Splunk Search

Splunk Search
Community Activity
harsush
Hi Team,index=AA source=*XXX.log| rex field=_raw "- (?<uc>U(\d{7}|\d{8})) "| rex field=uc "(?<ul5>\d{5})$"| rex "[^\w...
by harsush Path Finder in Splunk Search 12-18-2020
0 4
0
4
bowesmana
I'm struggling with parsing this JSON. This query shows the part of a larger JSON element (response.rules). | makeres...
by SplunkTrust SplunkTrust in Splunk Search 12-17-2020
0 2
0
2
wtaylor149
I have a need to find a user(s) that have multiple infections over a 7 day period.  Example would be user1 has an inf...
by wtaylor149 Explorer in Splunk Search 12-17-2020
0 6
0
6
asukaka
教えてください。STARTとENDの時間範囲のあるCSVを作成し、その範囲内にあるイベントを数えたいのですが、どのようにクエリを書けばよいでしょうか<pre>started,completed2020/10/2 08:00,2020/...
by asukaka Engager in Splunk Search 12-17-2020
0 1
0
1
bsuresh1
Environment: Splunk Cloud I am running the below search with table command. The data which I am searching is very hu...
by bsuresh1 Path Finder in Splunk Search 12-17-2020
2 3
2
3
alancalvitti
This question: How to use IN function with VALUE-LIST as a search or lookup  discusses using IN for a single key and ...
by alancalvitti Path Finder in Splunk Search 12-17-2020
0 2
0
2
mcaulsc
I seem to have tied myself in a knot.I have data similar to:h1  h2   h3    h4a    12  123  231a    32  45    678b   4...
by mcaulsc Path Finder in Splunk Search 12-17-2020
0 5
0
5
binurajps
Below are my log entry DateTime=2020-12-16 14:19:01:888 UTC, Type=Orchestrator Event Log, Environment=prod, Thread=[P...
by binurajps Engager in Splunk Search 12-17-2020
0 4
0
4
anandhalagaras1
Hi Team,I have a logfile in which I have few keywords such as ORA-1 , ORA-212, ORA-609 and similarly we have more tha...
by anandhalagaras1 Contributor in Splunk Search 12-17-2020
0 7
0
7
rajneeshdba
2020-12-17T01:21:44.690341+00:00 txn1.test-fdb-us-south-004 2020-12-17T01:21:44Z { "Severity": "10", "Time": "1608168...
by rajneeshdba Explorer in Splunk Search 12-16-2020
0 1
0
1
SabariRajanT
Hello Team,I have my service now ticketing logs enabled into my splunk. I do required  a below help and suggestions.L...
by SabariRajanT Path Finder in Splunk Search 12-16-2020
0 1
0
1
dwibedi03
I have a lookup table which consists of src_ip. This source Ip has mix of Ips in the format:Src_ip163.74.7.212163.74....
by dwibedi03 Explorer in Splunk Search 12-16-2020
0 3
0
3
vikasverma
Hello All,I hope you all are doing well.I have a situation wherein i have to pass current day value (Sun, Mon, Tue et...
by vikasverma Engager in Splunk Search 12-16-2020
0 4
0
4
seomaniv
I have two events: items received, and items acted on. I want to set an alert when the count by transactionID is not ...
by seomaniv Explorer in Splunk Search 12-16-2020
0 2
0
2
nivethainspire_
 In the below table, I was to search by field "Core Content" where "Core Content" should take top 2 highest value. Co...
by nivethainspire_ Explorer in Splunk Search 12-16-2020
0 8
0
8
BernardEAI
I'm interested in the mechanics of a base search (for a dashboard). Where would the results of a base search be store...
by BernardEAI Communicator in Splunk Search 12-16-2020
0 1
0
1
manoharkalva
Hi,Below used query is working perfectly fine when i searched directly in SPLUNK WEB. but when i use the same query i...
by manoharkalva Engager in Splunk Search 12-16-2020
0 1
0
1
timyong80
Hello,I have multiple values for a field in my search results and they look like the ones below. Can you show me the ...
by timyong80 Explorer in Splunk Search 12-16-2020
0 3
0
3
Newton
Hi all,Need help to build a query which helps   to identify the users that possibly leaking /auto-forwarding emails t...
by Newton Engager in Splunk Search 12-15-2020
0 1
0
1
pstalin_
Hi,Anyone please help me in rewplacing join in this below queryindex=168347-np [ | `last_np_sourcetype("index=168347-...
by pstalin_ Engager in Splunk Search 12-15-2020
0 7
0
7
priyastalin
@bowesmana Hi,could you please help me in replacing the join in below query?index=168347-np [ | `last_np_sourcetype("...
by priyastalin Explorer in Splunk Search 12-15-2020
0 5
0
5
kwholley63
I have a dashboard with two panels. One is sales data and one is returns. I would like to have a drop down that I ent...
by kwholley63 Loves-to-Learn Lots in Splunk Search 12-15-2020
0 2
0
2
anoopambli
I am using a DB query to get stats count of some data from 'ISSUE' column. This column also has a lot of entries whic...
by anoopambli Communicator in Splunk Search 12-15-2020
1 3
1
3
adalbor
Hey All,Was just curious if there is a way to calculate how long it should take to thaw\rebuild frozen buckets for se...
by adalbor Builder in Splunk Search 12-15-2020
0 0
0
0
Khushboo
Hi @all, i have following string which i want to break into there fields: service_name, host and port_idmetics-ha-592...
by Khushboo Explorer in Splunk Search 12-15-2020
0 3
0
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...