Splunk Search

Splunk Search
Community Activity
viswatejabolla
Hi All,I have field called stepName which will have below three values.TextResource.getFirstLineTextResource.getSecon...
by viswatejabolla New Member in Splunk Search 01-29-2021
0 3
0
3
marceloalejandr
Greetings,I've 2 Lookup (csv) files, one generated from index _internal (approx 15k events) and another generated fro...
by marceloalejandr Path Finder in Splunk Search 01-29-2021
0 6
0
6
dnsGuy314
I have a current alert that is working as expected to capture a log event that states a service is down. We have sta...
by dnsGuy314 New Member in Splunk Search 01-29-2021
0 10
0
10
dpwtheitguy
All, I have this search here and it's pretty slow. Any recommendations to speed it up? Currently 250.249 seconds and ...
by dpwtheitguy Loves-to-Learn Lots in Splunk Search 01-28-2021
0 2
0
2
deepuhassan
Hi,I have the below query which does the search on two different sources in the same index and join the results based...
by deepuhassan Explorer in Splunk Search 01-28-2021
0 6
0
6
EStallcup
I'm having a bit of trouble trying to backfill a couple days in my summary index from a query using the collect comma...
by EStallcup Path Finder in Splunk Search 01-28-2021
2 14
2
14
fdevera
How would I take the results from this search:| rex field=initiatedBy.user.userPrincipalName "ex(?<GUID>\d+)z\@"And p...
by fdevera Path Finder in Splunk Search 01-28-2021
0 3
0
3
TheBravoSierra
I'm trying to look for senders where they don't contain values from the lookup mimics.csv. Examples of values in the ...
by TheBravoSierra Path Finder in Splunk Search 01-28-2021
0 3
0
3
redrobish1
Been testing to get a ISE-Splunk successful authentication report and trying this but the "Calling-Station-ID" is not...
by redrobish1 Engager in Splunk Search 01-28-2021
0 2
0
2
youngsuh
Here is what I've done.  How to break out the results into individual software correctly in Splunk.  Any tips could b...
by youngsuh Contributor in Splunk Search 01-28-2021
0 3
0
3
alexspunkshell
Hi All,Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
by alexspunkshell Contributor in Splunk Search 01-28-2021
0 3
0
3
shazbot79
Hi,I have used the Service Now add on to pull in the incident table. We have a custom SNow field called "dv_u_configu...
by shazbot79 Path Finder in Splunk Search 01-28-2021
0 2
0
2
gcue
i am trying to figure out what the output values are not showing up in my pie chart.  i would eventually like to grap...
by gcue Loves-to-Learn in Splunk Search 01-28-2021
0 2
0
2
prettysunshinez
I have a search query that outputs the count of the event for all the host (i.e., | stats count by host)Now if the co...
by prettysunshinez Explorer in Splunk Search 01-28-2021
0 4
0
4
Abha11
I am having an issue with one of my monitor stanza in inputs.conf. The stanza is as below:  [monitor://E:Speech\Tomca...
by Abha11 Explorer in Splunk Search 01-28-2021
0 3
0
3
sweiland
Hello Everyone, We are currently working on exchange logs (IIS), and trying to detect abnormal traffic from different...
by sweiland Path Finder in Splunk Search 01-28-2021
0 10
0
10
DanielAmlung
Hi,iam stuck with a problem where i need help from you guys. I have a search that runs IDs against a lookup to determ...
by DanielAmlung Path Finder in Splunk Search 01-28-2021
0 3
0
3
renSplunk
Hi,I have a query that gives a table of records satisfying certain condition. Have another query that gives the same ...
by renSplunk New Member in Splunk Search 01-28-2021
0 3
0
3
moayadalghamdi
Hello Splunkers ! i want to write a command that shows a timeline of authentication activities as following:index=MyI...
by moayadalghamdi Path Finder in Splunk Search 01-27-2021
0 2
0
2
arielpconsolaci
Hi Splunkers,Good day. I am trying to perform search time masking using a Calculated Field to replace _raw with the r...
by arielpconsolaci Path Finder in Splunk Search 01-27-2021
0 6
0
6
geekf
I am trying to get the average of a time difference by using | stats avg(time_dur) by type and since I am using this ...
by geekf Path Finder in Splunk Search 01-27-2021
0 12
0
12
bernanda
Hi Splunk,We have data like this: ( how to get the result like on the table StartError EndError and SumCall ?) I have...
by bernanda Explorer in Splunk Search 01-27-2021
0 4
0
4
VS0909
I want to view bitbucket files changed , owners who changed bitbucket files in Splunk. Can someone please share the s...
by VS0909 Communicator in Splunk Search 01-27-2021
0 0
0
0
KaitoKozo
I am trying to average the sum of power consumption readings between 2 days and compare that sum to a 3rd day. If the...
by KaitoKozo Explorer in Splunk Search 01-27-2021
0 2
0
2
limalbert
Hello,Ignoring commas and spaces, how do I grab just the name string from the below log? Below regex kept returning t...
by limalbert Path Finder in Splunk Search 01-27-2021
0 4
0
4
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...