Splunk Search

Splunk Search
Community Activity
hashsplunk
Hi ,I need to replace the string in a field value role_seu_458137407337_prd-sso-data-science-752-2205-compute-role"  ...
by hashsplunk Loves-to-Learn Lots in Splunk Search 01-07-2021
0 1
0
1
jkjeong
I do exercise example about "Custom search command" step by step , but the following error occurred. What's the pro...
by jkjeong New Member in Splunk Search 01-06-2021
0 2
0
2
sumitkumarsk90
How can I retrieve data from Splunk dashboard or saved searches using SSIS.I am able to create the connection string ...
by sumitkumarsk90 New Member in Splunk Search 01-06-2021
0 0
0
0
moayadalghamdi
Hello splunkers  i want to create a visualization for my command to create a bar chart that contains the (src_ip/user...
by moayadalghamdi Path Finder in Splunk Search 01-06-2021
0 4
0
4
alexspunkshell
Hi All,I want to eliminate TruestedLocation = Zscaler in my splunk search result.Below is my query and screenshot. Pl...
by alexspunkshell Contributor in Splunk Search 01-06-2021
0 2
0
2
Khushboo
Hi Team,I have a table where employee name are group by manager name and their project count.PFB structure of my tabl...
by Khushboo Explorer in Splunk Search 01-06-2021
0 3
0
3
tah7004
Hello, I'm seeing an issue where tstats search is slow due to an automatic lookup. I'm running the searches over rang...
by tah7004 Path Finder in Splunk Search 01-06-2021
0 2
0
2
hoopydave
I'm being asked to compare device Entities in SAI with database data I am indexing that contains devices on our netwo...
by hoopydave Path Finder in Splunk Search 01-06-2021
0 0
0
0
Khushboo
[khush@1122]$ !531/dev/kt/splunk/splunkforwarder/bin/splunk startsplunkd 14116 was not running.Stopping splunk helper...
by Khushboo Explorer in Splunk Search 01-06-2021
0 0
0
0
jamesboustead
I am using the same timechart search query:'search| timechart span=1d sum(xxx)"when I set the time range picker to ye...
by jamesboustead Explorer in Splunk Search 01-06-2021
0 2
0
2
clementros
Hi all, I'm trying to calculate the time support team took to respond when a new ticket is created. For now i'm able ...
by clementros Path Finder in Splunk Search 01-06-2021
0 0
0
0
jamesboustead
Hi,I'm not able to create a timechart graph for the below search, it is coming up with no result.My current search is...
by jamesboustead Explorer in Splunk Search 01-06-2021
0 4
0
4
saeed
HiWhen i search in Splunk I only find logs in last 52 days I need to increase the retention period  to be available a...
by saeed Explorer in Splunk Search 01-05-2021
0 1
0
1
moayadalghamdi
Hello Splunkers ! i wanted to visualize data on map so i used this command and it worked:index=myFirewall | stats cou...
by moayadalghamdi Path Finder in Splunk Search 01-05-2021
0 3
0
3
ravivarmagv1
Hello All,I am new to splunk and looking for suggestion on search queries. In our environment, we have phantom app in...
by ravivarmagv1 Loves-to-Learn in Splunk Search 01-05-2021
0 0
0
0
abhayneilam
Hi, I have four line result as follows: value1 value2 value3 value4 but I want the serial no. should be before eac...
by abhayneilam Contributor in Splunk Search 01-05-2021
1 5
1
5
dchando
Hi,I am trying to use Split command to separate and get few fields. However I am getting different fields value due t...
by dchando Engager in Splunk Search 01-05-2021
0 4
0
4
bartstk18
I have a Splunk event with the following lines logged from a .txt file.HeaderField1 | HeaderField2 | HeaderField3Head...
by bartstk18 Loves-to-Learn Lots in Splunk Search 01-05-2021
0 4
0
4
ashodha
hi, I have a string int the following format:msg: Logging interaction event { eventId: '12dea8c0-dfb2-4988-9e97-314dd...
by ashodha Engager in Splunk Search 01-05-2021
0 3
0
3
archanas
hi, I am looking to convert the following time to UTC format:8/26/20203:47PM-06:00 Ultimately i am looking to convert...
by archanas Explorer in Splunk Search 01-05-2021
0 3
0
3
me74fhfd
Hi all,I have a use case to transform gzipped binary portion of HTTP ResponseCode into readable content. Is this some...
by me74fhfd Path Finder in Splunk Search 01-05-2021
0 3
0
3
mdurdel
I have a text string field in my events which contains one or many date/time stamps within the string. The string is...
by mdurdel New Member in Splunk Search 01-05-2021
0 11
0
11
kunalmao
I am trying to do a time chart of available indexes in my environment , I already tried below query with no luck | ...
by kunalmao Communicator in Splunk Search 01-05-2021
0 3
0
3
prettysunshinez
I have a dropdown(say field A) as input to a dashboard.And this dropdown value is passed/used only in certain panels ...
by prettysunshinez Explorer in Splunk Search 01-05-2021
0 4
0
4
gcbysc
I'm trying to compare multiplevalue fields in a search.My query is below:  sourcetype=app2_log OR sourcetype=app1_log...
by gcbysc Loves-to-Learn Everything in Splunk Search 01-05-2021
0 8
0
8
Get Updates on the Splunk Community!

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...
Top Solution Authors