Splunk Search

Splunk Search
Community Activity
ahcarpenter
Hi, Any thought off-hand as to what I'm not accounting for?Looking to extract values from a field in unstructured log...
by ahcarpenter Engager in Splunk Search 12-12-2020
0 2
0
2
khandelwaly
We have the below data, out of which I wanted to extract a particular field and value from the json format. PLATFORMI...
by khandelwaly Explorer in Splunk Search 12-12-2020
0 1
0
1
kirrusk
Hi,I have a simple json like below , {"env":"p1","label":"1788_kapi_fed","App":"admin-ipo-sel","lastUpdate":"2020-10-...
by kirrusk Communicator in Splunk Search 12-11-2020
0 3
0
3
berserkersyco
hi,i wanted to fetch some information from my logs. here is the scenario:index=xyz host=xxx.com source="/as/df/gh/*.l...
by berserkersyco New Member in Splunk Search 12-11-2020
0 1
0
1
AlexBryant
I'm performing a lookup against a csv and need to use two columns (description and function) to return the correct va...
by AlexBryant Path Finder in Splunk Search 12-11-2020
0 2
0
2
klaudiac
Hi guys, I'm looking to add a new column to my inputlookup. The idea is to mark the values that repeat e.g.: Email Th...
by klaudiac Path Finder in Splunk Search 12-11-2020
0 1
0
1
haph
Hi everyone, I have continuous data from a leakage test station with values as low as 1e-8 and spikes up to 1e-2 mba...
by haph Path Finder in Splunk Search 12-11-2020
0 4
0
4
Raghu_R
Hi All,I am working on Transaction Logs where I have a log field with the below data.Below is an example of the data ...
by Raghu_R Loves-to-Learn Lots in Splunk Search 12-11-2020
0 7
0
7
yshen
By the following query, I can list the hosts status and when they have their status change: index=snmptrapd | table ...
by yshen Communicator in Splunk Search 12-11-2020
0 3
0
3
moogmusic
We have VPC flow and firewall logs coming into Splunk from our Kubernetes deployments in GCP. I want to be able to ma...
by moogmusic Path Finder in Splunk Search 12-11-2020
0 2
0
2
uagraw01
How can i use multiple NOT condition in my second eval function. My attribute is there state_desc!="ONLINE" OR state_...
by uagraw01 Motivator in Splunk Search 12-11-2020
0 7
0
7
Colbasaur
Hello all!I am fairly new to SPLUNK but I wanted to make a chart that would use the X axis for a specified amount of ...
by Colbasaur New Member in Splunk Search 12-11-2020
0 1
0
1
pacifikn
Hi ALL!!Help me on how I can use the table function in query with percent|table  field-1, field-2, field-3  |stats co...
by pacifikn Communicator in Splunk Search 12-10-2020
0 2
0
2
ortalis
I'm getting from my dashboard parameter with '_' value in it, I would like to start my search by evaluating a new par...
by ortalis New Member in Splunk Search 12-10-2020
0 5
0
5
riffman1999
I am trying to determine the the successful UF deployments other than an incremental count from the forwarder manager...
by riffman1999 Observer in Splunk Search 12-10-2020
0 0
0
0
jadengoho
HI All, I have this JSON file that is 4400 Long , and i want it to reroute to a specific Indexer.If i use REGEX101 - ...
by jadengoho Builder in Splunk Search 12-10-2020
0 1
0
1
wmyersas
I have tried | eval mvindex(mvfield,0)="my new value" But it does not work. Is it even possible to change/replace...
by wmyersas Builder in Splunk Search 12-10-2020
0 8
0
8
epw0rrell
I know how to use eval and if statements to pull fields that contain a %.value.% but how can I use this when running ...
by epw0rrell Path Finder in Splunk Search 12-10-2020
0 4
0
4
rj1408
Hi ,So if I click at Success/Failure I'm able to get all the transaction IDs which have status Success/Failure, But i...
by rj1408 Path Finder in Splunk Search 12-10-2020
0 5
0
5
anonuser
I would like to use time range picker - advanced and create a formula that brings the last 4 business daysI found som...
by anonuser Explorer in Splunk Search 12-10-2020
0 1
0
1
waynephilip33
we have three management servers need to see to which our spunk agent deployed in new server is pointing to Saw below...
by waynephilip33 New Member in Splunk Search 12-10-2020
0 1
0
1
manoharkalva
I can able to search from splunk web using the below string:cs_uri_stem="*/reporting/rptttt.xls" AND (cs_uri_query="r...
by manoharkalva Engager in Splunk Search 12-10-2020
0 0
0
0
patrikstich
Hi,I have a list with terminated users with "Last name", "First name" and their email. I am trying to set up a query ...
by patrikstich Engager in Splunk Search 12-10-2020
0 2
0
2
ericwindmill
Howdy,Basically, what I'm trying to achieve is putting all events into 2 buckets, based on the `tracking policies`, a...
by ericwindmill Observer in Splunk Search 12-10-2020
0 0
0
0
jwalzerpitt
Found a great article on how to remove the Windows message description - https://www.hurricanelabs.com/splunk-tutoria...
by jwalzerpitt Influencer in Splunk Search 12-10-2020
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...