Splunk Search

Splunk Search
Community Activity
ethanthomas
The requirement is, there is a single index . Data in three different format and there is an InputType coming in the ...
by ethanthomas Path Finder in Splunk Search 04-19-2021
0 3
0
3
kesrich
I have a log that that has multiple utc times listed. The logs are ingested into Splunk and I have created a field ex...
by kesrich Explorer in Splunk Search 04-19-2021
0 3
0
3
andres91302
Hello everyone!I'm trying to create a time chart of a variable that I have to compute as a global percentage between ...
by andres91302 Communicator in Splunk Search 04-19-2021
0 4
0
4
valpravin
Hi Teamcan you please help in extracting the  123456 from following stringhello world  \"employee\":123456 
by valpravin Engager in Splunk Search 04-19-2021
0 1
0
1
MeMilo09
Hi All, I am trying to replace gentimes from my query due to slowness. I have read that if I add the field to an auto...
by MeMilo09 Path Finder in Splunk Search 04-19-2021
0 0
0
0
dwharam
For inventory management purposes, I have been running the below splunk search for years.  It first checks Remedy and...
by dwharam New Member in Splunk Search 04-19-2021
0 0
0
0
Dheeru
Hi,I am new to splunk and I am trying to create a dashboard with optimizing the independent queries and by using all ...
by Dheeru Engager in Splunk Search 04-19-2021
0 1
0
1
alancalvitti
What's a scalable to extract key-value pairs where the value matches via exact or substring match but the field is no...
by alancalvitti Path Finder in Splunk Search 04-19-2021
0 11
0
11
raultav
Hi, guys!I need to get the difference in hours between _time and now(). How can I get this number?
by raultav Engager in Splunk Search 04-19-2021
0 1
0
1
andres91302
Hello Friends, I'm trying to generate a table that summarizes the total count of events A, B and C as follows search ...
by andres91302 Communicator in Splunk Search 04-19-2021
0 2
0
2
teedilo
We have some issues with line breaking such that we have events that often consist of multiple logical events, or the...
by teedilo Path Finder in Splunk Search 04-19-2021
0 2
0
2
raultav
Hi, guys!I have an event table, which has a field called "COD SERIE CEI". I need to get the "COD SERIE CEI" which has...
by raultav Engager in Splunk Search 04-19-2021
0 3
0
3
rseri17
Can you please help with extracting the fields from the below sample log. I am unable to escape the "'// &" '" in the...
by rseri17 Explorer in Splunk Search 04-19-2021
0 6
0
6
Traer001
Hello!I have two searches that return separate data but have a common field. I am trying to filter my first search by...
by Traer001 Path Finder in Splunk Search 04-19-2021
0 1
0
1
ayadav38
Hey there,I  created a field extraction from UI,using regular expression method,where regular expression got created ...
by ayadav38 Engager in Splunk Search 04-19-2021
0 1
0
1
sudo_su
Hello Splunkers,I would like to create a timechart for status. The data only comes when there's an update, so general...
by sudo_su Engager in Splunk Search 04-19-2021
0 2
0
2
nsantiago17
I'm trying to run this query below: (index=A sourcetype=jobs_info JOB_NAME IN (ACQUA)) OR (index=B sourcetype=FIRE) ...
by nsantiago17 Explorer in Splunk Search 04-19-2021
0 2
0
2
jacobmcn67
Hi all, I am trying to create a fourth column which would display all values between a given time range in the single...
by jacobmcn67 New Member in Splunk Search 04-18-2021
0 1
0
1
mariannedave
I have this XML data in one event but there are multiple transactions with same fieldnames . We need to display them ...
by mariannedave Explorer in Splunk Search 04-18-2021
0 2
0
2
shinobu
I have stored data in 2 indexes. One Index has a attribute which can be a substring of the second index _raw event da...
by shinobu Explorer in Splunk Search 04-18-2021
0 2
0
2
surejsajeev
Hi,I have a csv file uploaded in the location /opt/splunk/etc/apps/search/lookups/. My transforms file is in /opt/spl...
by surejsajeev Explorer in Splunk Search 04-18-2021
0 1
0
1
edoardo_vicendo
Hello,Suppose I have raw records like this: user=blabla,org_L1=12345,org_L2=777,department=7890 user=testtt,org_L1=34...
by edoardo_vicendo Builder in Splunk Search 04-17-2021
0 2
0
2
lohit
I am facing problems with restoring splunk. I require the searches, indexed data and users created on one installati...
by lohit Path Finder in Splunk Search 04-17-2021
0 6
0
6
SamHTexas
How are AWS logs get ingested into Splunk Enterprise or ES? Please advise the steps.
by SamHTexas Builder in Splunk Search 04-17-2021
0 2
0
2
jlph
I would like to run a query for any user additions to privileged Active Directory groups. I am storing the AD groups ...
by jlph Loves-to-Learn in Splunk Search 04-17-2021
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...