Splunk Search

Splunk Search
Community Activity
yuming1127
Hi, i'm looking for a solution which only show the last and last-1 result using stats or streamstats function.  Aim i...
by yuming1127 Path Finder in Splunk Search 05-16-2021
0 3
0
3
or1515
Hi! There is another way to create a query with EventID ("user-created") and then EvendID ("user deleted") in 5 min?I...
by or1515 Loves-to-Learn Everything in Splunk Search 05-16-2021
0 1
0
1
Shan
Hi All,I have a requirement to use foreach with search filter.Example fileds 192345_Employeestatus,207754_Employeesta...
by Shan Builder in Splunk Search 05-16-2021
0 6
0
6
mamoSplunk
Hi all,I would like extract from intranet weblog (IIS log) top pages grouped by departments to see which pages are mo...
by mamoSplunk Explorer in Splunk Search 05-16-2021
0 4
0
4
Sidmi09
To obtain "list of suspicious IP addresses that attempt to make an unauthorized web connection having a duration of l...
by Sidmi09 New Member in Splunk Search 05-16-2021
0 3
0
3
keiran_harris
Hey Splunk Gurus! have been going in circles trying to get a query going to give me a pie chart on what I would have ...
by keiran_harris Path Finder in Splunk Search 05-15-2021
0 6
0
6
srinathd
Hi Srinath, Srinath USER1 IND0010001 USER2 IND0010002 USER3 IND0010003 ...
by srinathd Contributor in Splunk Search 05-15-2021
0 6
0
6
rahul_n
Hi. I am trying to edit a source code of a splunk panel such that, the token should only when the user clicks on a pa...
by rahul_n Explorer in Splunk Search 05-15-2021
0 2
0
2
oshirnin
Hello, everybody!Does anybody can help with such an easy problem as counting events in summary index?I have a summary...
by oshirnin Path Finder in Splunk Search 05-15-2021
0 6
0
6
DLT76
I have logs with data in two fields: _raw and _time. I want to search the _raw field for an IP in a specific pattern ...
by DLT76 Path Finder in Splunk Search 05-14-2021
0 10
0
10
puneetgureja
new to Splunk so want to know how I can fetch total time take per request applog.msg=XXXX_Logs,CorrelationId=XXXXXXXX...
by puneetgureja Engager in Splunk Search 05-14-2021
0 1
0
1
Als123
Hi Team,I am having a question regarding log details in Splunk.1.How response time is generating in logs.?2.From wher...
by Als123 Explorer in Splunk Search 05-14-2021
0 6
0
6
christian75
When i try to extract BiosMake fields in my log file with field extraction (Mode regex).I have this:Error in 'rex' co...
by christian75 Engager in Splunk Search 05-14-2021
0 3
0
3
majbo
Hi,Any suggestion about how can I collect avgLoad1m for each cpu core (hosts with multi-core cpu) by Splunk_TA_nix ap...
by majbo Explorer in Splunk Search 05-14-2021
0 0
0
0
MeMilo09
Hey There, I have seen the Splunk. com answers and the rex cheat sheets online. However, I cant seem to get rex comma...
by MeMilo09 Path Finder in Splunk Search 05-13-2021
0 3
0
3
PotatoHero
Hi I would like to remove some Data from my search (only want AreaOIC), however, I tried to do Data = AreaOIC or Data...
by PotatoHero Loves-to-Learn Lots in Splunk Search 05-13-2021
0 15
0
15
LKrieger
Hi Splunkers, Iam a beginner at splunk. So I managed to get all Data from Aida64 into Splunk. That does include Tempe...
by LKrieger Explorer in Splunk Search 05-13-2021
0 5
0
5
ChrisFontana
Hello,This is my first question here, since I don't know how to look for the solution. I tried to resolve this case o...
by ChrisFontana Loves-to-Learn Lots in Splunk Search 05-13-2021
0 0
0
0
user93
Hi,So, I want to count the number of visitors to a site, but because of the logging mechanism, I get many events per ...
by user93 Communicator in Splunk Search 05-13-2021
0 5
0
5
wilcomply13
I have a single user that is being affected by a strange issue where they are able to search, however the event table...
by wilcomply13 Explorer in Splunk Search 05-13-2021
0 0
0
0
elpaisa
Hi all,I have server errors and success logs in the data, i want to get the percent of failures out of the total coun...
by elpaisa Splunk Employee Splunk Employee in Splunk Search 05-13-2021
0 1
0
1
pgreer_splunk
I have a use case where there are over 50+ lookup files that I need to 'sync' between one app context and another. Th...
by pgreer_splunk Splunk Employee Splunk Employee in Splunk Search 05-12-2021
0 2
0
2
munisb
Hi,I have this query where I am trying to compare two csv files and have the assets data mergedCSV1hostiposabc.domain...
by munisb Explorer in Splunk Search 05-12-2021
0 0
0
0
rockb
I am trying to use Splunk to review windows events that have been exported from disconnected systems.  I have all the...
by rockb Explorer in Splunk Search 05-12-2021
0 0
0
0
rockb
I just installed splunk and imported my license.I have a series of Windows event viewer files that have been exported...
by rockb Explorer in Splunk Search 05-12-2021
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...