Splunk Search

Splunk Search
Community Activity
fdevera
I'm trying to dump this info into a scheduled lookup but these are just azuread UPNs that are appearing in the logs f...
by fdevera Path Finder in Splunk Search 02-20-2021
0 1
0
1
edfigue
Hi, I'm trying to calculate the standard deviation for range of time to create an alert an know when the total of tra...
by edfigue Engager in Splunk Search 02-20-2021
0 1
0
1
klim
I have this query index=some_index | timechart limit=15 useOther=false count by acct_id and it needs to run up to a t...
by klim Path Finder in Splunk Search 02-20-2021
0 7
0
7
klim
I know you can use a search with format to return the results of the subsearch to the main query. Like for example I ...
by klim Path Finder in Splunk Search 02-20-2021
0 1
0
1
treverce
I just moved over to a docker Splunk set up and im having an issue where Splunk thinks im in UTC even when the prefer...
by treverce Explorer in Splunk Search 02-20-2021
0 0
0
0
ForeverNoob2
Hi. I am new to Splunk. I want to create a Pie Chart that consists of a particular type of event as a percentage of a...
by ForeverNoob2 Engager in Splunk Search 02-20-2021
0 2
0
2
hishamjan
Hi, I have two instances of Asterisk running in my production environment. The third server has a Splunk indexer inst...
by hishamjan Explorer in Splunk Search 02-20-2021
0 1
0
1
Astorn
I have some forwarders which are sending logs to indexers in another subnets and i have connected search head to thes...
by Astorn Loves-to-Learn in Splunk Search 02-20-2021
0 1
0
1
splunkcol
 I am performing a query to generate a chart.The query time range is the previous 7 days, when I use this time range ...
by splunkcol Builder in Splunk Search 02-20-2021
0 1
0
1
flyingpiglet
HiI need to calculate a sum of different counters from several sourcetypes. They are located in one index, but simple...
by flyingpiglet Engager in Splunk Search 02-20-2021
0 6
0
6
alexspunkshell
 index=graphsecurityalert having information's about all attacks in "title" fieldindex=zscaler having information's a...
by alexspunkshell Contributor in Splunk Search 02-20-2021
0 1
0
1
tscroggins
In Splunk Enterprise 8.1, when using chart with spans containing fractional values of 0.54, 0.95, and others that res...
by tscroggins Champion in Splunk Search 02-20-2021
1 0
1
0
REACHGPRAVEEN
Hello , Please help on the below:it should look like below 2 rowssearch by employeeid(hyperlink)search by app(hyperli...
by REACHGPRAVEEN Explorer in Splunk Search 02-19-2021
0 1
0
1
HattrickNZ
How do I get the average of all the individual rows (like the addtotals but average) and append those values as a col...
by HattrickNZ Motivator in Splunk Search 02-19-2021
0 7
0
7
shrogers
Hi All,Need some assistance combining 3 queries in tabular form so I can export them to a lookup table.I'm also tryin...
by shrogers Loves-to-Learn Everything in Splunk Search 02-19-2021
0 3
0
3
v33jay
I have a log with the following entries among others and I am looking for a way to display the top 2 times by each ac...
by v33jay Explorer in Splunk Search 02-19-2021
0 5
0
5
Astorn
Hello,i have problem with dnslookup, i want to check what is the hostname of the ip, the ip is the ip address of host...
by Astorn Loves-to-Learn in Splunk Search 02-19-2021
0 3
0
3
crlunde
I'm looking to do some alerting or analysis to help troubleshoot lag time and logging. I'd like to compare the _index...
by crlunde Loves-to-Learn Everything in Splunk Search 02-19-2021
0 1
0
1
vinod0313
I have two queries and i want to append those two queries and i need new column for separationfor ex:i got below resu...
by vinod0313 Explorer in Splunk Search 02-19-2021
0 1
0
1
sc0tt
I have a field that is more than 10,000 characters. I updated props.conf to include [source::log.txt] TRUNCATE=20000...
by sc0tt Builder in Splunk Search 02-19-2021
0 8
0
8
iamarkaprabha
Hi All, I was trying to filter out the usernames which contains underscore in splunk. I had tried with regex Accoun...
by iamarkaprabha Contributor in Splunk Search 02-19-2021
0 3
0
3
willadams
My scenario is that I am trying to alert in the event where a user has been provided to an application but that same ...
by willadams Contributor in Splunk Search 02-19-2021
0 2
0
2
nits
I have one  query which looks like:Query1:index=test "TestRequest" | dedup _time | rex field=_raw "Price\":(?<price>....
by nits Explorer in Splunk Search 02-18-2021
0 4
0
4
vashodha
Hello,I have log in the format "2021-02-18T16:17:12,189Z [main] INFO logname -streamstart-k1:V1,K2:V2,K3:V3,streamsto...
by vashodha Loves-to-Learn Lots in Splunk Search 02-18-2021
0 4
0
4
rbachu1
Hi everyone, I have the below string.isadhakdahdj asdh, hosadhao activity=Follow Up, entryName=Initial Outreach, asas...
by rbachu1 Explorer in Splunk Search 02-18-2021
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors