the field date_e which returns an epoch value. I conve...
by dojiepreji Path Finder in Splunk Search 06-03-2021
0 3
0
3
teco_akelly
I've got a number of files coming from directories similar to this....C:\File Transfer\Relay Files\8Series_files\WB-C...
by teco_akelly Engager in Splunk Search 06-03-2021
0 1
0
1
badari
Hello,Sorry for a newbie question, I have the following event thats generated{<!-- -->&#64;timestamp: 2021-06-03T17:39:34.720&#43;00:...
by badari Engager in Splunk Search 06-03-2021
0 3
0
3
anil1432
I need to know  more details about splunk usage for Paas/Rpaas  users.Can you define us some brief explanation please...
by anil1432 Explorer in Splunk Search 06-03-2021
0 0
0
0
abidkar
Hello,I am trying to search the splunk log but I am getting the output in payload format. is there a way I can get it...
by abidkar Loves-to-Learn Lots in Splunk Search 06-03-2021
0 17
0
17
javier_reina
Good morningIn a kv store we have 3 columns: Subcontrol, Value1 and Value2.We are trying to calculate the percentage ...
by javier_reina Explorer in Splunk Search 06-03-2021
0 0
0
0
ajees_basha
how can we change the phone number format. i used sed mod it is working fine but i want to store the formatted phone ...
by ajees_basha Explorer in Splunk Search 06-03-2021
0 10
0
10
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...