Splunk Search

Splunk Search
Community Activity
nwoolley
Thats all i need the method for cloning alerts as we migrate 
by nwoolley Engager in Splunk Search 04-07-2021
0 5
0
5
robertlynch2020
Hi My iplocation is not working at all, what am i missing? index=_internal sourcetype=splunkd_ui_access | stats cou...
by robertlynch2020 Influencer in Splunk Search 04-07-2021
0 4
0
4
dishantgniit
Hello Team, I would like to setup Splunk email alert when Log Statement 2 and Log Statement 3 doesn’t execute due to ...
by dishantgniit New Member in Splunk Search 04-07-2021
0 3
0
3
stevenfharris
I am trying to search for log entries that contain the following: KeyError: 'ABC_DEF'The following work, but will fin...
by stevenfharris New Member in Splunk Search 04-07-2021
0 1
0
1
andres91302
Hello Talented People of the wordl!I hope you are having a great day, I wish to know if there is a way to have a YES ...
by andres91302 Communicator in Splunk Search 04-07-2021
0 3
0
3
chrisboy68
Hi,  Been struggling to get Workload Admission Rules working properly. After a bunch of testing and monitoring with t...
by chrisboy68 Contributor in Splunk Search 04-07-2021
0 2
0
2
jerinvarghese
Hi Team,I am having few devices located across the globe and want to monitor only during their Business hour timings ...
by jerinvarghese Communicator in Splunk Search 04-07-2021
0 0
0
0
johefu
Hello All,I am trying to get a total number of bytes/MB/GB  uploaded per application in Splunk.Can't seem to find the...
by johefu Loves-to-Learn in Splunk Search 04-07-2021
0 1
0
1
uagraw01
As per below screen shot i created toggle tabs and when i used the in by below panel results are not poplutating.Plea...
by uagraw01 Motivator in Splunk Search 04-07-2021
0 0
0
0
mrovira
Hello,I've around questions and answers but I cannot find the one I need.I'm selecting previous week in the time rang...
by mrovira Engager in Splunk Search 04-07-2021
0 3
0
3
zoe
Hi, I have 3 products 1, 2, and 3, each of them contain several elements a, b c, d. Each product has different specif...
by zoe Path Finder in Splunk Search 04-07-2021
0 4
0
4
aaa2324
What is the difference between earliest=-5min and earliest=-5min@min
by aaa2324 Explorer in Splunk Search 04-07-2021
0 1
0
1
sanketas
Team,I have been using this below commands to verify whether particular print queues have printed from the print serv...
by sanketas New Member in Splunk Search 04-06-2021
0 1
0
1
splunkpaterd2
Good morning, suppose I have the following entries in my file :BEGIN abcdefEND;BEGIN xyzEND;***I want to search for t...
by splunkpaterd2 Explorer in Splunk Search 04-06-2021
0 6
0
6
sdkp03
I have a lookup file with 3 fields - source, status, timestamp.  Timestamp is saved as per below:eval timestamp=strft...
by sdkp03 Communicator in Splunk Search 04-06-2021
0 5
0
5
alancalvitti
We need to run the same query over a list of values (10k to 100k) without knowing the exact key across various indexe...
by alancalvitti Path Finder in Splunk Search 04-06-2021
0 5
0
5
adidibra
Hello, I need to move old logs for a specific logsource(host) to be indexed in another splunk cluster. When I use the...
by adidibra Engager in Splunk Search 04-06-2021
0 0
0
0
adidibra
Hello,I am getting the following error while searching in splunk.Could not load lookup=LOOKUP-cisco_pix_severity_look...
by adidibra Engager in Splunk Search 04-06-2021
0 2
0
2
Traer001
Hi all, I'm trying to use a transaction to get multiple pairs of events (the selection and release of a node). So I h...
by Traer001 Path Finder in Splunk Search 04-06-2021
0 4
0
4
zoe
Hi, I have:index=............|stats avg(test) by OrderNr Sub_OrderNrBut I want to something like this:OrderNr       S...
by zoe Path Finder in Splunk Search 04-06-2021
0 1
0
1
deees
I'm tasked with auditing syslog messages from some network devices for suspicious activity. I can use the IN operator...
by deees New Member in Splunk Search 04-06-2021
0 1
0
1
satyajit7
How to print a splunk default variable in search query? Actually I have two variables like $job.earliestTime$ and $jo...
by satyajit7 Explorer in Splunk Search 04-06-2021
0 4
0
4
bharat149
I have a log of the form"Associated integration for customer AAA is Integration{id=1865, clientID}, carrying out deac...
by bharat149 Explorer in Splunk Search 04-06-2021
0 1
0
1
phanichintha
Hello!As shown in the below picture, those are the events with a timestamp. I want when a "Kafka" service or "Jps" se...
by phanichintha Path Finder in Splunk Search 04-06-2021
0 14
0
14
luna
Hi Guys, How can I query an automatic lookup? Now, this is not the fields created through  an automatic lookup, but t...
by luna Explorer in Splunk Search 04-05-2021
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...