Splunk Search

Splunk Search
Community Activity
Patrick_Peeters
I have a JSON input with different types, all representing a data point at a certain time. I have the start time of t...
by Patrick_Peeters Splunk Employee Splunk Employee in Splunk Search 11-17-2020
0 1
0
1
ny34940
What I want to do is add color formatting to multiple columns of a table depending upon the name of the columns. ...
by ny34940 Path Finder in Splunk Search 11-17-2020
0 11
0
11
jboustead
Is it possible to run a search that will only include all the events for that day after a certain time? (using the ti...
by jboustead Explorer in Splunk Search 11-17-2020
0 2
0
2
Hemant1
0
2
Sasquatchatmars
Hi all,I have been making a search to know which account is in which groups using ldapsearch. I succesfully made the ...
by Sasquatchatmars Communicator in Splunk Search 11-17-2020
0 2
0
2
jboustead
Please help create a Regex that will only take the 4 characters/number after MTCP from below events?For example below...
by jboustead Explorer in Splunk Search 11-17-2020
0 1
0
1
SausagePizzza
Hello, I'm trying to get a few things from my tstats search:count for last hourcount for yesterdayUse the two counts ...
by SausagePizzza Engager in Splunk Search 11-17-2020
1 1
1
1
tefa627
 I am trying to compare 2 fields in this xml.  I have a field named avg that I want to compare with the other columns...
by tefa627 Explorer in Splunk Search 11-17-2020
0 2
0
2
Ralf
Hi there,I did already several trials with search commands like "eval _time=strptime(time,"%Y-%m-%dT%H:%M:%S")"but wa...
by Ralf Explorer in Splunk Search 11-17-2020
0 10
0
10
dordavid
Hey, i want to search a field and get all the results which contain a value from another field.For example:  I have 2...
by dordavid Explorer in Splunk Search 11-17-2020
1 4
1
4
Nidd
Hi,I have the following log from which I need to extract 2 fields: [INFO ] 2020-11-16 20:52:30,729 (http-nio-8085-exe...
by Nidd Path Finder in Splunk Search 11-17-2020
0 5
0
5
alok
Hello,Query one returns a result with one fields as list of values. I want to  pass those list of value as the search...
by alok Loves-to-Learn Everything in Splunk Search 11-16-2020
0 3
0
3
vvemula
I have result like this, parametercompliancenon-compliance64bit4322Bios2441Error065Inter641OS614 And I want Error to ...
by vvemula Path Finder in Splunk Search 11-16-2020
0 3
0
3
BernardEAI
HiI'm trying to get the username and password of the user calling a python script from the search bar in the Splunk U...
by BernardEAI Communicator in Splunk Search 11-16-2020
0 4
0
4
ayushchoudhary
Hello all,can some one suggest me the best method to compare the source_ip in events to the lookup table which have t...
by ayushchoudhary Path Finder in Splunk Search 11-16-2020
0 0
0
0
hollybross1219
I have the following query:splunk_server=indexer* index=wsi sourcetype=fdpwsiperf (channel_type=ofx2 OR agent_service...
by hollybross1219 Path Finder in Splunk Search 11-16-2020
0 1
0
1
SS1
Hello Everyone,I have two searchessearch 1=> index="appv" sourcetype="AppV-User" *PUT /package*search2=> index="appv"...
by SS1 Path Finder in Splunk Search 11-16-2020
0 12
0
12
chandukreddi
Hello Tem,I have log like below and I want to extract 3 fields and its values like below and do a line chart for top ...
by chandukreddi Path Finder in Splunk Search 11-16-2020
0 9
0
9
ian17
Hi all,Newbie question here: I'm trying to set up some of the 'InfoSec App for Splunk' Dashboards, and running into d...
by ian17 New Member in Splunk Search 11-16-2020
0 0
0
0
AshChakor
I have the following resultset I want to get the most recent eventsResultset ACustom_IDEligibilityStart_dateEnd_DateU...
by AshChakor Path Finder in Splunk Search 11-16-2020
0 3
0
3
Hanliamadeus
Hello experts, I am working on a stats of meetings. As the attached photo shows, this meeting lasts for 7 (duration_h...
by Hanliamadeus Explorer in Splunk Search 11-16-2020
0 2
0
2
akumar
i have issue where i am comparing values from 2 fields which will have same value always, but sometimes it differs. I...
by akumar Loves-to-Learn Lots in Splunk Search 11-16-2020
0 6
0
6
vinayakolhapure
I want to extract a number from logs where the line of interest looks like,INFO 2020-11-16 12:11:47,161 [ThreadName-1...
by vinayakolhapure Engager in Splunk Search 11-16-2020
0 2
0
2
logginz85
Hi.I have an alert that'll tell me if a host is down, and it runs for both Active and Standby hosts.The issue is that...
by logginz85 Explorer in Splunk Search 11-16-2020
0 3
0
3
user2020dy
I have field src_ip in my data. My lookup fields: ip1,  ip2,  ip3, ip4,  user What I want is to find matching pairs i...
by user2020dy Path Finder in Splunk Search 11-16-2020
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...