Splunk Search

Splunk Search
Community Activity
splunkerer
I have a data set as seen below.exec                   arguments/bin/shsh-cuname -p ** /dev/null/sbin/ldconfig/bin/sh...
by splunkerer Path Finder in Splunk Search 05-20-2021
0 4
0
4
RonD
I am creating a search that detects compliance received from palo alto signatureswe are receving 4 sets of dates:app-...
by RonD Explorer in Splunk Search 05-20-2021
0 2
0
2
Godspeed_74
I am trying to fill the null values and using a datamodel. I want to use tstats and fill null values will "Null" usin...
by Godspeed_74 Loves-to-Learn Lots in Splunk Search 05-20-2021
0 6
0
6
szukacz
Hi team,I'm trying to build a search which will search for the alerts which have been triggered for a hosts during sp...
by szukacz Engager in Splunk Search 05-20-2021
0 3
0
3
Sangu
HiI need to extract hostname or IP address from raw log. My log looks like below:somerandometest  host: abc@email.com...
by Sangu Explorer in Splunk Search 05-20-2021
0 2
0
2
jugarugabi
Hi, I have a csv file that is updated by a script once a minute. The output is similar to: time,queuename,vpn,last-me...
by jugarugabi Path Finder in Splunk Search 05-20-2021
0 4
0
4
srinivasgowda
Hello team, I am trying to ignore the value "Total" if its concurrent Os_type matches "Linux" Below is what I tried.|...
by srinivasgowda Explorer in Splunk Search 05-20-2021
0 3
0
3
stephenreece78
hi all, newbee question here but i can't seem to find an answer. I am trying to create a timechart table grouped tabl...
by stephenreece78 Engager in Splunk Search 05-20-2021
0 2
0
2
timrich66
I've been searching and trying options for a couple of days now with this search and cannot find a solution.I am usin...
by timrich66 Communicator in Splunk Search 05-20-2021
0 10
0
10
yuanliu
I have an attribute that is determined by two inputs, one with many possible values, the other few.  I can enlist the...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2021
1 4
1
4
teewenjie22
How to convert below _time    Server      col1     col2       col38am       SerA          1           2             3...
by teewenjie22 Engager in Splunk Search 05-19-2021
0 1
0
1
payton_tayvion
I'm currently trying to create a search that look for employees hired within the last 3 months, but I keep getting al...
by payton_tayvion Path Finder in Splunk Search 05-19-2021
0 1
0
1
malanirishi
Problem: I want to ignore all results from search that have message: <4 digits> in them. For example: { timestamp: 20...
by malanirishi New Member in Splunk Search 05-19-2021
0 1
0
1
chirsf
I'm looking for a way to numerically sort a multivalue field without expanding the field, sorting and then recombinin...
by chirsf Explorer in Splunk Search 05-19-2021
1 3
1
3
mkroczak
Hi there,I'm just a basic user of Splunk in my company and I have 0 experience with programming or SQL please don't g...
by mkroczak Loves-to-Learn in Splunk Search 05-19-2021
0 1
0
1
thaghost99
i would need help splitting this output into its own line.if we can even remove the quotes, comma, curly brackets and...
by thaghost99 Path Finder in Splunk Search 05-19-2021
0 4
0
4
MrPink99
Hi,New to splunk first time lister. Hoping for some help.I am trying to extract nested JSON data from a Widows Event ...
by MrPink99 New Member in Splunk Search 05-19-2021
0 0
0
0
jheiselman
I'm sure this has been asked before, but nothing I'm coming up with for searches against this forum have proved usefu...
by jheiselman Explorer in Splunk Search 05-19-2021
0 3
0
3
chirsf
I have an odd situation with a macro starting with an inputlookup like this: inputlookup ADcomputerslist ```logic tim...
by chirsf Explorer in Splunk Search 05-19-2021
0 3
0
3
showser
I have this result and  would like to just pull out the accountNumber 12345678021-05-19_09:36:25.459 ERROR c.r.r.m.m....
by showser New Member in Splunk Search 05-19-2021
0 1
0
1
woodcock
We have a CMDB lookup that adds 100 fields when we do not specify a limited set with "OUTPUT". More fields are added...
by Esteemed Legend in Splunk Search 05-19-2021
1 6
1
6
vinod0313
HI I have two queries ,and i need to display the results from the both the queries in one line graph report
by vinod0313 Explorer in Splunk Search 05-19-2021
0 3
0
3
MarcRiese
In an existing alert I found the following code:...| fillnull Foo value="bar"| search Foo!=none…It seems that the res...
by MarcRiese Explorer in Splunk Search 05-19-2021
0 2
0
2
MeMilo09
Hello,How can I check to see if value is in one field first, if not check the next field?I have so far the below, it ...
by MeMilo09 Path Finder in Splunk Search 05-18-2021
0 1
0
1
bspargur
Is there a way, that anyone is aware of, to timechart off of a field sumarry. I can break down the fieldsummary by ti...
by bspargur Engager in Splunk Search 05-18-2021
0 6
0
6
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors