Splunk Search

Splunk Search
Community Activity
Dheeru
Hi,I am new to splunk and I am trying to create a dashboard with optimizing the independent queries and by using all ...
by Dheeru Engager in Splunk Search 04-19-2021
0 1
0
1
alancalvitti
What's a scalable to extract key-value pairs where the value matches via exact or substring match but the field is no...
by alancalvitti Path Finder in Splunk Search 04-19-2021
0 11
0
11
raultav
Hi, guys!I need to get the difference in hours between _time and now(). How can I get this number?
by raultav Engager in Splunk Search 04-19-2021
0 1
0
1
andres91302
Hello Friends, I'm trying to generate a table that summarizes the total count of events A, B and C as follows search ...
by andres91302 Communicator in Splunk Search 04-19-2021
0 2
0
2
teedilo
We have some issues with line breaking such that we have events that often consist of multiple logical events, or the...
by teedilo Path Finder in Splunk Search 04-19-2021
0 2
0
2
raultav
Hi, guys!I have an event table, which has a field called "COD SERIE CEI". I need to get the "COD SERIE CEI" which has...
by raultav Engager in Splunk Search 04-19-2021
0 3
0
3
rseri17
Can you please help with extracting the fields from the below sample log. I am unable to escape the "'// &" '" in the...
by rseri17 Explorer in Splunk Search 04-19-2021
0 6
0
6
Traer001
Hello!I have two searches that return separate data but have a common field. I am trying to filter my first search by...
by Traer001 Path Finder in Splunk Search 04-19-2021
0 1
0
1
ayadav38
Hey there,I  created a field extraction from UI,using regular expression method,where regular expression got created ...
by ayadav38 Engager in Splunk Search 04-19-2021
0 1
0
1
sudo_su
Hello Splunkers,I would like to create a timechart for status. The data only comes when there's an update, so general...
by sudo_su Engager in Splunk Search 04-19-2021
0 2
0
2
nsantiago17
I'm trying to run this query below: (index=A sourcetype=jobs_info JOB_NAME IN (ACQUA)) OR (index=B sourcetype=FIRE) ...
by nsantiago17 Explorer in Splunk Search 04-19-2021
0 2
0
2
jacobmcn67
Hi all, I am trying to create a fourth column which would display all values between a given time range in the single...
by jacobmcn67 New Member in Splunk Search 04-18-2021
0 1
0
1
mariannedave
I have this XML data in one event but there are multiple transactions with same fieldnames . We need to display them ...
by mariannedave Explorer in Splunk Search 04-18-2021
0 2
0
2
shinobu
I have stored data in 2 indexes. One Index has a attribute which can be a substring of the second index _raw event da...
by shinobu Explorer in Splunk Search 04-18-2021
0 2
0
2
surejsajeev
Hi,I have a csv file uploaded in the location /opt/splunk/etc/apps/search/lookups/. My transforms file is in /opt/spl...
by surejsajeev Explorer in Splunk Search 04-18-2021
0 1
0
1
edoardo_vicendo
Hello,Suppose I have raw records like this: user=blabla,org_L1=12345,org_L2=777,department=7890 user=testtt,org_L1=34...
by edoardo_vicendo Builder in Splunk Search 04-17-2021
0 2
0
2
lohit
I am facing problems with restoring splunk. I require the searches, indexed data and users created on one installati...
by lohit Path Finder in Splunk Search 04-17-2021
0 6
0
6
SamHTexas
How are AWS logs get ingested into Splunk Enterprise or ES? Please advise the steps.
by SamHTexas Builder in Splunk Search 04-17-2021
0 2
0
2
jlph
I would like to run a query for any user additions to privileged Active Directory groups. I am storing the AD groups ...
by jlph Loves-to-Learn in Splunk Search 04-17-2021
0 1
0
1
biers04
I am working on statsing firewall data into a sparkline.  However, when I run the search, the sparkline caps out at 1...
by biers04 Explorer in Splunk Search 04-16-2021
0 0
0
0
aquinojason
Hi,Is there a way from a dashboard perspective that I present a chart from 2 big groups and if I click on the legend ...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 5
0
5
aquinojason
Hi, Below is a result of a lookup command, how do I exclude the other information if I based in on BusinessUnit, For ...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 4
0
4
Sathya0Q
 I recently started learning Splunk . Could you help me!!Have list of users and particular looking for search query t...
by Sathya0Q Engager in Splunk Search 04-16-2021
0 1
0
1
sumandevops
Example:My search is index=* source=*xyz*I am getting an event with plenty of lines in string formatI want to display...
by sumandevops Engager in Splunk Search 04-16-2021
0 9
0
9
aquinojason
Hi, I am trying to do the following:1. Using this | inputlookup Application.csv where BusinessUnit = BU1, it will fil...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...