Splunk Search

Splunk Search
Community Activity
ritesh14
question is two foldquestion 1 -here is sample log|>messageType|2020-02-2 14:01:55.995|094a786b-4d07-498c-9c26-685aa4...
by ritesh14 Explorer in Splunk Search 01-26-2021
0 4
0
4
ZackWang
As the title said, if we have a field: "sourcetype=log4j" for all result, Should I add it to the search or remove it ...
by ZackWang Engager in Splunk Search 01-26-2021
0 1
0
1
kojodei789
Goodmorning guys much help needed. I have been receiving a lot of phishing attempts to recipients emails. I am lookin...
by kojodei789 Observer in Splunk Search 01-26-2021
0 2
0
2
donB
I am trying to find the top api url's that were consumed by our clients. Our uri in logs are of below format.1. https...
by donB Loves-to-Learn Lots in Splunk Search 01-26-2021
0 1
0
1
cheriemilk
Hi team, I have a stats requirement to get he user retention rate that visit a module per month in last 1 year.Detail...
by cheriemilk Path Finder in Splunk Search 01-26-2021
0 1
0
1
Damianv
Good day,I have been trying to figure out how to accomplish the following task for a few days now and thought I would...
by Damianv New Member in Splunk Search 01-26-2021
0 2
0
2
donB
i have to replace multiple text strings with different values. e.g.Log Statement:- "Hello, this is sample url for emp...
by donB Loves-to-Learn Lots in Splunk Search 01-26-2021
0 1
0
1
vikashperiwal
HI , I am trying to send values from one panel to another dashboard using drill down , is it possible to split the va...
by vikashperiwal Path Finder in Splunk Search 01-26-2021
0 2
0
2
ajromero
Need to calculate the percentage of two columns- I have a search that gives me a total of two columns and I need to g...
by ajromero Path Finder in Splunk Search 01-25-2021
0 1
0
1
rfiscus
I can test\\[\w]+\\[\w]+\\(?<File_Path>.+) or simply \\\w+\\\w+\\(?<File_Path>.+)in Rex101 and it works fineIn Splunk...
by rfiscus Path Finder in Splunk Search 01-25-2021
0 2
0
2
ak8675309
Splunk noob here,Wanted to group our get endpoints under a single entry. We have the following query  index=reporting...
by ak8675309 Engager in Splunk Search 01-25-2021
0 2
0
2
pdevosceazure
After Extracting fields for a source type, and spending a lot of time renaming them. I noticed I missed one.I can go ...
by pdevosceazure Path Finder in Splunk Search 01-25-2021
0 5
0
5
jerinvarghese
Hi All,need help in my query, formatting an IF statement.My Code:    index=opennms "uei.opennms.org/nodes/nodeUp" OR ...
by jerinvarghese Communicator in Splunk Search 01-25-2021
0 3
0
3
aaronhernandez
Hi friends! Im doing a search likeindex=_internalFrom a custom app, even if Im the admin user. I have a cluster Splun...
by aaronhernandez Explorer in Splunk Search 01-25-2021
1 3
1
3
duckware
Every event in an index has field XYZ (with a non-null positive number, no exceptions), and yet this search:index=<in...
by duckware Explorer in Splunk Search 01-24-2021
0 4
0
4
vijaykumartcs
I have a dashboard which has 11 rows and each row has 4 panels, now out of 11 rows 5rows belong to one application an...
by vijaykumartcs Explorer in Splunk Search 01-24-2021
0 1
0
1
arjit
Hi All,  I have a requirement where I need to show only alternate X axis label when I am running a chart command: ind...
by arjit Path Finder in Splunk Search 01-24-2021
0 1
0
1
gfriedmann
I have been tagging hosts to aid in searching by environment, service, sub-service I would like to make a dashboard ...
by gfriedmann Communicator in Splunk Search 01-23-2021
1 6
1
6
vsasdao
In my Search 1, it will list all unique port numbers associated with a certain IP address, i.e. 1.2.3.4"MYTOKEN is: f...
by vsasdao Explorer in Splunk Search 01-23-2021
0 3
0
3
syedabuthahir
i want to extract this below event from the _raw event for all the entries in query. Can you please help me on this. ...
by syedabuthahir Explorer in Splunk Search 01-23-2021
0 3
0
3
alancalvitti
I get a different result set when using jobs.export of python SDK with a simple stats query compared to the same quer...
by alancalvitti Path Finder in Splunk Search 01-22-2021
0 0
0
0
dpolochefm
The goal is to get a count when a specific value exists 'by id'.  This is not working on a coalesced search.The searc...
by dpolochefm Explorer in Splunk Search 01-22-2021
0 2
0
2
lalithadevisegu
I have data following data in  csv file. need to suppress last one or two columns. please suggest me how to do that.1...
by lalithadevisegu Loves-to-Learn Everything in Splunk Search 01-22-2021
0 3
0
3
parker_ryan
I am looking to compare the count of transactions processed in a 3 hour window to the count of transactions made in t...
by parker_ryan Engager in Splunk Search 01-22-2021
0 2
0
2
CesarCrt
Hello everyone,There is my search :my_severity=error my_app="name" earliest=-48h latest=-24h  | stats count as nb_yes...
by CesarCrt Path Finder in Splunk Search 01-22-2021
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...