Splunk Search

Splunk Search
Community Activity
timm7474
I'm trying to check the value of a token and if it is equal to "X" change it to an * but if it is equal to anything e...
by timm7474 Explorer in Splunk Search 05-18-2021
0 4
0
4
Mahi4rus
HI all i have prepared splunk search query for every day  poolwise license  but i need  last 6 months poolwise data a...
by Mahi4rus Explorer in Splunk Search 05-18-2021
0 0
0
0
vinod0313
I have two queries and i want to display both the query result in line chart (one line in the line chart from the res...
by vinod0313 Explorer in Splunk Search 05-18-2021
0 4
0
4
christian75
When i want to extract BiosMake fields with fields extraction.I have this error:Error in 'rex' command
by christian75 Engager in Splunk Search 05-18-2021
0 5
0
5
randy_moore
We are getting: Dispatch Runner: Configuration initialization for splunk\var\run\searchpeers\ really long string of ...
by randy_moore Path Finder in Splunk Search 05-18-2021
1 13
1
13
srinivas_gowda
Hello all, I am trying to run the below query and when I change the earliest to last 7 days I am getting the below er...
by srinivas_gowda Path Finder in Splunk Search 05-18-2021
0 5
0
5
surejsajeev
I am running a query to parse a two-level nested JSON that takes out only the second level dict and puts it in the fo...
by surejsajeev Explorer in Splunk Search 05-17-2021
0 1
0
1
samrat1220
0
1
Becherer
I am looking to have a eval search that looks for a field name of "Name" and adds the value. If the field doesn't exi...
by Becherer Explorer in Splunk Search 05-17-2021
0 1
0
1
weetabixsplunk
Hi guys,I'm trying to create a search that triggers an alert every time a user has been signed out of their o365 sess...
by weetabixsplunk Explorer in Splunk Search 05-17-2021
0 0
0
0
chaday00
I have built a query that exports data by a date range and based on a scan or source. Currently I'm grouping them int...
by chaday00 Path Finder in Splunk Search 05-17-2021
0 2
0
2
kig121
I would like to listed those events (reuirements) which state are changed to Agreed from last 3 days.Today have a dat...
by kig121 Loves-to-Learn Lots in Splunk Search 05-17-2021
0 3
0
3
saulverde
I have specific events with rows and rows of MV data.  They have a header and footer data but the bulk of the body is...
by saulverde Path Finder in Splunk Search 05-17-2021
0 3
0
3
agenco01
I have a CSV with multiple hundred email addresses and I am trying to run a report to determine which accounts are ac...
by agenco01 Engager in Splunk Search 05-17-2021
0 3
0
3
Villo
Hi, I have an issue with a query of mine.  The length of it is exactly 378 lines, and however I managed to save it on...
by Villo Observer in Splunk Search 05-17-2021
0 4
0
4
moinyuso96
Description                     Recorded value for [Turn On Test 123]Recorded value for [Turn On Test 456]Execute all...
by moinyuso96 Path Finder in Splunk Search 05-17-2021
0 4
0
4
_Mauro_Costa_
Hello,I have a table of items and I need to convert the results in the rows "pa_name" and "pa_valor" to columns and k...
by _Mauro_Costa_ Explorer in Splunk Search 05-17-2021
0 3
0
3
DjNaGuRo
Hello everyone,I'm new in Splunk. My issue is to make an EXCEPT SQL query in SPL. Something like the following:  inde...
by DjNaGuRo Explorer in Splunk Search 05-17-2021
0 8
0
8
jeyakumar8
Hi,I'm using   | sim flow query="<My query>" format=table org_id=<ID> resolution=900000  For my metric query, above q...
by jeyakumar8 Loves-to-Learn Everything in Splunk Search 05-17-2021
0 1
0
1
kig121
Hi All,I am a newbie in Splunk world and looking for some help in structuring my query.I have an index with data like...
by kig121 Loves-to-Learn Lots in Splunk Search 05-16-2021
0 5
0
5
yuming1127
Hi, i'm looking for a solution which only show the last and last-1 result using stats or streamstats function.  Aim i...
by yuming1127 Path Finder in Splunk Search 05-16-2021
0 3
0
3
or1515
Hi! There is another way to create a query with EventID ("user-created") and then EvendID ("user deleted") in 5 min?I...
by or1515 Loves-to-Learn Everything in Splunk Search 05-16-2021
0 1
0
1
Shan
Hi All,I have a requirement to use foreach with search filter.Example fileds 192345_Employeestatus,207754_Employeesta...
by Shan Builder in Splunk Search 05-16-2021
0 6
0
6
mamoSplunk
Hi all,I would like extract from intranet weblog (IIS log) top pages grouped by departments to see which pages are mo...
by mamoSplunk Explorer in Splunk Search 05-16-2021
0 4
0
4
Sidmi09
To obtain "list of suspicious IP addresses that attempt to make an unauthorized web connection having a duration of l...
by Sidmi09 New Member in Splunk Search 05-16-2021
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...