Splunk Search

Splunk Search
Community Activity
thx
I  am trying to use a lookup of "known good" filenames that are within FTP transfer logs, to add extra data to files ...
by thx Explorer in Splunk Search 08-30-2024
0 2
0
2
bcanfiel83
Hi All,I have a somewhat unusual requirement (at least to me) that I'm trying to figure out how to accomplish. In the...
by bcanfiel83 Engager in Splunk Search 08-30-2024
0 2
0
2
guldendraak
When defining a custom modular input in an app, it is possible to design a custom user interface for setting up the p...
by guldendraak Explorer in Splunk Search 08-30-2024
1 1
1
1
vijaynela
I am working Service now logs in Splunk. The tickets data has one field called "sys_created" this field gives the tic...
by vijaynela New Member in Splunk Search 08-30-2024
0 1
0
1
jaibalaraman
Hi All We have created a dashboard to monitor CCTV and it was working fine. However suddenly data stopped populating....
by jaibalaraman Path Finder in Splunk Search 08-30-2024
0 5
0
5
Taruchit
Hello All, I need to search for SPLs having time range as All time. I used the below SPL:-  index=_audit action=searc...
by Taruchit Contributor in Splunk Search 08-30-2024
0 2
0
2
nkavouris
I have a subsearch[search index="june_analytics_logs_prod" (message=* new_state: Diagnostic, old_state: Home*)|spath ...
by nkavouris Path Finder in Splunk Search 08-29-2024
0 2
0
2
shashank9
Hi Splunkers, I'm trying to compare the policy names from Today with policy names from past 48 hours to see if there ...
by shashank9 Explorer in Splunk Search 08-29-2024
0 5
0
5
manuelostertag
Hello,I've create a search which contains (...(CallerCountry="CN")).When I take a look in the search log in the job i...
by manuelostertag Path Finder in Splunk Search 08-29-2024
1 1
1
1
DDowns
Wondering if there are any industry best practices and/or recommendation for  setting fileSizeGB AND fileCount thresh...
by DDowns New Member in Splunk Search 08-29-2024
0 1
0
1
VRP136
Below is my raw log   [08/28/2024 08:14:50] Current Device Info ... *************************************************...
by VRP136 Engager in Splunk Search 08-29-2024
0 5
0
5
jwhughes58
I'm working on a dashboard in which the user enters a list of hosts.  The issue I'm running into is they must add an ...
by jwhughes58 Contributor in Splunk Search 08-29-2024
0 3
0
3
mninansplunk
Hello,Thank you for your help on this in advance,  I just need to create a field in Splunk Search that contains the v...
by mninansplunk Path Finder in Splunk Search 08-29-2024
0 1
0
1
MatthewWolf
The task guide for the Forage job sim states this: For example, to add “Count by category” to your dashboard, type ou...
by MatthewWolf New Member in Splunk Search 08-29-2024
0 1
0
1
jagan_vannala
HI Team,When i am trying to exclude one field by inserting condition sessionId!=X its not working . even though I use...
by jagan_vannala Observer in Splunk Search 08-29-2024
0 6
0
6
btheneghan
I have never been one to understand regex, however I need to extract everything after the first entry (#172...) into ...
by btheneghan New Member in Splunk Search 08-28-2024
0 2
0
2
jwhughes58
I've got this searchindex=my_index data_type=my_sourcetype earliest=-15m latest=now | eval domain_id=if(isnull(domain...
by jwhughes58 Contributor in Splunk Search 08-28-2024
0 6
0
6
OzzMann80
Howdy, Im fairly new to splunk and couldnt google the answer I wanted to Here we go. I am trying to simplify my queri...
by OzzMann80 Engager in Splunk Search 08-28-2024
0 2
0
2
andreaswpv
Running queries on really large sets of data, and sending the output to an outputlookup works well for weekly refresh...
by andreaswpv Explorer in Splunk Search 08-28-2024
0 2
0
2
sumarri
When I search I want something like this:if(ID =99): then lookup 1,else: lookup 2.What I have right now is something ...
by sumarri Path Finder in Splunk Search 08-28-2024
0 2
0
2
JandrevdM
Good day, I have a query that I would like to add more information onto. The query pulls all users that accessed a AI...
by JandrevdM Path Finder in Splunk Search 08-28-2024
0 3
0
3
st1
I'm not very good with SPL. I currently have Linux application logs that show the IP address, user name, and if the u...
by st1 Path Finder in Splunk Search 08-28-2024
0 2
0
2
irkey
Is there a way to reference or combine multiple fields into a single name so that it can be referenced by that new na...
by irkey Explorer in Splunk Search 08-27-2024
1 5
1
5
ksukumaran
Im getting a "not found" error. On trying to start splunk in the 'bin' folder I am getting am error. Any help appreci...
by ksukumaran New Member in Splunk Search 08-27-2024
0 10
0
10
elsaddiq
I'm a student running the free Community Edition in my homelab. My host currently receives a dynamic IP. Is a static ...
by elsaddiq Engager in Splunk Search 08-27-2024
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...