Splunk Search

Splunk Search
Community Activity
ebs
Hi,Bit out of my depth here but I have done an eval so we divide the events in the index by the URLs and I have 4 cat...
by ebs Communicator in Splunk Search 05-26-2021
0 0
0
0
parkz
I have a field of titles that are filled with sentences about why a test was failed in a security audit, but they are...
by parkz Explorer in Splunk Search 05-26-2021
0 1
0
1
yuanliu
I've never used |regex, but use |where match() quite often.  Is the former just syntax sugar or is there any differen...
by SplunkTrust SplunkTrust in Splunk Search 05-26-2021
0 4
0
4
dkr3500
Hi,I know there are other ways to get this through the deployment server, but I'm trying to find a SPL to get results...
by dkr3500 Path Finder in Splunk Search 05-26-2021
0 1
0
1
Daniel_Pham
I'm new to Splunk And I'm trying to build summary index i have KVStore and indexA: inputlookup spam_ip (which is Indi...
by Daniel_Pham Explorer in Splunk Search 05-26-2021
0 7
0
7
bitofrumncoke
Strangest thing. I have some Infoblox logs coming in from a Syslog-NG server where we have a UF installed. UF is succ...
by bitofrumncoke New Member in Splunk Search 05-26-2021
0 2
0
2
nm8181
Hello,I am trying to extract the full line from the raw data log matching a pattern in the line.  Sample data:blah bl...
by nm8181 Engager in Splunk Search 05-26-2021
0 2
0
2
verifi81
Hi everyone. I'm trying to get this query going  with one search but I can't seem to do that. I can only get it to wo...
by verifi81 Path Finder in Splunk Search 05-26-2021
0 10
0
10
sbrewerton
HelloI have a query that examins events can outputs how many of each level of event there areindex=* eval level=lower...
by sbrewerton Engager in Splunk Search 05-26-2021
0 1
0
1
sangs8788
HiI have a query which results me data in the below format,I am trying to put out a table assigning priority based on...
by sangs8788 Communicator in Splunk Search 05-26-2021
0 0
0
0
onur
Hi,In our organization, some teams would like to see the new index logs. To explain, they want to see who created a n...
by onur Explorer in Splunk Search 05-26-2021
0 1
0
1
auaave
Hi guys, I am making a dashboard with Error Duration per RobotId. Since the duration is in seconds, I rounded it to ...
by auaave Communicator in Splunk Search 05-26-2021
0 10
0
10
JiachengWei
Hi Guys, I'd like to calculate the time delta. Here is the sample:_time                                    _raw 2021-...
by JiachengWei Engager in Splunk Search 05-26-2021
0 5
0
5
Learner
Hi everyone, below is my sample query index=xyz source=ABC | stats count If I schedule this search then result have t...
by Learner Path Finder in Splunk Search 05-26-2021
0 1
0
1
Learner
Hi everyone,index=xyz source="something" |stats earliest(_time) as minTime latest(_time) as maxTime values(activityNa...
by Learner Path Finder in Splunk Search 05-26-2021
0 4
0
4
KongJian
Scenarioexample Index:Index=os, Ingesteddata _time, type, id08:00,A,108:10,A,208:11,A,308:12,A,408:13,A,509:00,B,109:...
by KongJian Engager in Splunk Search 05-26-2021
0 3
0
3
sashaank
So I am trying to run a splunk search using Splunk REST API which finds a list of triggered alerts.  | rest /services...
by sashaank Observer in Splunk Search 05-26-2021
0 0
0
0
syedabuthahir
How to change a span of 1 week time to start from Monday to friday usually span=1w it will show data from monday 00:0...
by syedabuthahir Explorer in Splunk Search 05-25-2021
0 4
0
4
klim
I am trying to set up a restricted search for a role so that they can only see data when a field1=customer01. The def...
by klim Path Finder in Splunk Search 05-25-2021
0 3
0
3
ebs
Hi.I've created the following macro: sessionCount(1)With this definition:datamodel Test summariesonly=true search | s...
by ebs Communicator in Splunk Search 05-25-2021
0 4
0
4
kedjjang
WARN DistributedPeer - Peer:https:/:8089 Unable to get server info from https://:8089/services/server/info due to: Co...
by kedjjang Path Finder in Splunk Search 05-25-2021
1 2
1
2
ekucevic
I have events in my logs. I want to capture "temp" and table itreceived_time="2021-05-25T15:51:22.181+00:00"] 37 poll...
by ekucevic Loves-to-Learn Everything in Splunk Search 05-25-2021
0 1
0
1
Krapht
Going to be very tough to explain but I'll give it my best shot. I have some fields I'm trying to report on, IP and I...
by Krapht Explorer in Splunk Search 05-25-2021
0 4
0
4
vl951f
I have a summary index for hourly event count of a feed. The feed has some hours with event count empty. How can I ge...
by vl951f Path Finder in Splunk Search 05-25-2021
0 7
0
7
nangrosso
I was asked to " update a search to append a final ' | regex PatternStringMatch="[A-Z]" query that will look for anyt...
by nangrosso Engager in Splunk Search 05-25-2021
0 6
0
6
Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...