Splunk Search

Splunk Search
Community Activity
thailam
Good day everyone,Ran into following problem,The queryindex=source | eval time=strftime(_time, "%+)|statsmax(time)val...
by thailam Engager in Splunk Search 01-03-2021
0 10
0
10
muralip543
Hi Team/Kamlesh,@kamlesh_vaghela Below is my json object and i want find the count of exception_type  whose value is ...
by muralip543 Loves-to-Learn Lots in Splunk Search 01-03-2021
0 8
0
8
Deepz2612
I have a single value chart,who statistical date is as below<Field_name>_____________<field_value> Now when i click o...
by Deepz2612 Explorer in Splunk Search 01-03-2021
0 1
0
1
Deepz2612
Hi I have multiple panels and when i click on some value in one panel the other panels shouldnt be displayed so i uns...
by Deepz2612 Explorer in Splunk Search 01-03-2021
0 3
0
3
im_abhinav22
Hi All,My requirement is to get time range of exact same length what i get from time picker. Suppose if i select rang...
by im_abhinav22 New Member in Splunk Search 01-01-2021
0 1
0
1
fralcalde
What i am trying to accomplish is forcing the scheduler to dispatch a scheduled saved search throgh REST in order to ...
by fralcalde Explorer in Splunk Search 12-31-2020
0 0
0
0
mah
Hi,I have a table like that : idnameappenv123test1[app]:my_app[env]:my_env456test2[env]:my_env[app]:my_app My issue i...
by mah Builder in Splunk Search 12-31-2020
0 4
0
4
OiskyPoisky
Morning All,I've setup several internal lookup files and made them part of an Intelligence download. I've added in lo...
by OiskyPoisky Explorer in Splunk Search 12-31-2020
0 0
0
0
OiskyPoisky
Morning Community,Looking at a way to pull multiple columns into an alert Im attempting to build. In the below syntax...
by OiskyPoisky Explorer in Splunk Search 12-31-2020
0 3
0
3
timbilt
Given the following eventsHOSTVALUEHost11Host24Host32Host27Host35Host18 How do I maintain the latest value for each h...
by timbilt Loves-to-Learn Lots in Splunk Search 12-31-2020
0 1
0
1
rkishoreqa
Hi , Based on your suggestion I prepared queries for two different apps as below.  Now I need to combine these two an...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 0
0
0
peetchow
All,I know there are a lot of postings with answers on lookup tables but I am still stuck.  I have not splunked in a ...
by peetchow Loves-to-Learn Lots in Splunk Search 12-30-2020
0 2
0
2
Sam_2020
I want the values of TID_now and TID_7 days ago in my table I tried | eval TID_7days=TID(now(), "-7d@d")it says expre...
by Sam_2020 New Member in Splunk Search 12-30-2020
0 3
0
3
splunkyj
See the example values below. How do I convert the value of the version field, so that they have the same number of d...
by splunkyj Path Finder in Splunk Search 12-30-2020
0 4
0
4
splunkcol
I have been asked to generate a csv with the indexed information of 1 index after 02:00 hours and that the name of th...
by splunkcol Builder in Splunk Search 12-30-2020
0 1
0
1
SabariRajanT
Hi Team,We have designed a dashboard panel where all the azure identity protection center logs has been enabled, We s...
by SabariRajanT Path Finder in Splunk Search 12-30-2020
0 0
0
0
rkishoreqa
I need to fetch the 'sid' value from the below JSON.  For that I prepared the below query, but it is not working. |re...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 1
0
1
ngwodo
I need help on how I  can compare 1 day security metric to another day and also generate a metric report that shows l...
by ngwodo Path Finder in Splunk Search 12-30-2020
0 2
0
2
rkishoreqa
I need to build a query to get count of transactions having multiple 'jId' and time difference greater than 5 mins. W...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 5
0
5
jaibalaraman
Hi First , I would like to thank everyone in this community who guided and helped me a lot. Now i have a problem exec...
by jaibalaraman Path Finder in Splunk Search 12-30-2020
0 16
0
16
Annna
wed } } }, { "S" : "12:00" } } }, "day" M" : { "close" : { "S" : "23:00" open "S" : "12:00" } } } } }, "email" : { "S...
by Annna Explorer in Splunk Search 12-30-2020
0 3
0
3
Yolan
Hi,I am trying to use a macro inside a macro validation expression. This is because I plan to make a number of simila...
by Yolan Explorer in Splunk Search 12-30-2020
0 0
0
0
gcusello
Hi at all,I developed an app that uses a KV Store to manage a whitelist and it runs without problems.But when I start...
by SplunkTrust SplunkTrust in Splunk Search 12-30-2020
0 1
0
1
efaundez
How can you see the search.log of a bd output?Good evening, it is required to validate the information of a certain d...
by efaundez Path Finder in Splunk Search 12-30-2020
0 1
0
1
Vignesh-107
I have a saved search need to check the each hour the search is being executed based on the cron configuration.Expect...
by Vignesh-107 Path Finder in Splunk Search 12-30-2020
0 2
0
2
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...