Splunk Search

Splunk Search
Community Activity
prajwal_94
For the below query, searching for the values of 2nd occurence of earliest and latest events so that the timechart wo...
by prajwal_94 Explorer in Splunk Search 05-09-2021
0 2
0
2
hvdtol
I would kindly need some help for a query i am not able to create.I have  inputlookups as source.And i want to filter...
by hvdtol Path Finder in Splunk Search 05-09-2021
0 4
0
4
PaintItParker
Right now I have something like this: index=my_index sourcetype=my_sourcetype | rex field=message "- (?<User>\S+) -:"...
by PaintItParker Explorer in Splunk Search 05-08-2021
0 3
0
3
cboonyan
I am aiming to provide headers to my generated report. I have 3 hosts, host1 host2 and host3. My report is configured...
by cboonyan New Member in Splunk Search 05-08-2021
0 1
0
1
Matthew
Hi Guys, Wondering if you can help me out with the following. Within a single event I have to fields: 1) expiry_date2...
by Matthew Engager in Splunk Search 05-08-2021
0 2
0
2
sh_tavousi
Hi,I have 2 servers with the same names and I have installed universal forwarder on both servers. In forwarder manage...
by sh_tavousi Explorer in Splunk Search 05-08-2021
0 3
0
3
junlozhang
Let's say the data looks like:StudentNameStudentIdGradeExamDateTom1602021-04-01Jerry2702021-04-01Tom1622021-04-07Jerr...
by junlozhang Explorer in Splunk Search 05-08-2021
0 2
0
2
obais9346
Example:field1=ADOBE INC.field2=ADOBE SYSTEMS&sep1; INCORPORATEDi want to match this as both fields containing "ADOBE...
by obais9346 Engager in Splunk Search 05-07-2021
0 3
0
3
Hemnaath
Hi All,   Can any one guide me how to find, how much data is getting ingested into Splunk from a particular HEC token...
by Hemnaath Motivator in Splunk Search 05-07-2021
0 3
0
3
nikoloz04
I have O365 logs in Splunk. I want to find all shared files/folders plus display sensitivity labels of these files. A...
by nikoloz04 New Member in Splunk Search 05-07-2021
0 0
0
0
bcouavoux
Hello !My data is in this form  :_time (dd/mm/yyyy), NbRisk, SubProject, GlobalProject02/05/2021, 10 ,  SubProject1, ...
by bcouavoux Explorer in Splunk Search 05-07-2021
0 4
0
4
antonio147
Hi all,I performed an initial search, to this I added a second search, with the map command, where based on the value...
by antonio147 Communicator in Splunk Search 05-07-2021
0 3
0
3
wiar
I have a search result where each 3  follwing lines are a block I want to join to one row like:fld1 fld2 fld3 fld4A  ...
by wiar Explorer in Splunk Search 05-07-2021
0 4
0
4
Am
Hello,Two months ago we had the trial for the Enterprise version but now we are using the free version. Since the fre...
by Am Explorer in Splunk Search 05-07-2021
0 9
0
9
lancair
Desired Outcome : I am trying to create a simple timechart  to show a count of ports and the relative time line on th...
by lancair Observer in Splunk Search 05-07-2021
0 3
0
3
splunkkid
Hello,I'm struggling with the way to make efficient alerts trigger with SPL. I made splunk dashboard to visualize our...
by splunkkid Path Finder in Splunk Search 05-07-2021
0 0
0
0
renuka
<search id="base_query_filter"><query>      Index=a,sourcetype=x,eval y=A+B</query></search><search id="base_query"><...
by renuka Path Finder in Splunk Search 05-06-2021
0 2
0
2
splunkcol
I have 2 servers that receive the logs through Syslog and through a universal forwarder I forward them to 2 indexers....
by splunkcol Builder in Splunk Search 05-06-2021
0 1
0
1
cyp112
Hello,I am trying to use a subsearch on another search but not sure how to format it properlySubsearch:eventtype=pan ...
by cyp112 Engager in Splunk Search 05-06-2021
0 2
0
2
cclva
I have a dashboard which provides a handful of filter criteria, for example, `fieldA=A` and `fieldB=B`.One such crite...
by cclva Explorer in Splunk Search 05-06-2021
0 1
0
1
mdeterville
Hello SMEs:I need some assistance extracting everything between the 1st and 2nd semi-colon ; (FROM THE RIGHT)  from a...
by mdeterville Path Finder in Splunk Search 05-06-2021
0 4
0
4
Alfred
I want to extract from the Message field in the Windows Event Log just the first few words until the period - example...
by Alfred Explorer in Splunk Search 05-06-2021
0 5
0
5
billycn20
i have a working query which is monitoring the success rate based off a value called app_id. i want to extend the cur...
by billycn20 Explorer in Splunk Search 05-06-2021
0 4
0
4
billycn20
I am trying to measure our success rate on our platform. there are two individual events which we care to see in orde...
by billycn20 Explorer in Splunk Search 05-06-2021
0 6
0
6
ajtokar
I have a query where I can see in a snapshot current active users per VPN profile (group). Having a hard time being a...
by ajtokar Engager in Splunk Search 05-06-2021
0 2
0
2
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors