Splunk Search

Splunk Search
Community Activity
timyong80
 Hello,How can I extract multiple values from a string after each slash? For example below, I would like to extract f...
by timyong80 Explorer in Splunk Search 05-04-2021
0 6
0
6
stevenulbrich
Hello - I am looking for recommendations on combining 2 searches that use the same Lookup CSV but different columns i...
by stevenulbrich Explorer in Splunk Search 05-04-2021
0 0
0
0
stevenulbrich
Hello - I have Splunk report that was generated 5 years ago.  I was looking for advice.  Can it be updated to work be...
by stevenulbrich Explorer in Splunk Search 05-04-2021
0 3
0
3
cindygibbs_08
Hello friends,Thank you so much for your help in advance.I have a field named "ERROR_COLAB" in which a series of resp...
by cindygibbs_08 Communicator in Splunk Search 05-04-2021
0 2
0
2
dbashyam
Hi, I am trying to extract the following [04 May 2021 13:13:59,786] [Nsh-Proxy-Thread-93] [INFO] [abc@abc.com:abc:10....
by dbashyam Explorer in Splunk Search 05-04-2021
0 3
0
3
Nidd
I have a list of unstructured logs like below for which I have to extract certain fields. Tried using "Extract fields...
by Nidd Path Finder in Splunk Search 05-04-2021
0 2
0
2
mah
Hi,I have a table like that : testtotalproductA_xxxxproductA_zzzzproductB_xxxxproductB_zzzz1220.230.360.440.55 What I...
by mah Builder in Splunk Search 05-04-2021
0 4
0
4
Matioski7
Hello,I'm trying to show this event as a table:  2021-05-04 11:28:56.722, TIME="2021-05-04 11:28:56.722", ID="0a7a270...
by Matioski7 Explorer in Splunk Search 05-04-2021
0 4
0
4
aaa2324
Hi Team,I would like to compare below 5 different columns and get one more column as a count.category code  text  cou...
by aaa2324 Explorer in Splunk Search 05-04-2021
0 3
0
3
bz
I am trying to get an alert to recognize a lookup file with a whitelist for external devices.  Some devices I don't c...
by bz New Member in Splunk Search 05-04-2021
0 0
0
0
aquinojason
Hi,I have a list of accounting codes in a lookup table. I use that to identify applications under that accounting cod...
by aquinojason Path Finder in Splunk Search 05-04-2021
0 2
0
2
Flo-Paris
Hello,i searched few hours how to extract the RULE_NAME field from my Firewall logs without success.RULE_NAME is at t...
by Flo-Paris Explorer in Splunk Search 05-04-2021
0 3
0
3
pacifikn
Greetings!!Dear all!Hope you are well. I need your support on how to calculate the size of events we received per day...
by pacifikn Communicator in Splunk Search 05-04-2021
0 4
0
4
aaa2324
How to compare the incoming data with dynamic date and time with the lookup table, examplei have incoming data in bel...
by aaa2324 Explorer in Splunk Search 05-03-2021
0 3
0
3
Nith1
Hi TeamI have the required data in one of the fields but the logs are not in order how can i extract the required dat...
by Nith1 Path Finder in Splunk Search 05-03-2021
0 1
0
1
pjohnson1
I am working on time series data and would like to detect these type of trough's in the graphs.   The y axis is netwo...
by pjohnson1 Path Finder in Splunk Search 05-03-2021
0 4
0
4
ajmanish
I am trying to find the average time duration in hh:mm from the data in one column. Below is the search query which g...
by ajmanish New Member in Splunk Search 05-03-2021
0 1
0
1
nortonjco
index=environment sourcetype=infinity_thermostat < shows all the extracted fields and values under "Interesting Field...
by nortonjco Explorer in Splunk Search 05-03-2021
0 2
0
2
klim
I'm trying to use a case statement and assign part of a field for each case statement. For example case(len(field)=5,...
by klim Path Finder in Splunk Search 05-03-2021
0 2
0
2
jcorcoran508
Greetings -I do have the TA for nix.I spend a couple of hours scouring all my resources and looking at the TA_nix  wh...
by jcorcoran508 Path Finder in Splunk Search 05-03-2021
0 1
0
1
sl4dy
I have submitted the following query via Python SDK: earliest=-1d@d latest=@d | eval size_B=len(_raw) | eval mytime=...
by sl4dy Explorer in Splunk Search 05-03-2021
0 4
0
4
danielbb
Within _raw we have this segment - SQL_TEXT="grant create database link to aaa01, bbb02, yyy03, xxx04", We would like...
by danielbb Motivator in Splunk Search 05-03-2021
0 4
0
4
bmendez0428
The error I receive with this search causes me this error. Error in 'dbxquery' command: External search command exi...
by bmendez0428 Explorer in Splunk Search 05-03-2021
0 2
0
2
Janani_Krish
Currently I am using below query to run my search to get the common event in tc and email,|inputlookup tc | search ty...
by Janani_Krish Path Finder in Splunk Search 05-03-2021
0 17
0
17
sh_tavousi
Hi,Is there any way to backup/export regex saved in extracted fields as we want to use new instance as a search head ...
by sh_tavousi Explorer in Splunk Search 05-03-2021
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...