Splunk Search

Splunk Search
Community Activity
tefa627
I am trying to get an average for the last (x) days for a that specific day and hour. This search lists a count for t...
by tefa627 Explorer in Splunk Search 11-04-2020
0 2
0
2
M_fahad_hassan
Hi,  I am having confusion in understanding some portion of following search. Can anyone help me in understanding it ...
by M_fahad_hassan Engager in Splunk Search 11-04-2020
0 2
0
2
waJesu
My DNS is now only showing IP addresses in the logs. How do I get to see DNS names in the logs?
by waJesu Path Finder in Splunk Search 11-04-2020
0 1
0
1
dbuehler
Hey guys, I have IIS logs that are logging multiple IPs to the X-Forwarded-For field as below:  114.119.136.78,+162.1...
by dbuehler Loves-to-Learn Everything in Splunk Search 11-04-2020
0 6
0
6
dustintroop
Having issues with splitting the complete search between "basesearch" and "remaining search in other panels". Complet...
by dustintroop Explorer in Splunk Search 11-04-2020
0 5
0
5
mailmetoramu
Hello All,Actually i have an lookup table DIUSERS.csv, i would like to build a query as like below :index=* |inputloo...
by mailmetoramu Explorer in Splunk Search 11-04-2020
0 1
0
1
matthewwhittle
Hi all!I have this query which gets me the list of hostsstuff stuff stuff | rename host as host_changed | dedup host_...
by matthewwhittle Explorer in Splunk Search 11-04-2020
0 3
0
3
wtaylor149
I have a field that sometimes has only what appears to be a whatspace.  How would I replace the existing whitespace w...
by wtaylor149 Explorer in Splunk Search 11-04-2020
0 2
0
2
aohls
I am attempting to use the map command and table the data. I am trying to map in values to run through the a predict ...
by aohls Contributor in Splunk Search 11-04-2020
0 2
0
2
mailmetoramu
Looking for an search query to monitor some bunch of users on all indexes activity. Tried the below one but couldn't ...
by mailmetoramu Explorer in Splunk Search 11-04-2020
0 2
0
2
LogUx
As per the below screenshot, when i used to select any host from the dropdown, i want to hide first four panel and ot...
by LogUx Motivator in Splunk Search 11-04-2020
0 1
0
1
dgitdos
Hello,  Splunk newbie here. I have a CSV file with a bunch of hostnames titled 'Device' that I added as a lookup 'hos...
by dgitdos Loves-to-Learn in Splunk Search 11-04-2020
0 3
0
3
LogUx
As per below screenshot, my token is not working while put this search in panel. Please let me why my token is not wo...
by LogUx Motivator in Splunk Search 11-04-2020
0 2
0
2
bmorgenthaler
Is it possible to drop events if they occur within a certain timespan of each other? I'm specifically looking at VMwa...
by bmorgenthaler Path Finder in Splunk Search 11-03-2020
0 1
0
1
georgear7
I have below query which will get results from other panels and corresponding results will get stored here. I have us...
by georgear7 Communicator in Splunk Search 11-03-2020
0 2
0
2
weidertc
I am writing a query to look for rises in error messages over the past hour.  It looks in 15 minute chunks from 0 to ...
by weidertc Contributor in Splunk Search 11-03-2020
0 2
0
2
shannan2
I have an event ingesting to splunk via HEC which is around 13k characters, and approx. 260 fields within the json of...
by shannan2 Explorer in Splunk Search 11-03-2020
0 2
0
2
jip31
hello i use the search below which works fine| inputlookup lookup_patch | lookup fo_all HOSTNAME as host output SITE ...
by jip31 Motivator in Splunk Search 11-03-2020
0 3
0
3
vamsigurram
 I am looking for SPL, that can give me list of all the knowledge Objects, created in last 24 hours, in search app.I ...
by vamsigurram Path Finder in Splunk Search 11-03-2020
0 2
0
2
splunker_rmc
Looking to write a search that filters mount drives. For example, the values for the field "mount" are "C:" "D:" "F" ...
by splunker_rmc Splunk Employee Splunk Employee in Splunk Search 11-03-2020
0 1
0
1
kuriakose
How to ignore a field from search if the value is null, search based on the second input.?I have two inputs and this ...
by kuriakose Explorer in Splunk Search 11-03-2020
0 5
0
5
LogUx
I want difference between 155 and 132, how can i do with the Spl. IMG_20201103_194436.jpg
by LogUx Motivator in Splunk Search 11-03-2020
0 2
0
2
nicofantinato
Hi all,I have a cluster with 2 indexers, plus a cluster master in a different server. For some reasons that I don't k...
by nicofantinato Path Finder in Splunk Search 11-03-2020
0 1
0
1
heamik
I am trying to get a distinct count of tacking id from all of our production indexes. The issue I am running into is ...
by heamik Engager in Splunk Search 11-03-2020
0 2
0
2
mtaher
I have Splunk version: 7.3.1 and I see the message: APPSERVER_PORT_ZEROThe value for: "appServerPorts" is set to 0, I...
by mtaher Loves-to-Learn in Splunk Search 11-03-2020
0 11
0
11
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors