Splunk Search

Splunk Search
Community Activity
renuka
I got the output in the form ofsearch is : stats values(status) by id..Id   statusIDStatus1AgreedN/ANegoiate2AgreedSu...
by renuka Path Finder in Splunk Search 10-08-2020
1 10
1
10
hethu
I have struggled with getting splunk to recognize timestamps in timestamps from an udp input. I have tried for many h...
by hethu Path Finder in Splunk Search 10-08-2020
0 3
0
3
kiru2992
Hello Everyone!I have an output in the below format and would like to filter the duplicate ids with 'fieldA' value as...
by kiru2992 Path Finder in Splunk Search 10-07-2020
0 8
0
8
c799651
Hi, I have an index that returns alarms with details as  string. I want to define the text in bold  as a field. The s...
by c799651 Explorer in Splunk Search 10-07-2020
1 3
1
3
munisb
Hi,I am trying to create a trending single value however having trouble setting it up. Essentially the stats below su...
by munisb Explorer in Splunk Search 10-07-2020
0 2
0
2
mborner
I've got email subjects extracted into a field, which are encoded in UTF-8 or ISO-8859-* Examples: =?ISO-8859-15?Q?...
by mborner Explorer in Splunk Search 10-07-2020
2 4
2
4
Allampally
I am preparing a volume report for my project. My requirement is to capture the peak hour (hour which has highest cal...
by Allampally Path Finder in Splunk Search 10-07-2020
0 11
0
11
CarbonCriterium
Let's say you have the following search:... | stats sum(eval(sc_bytes/1073741824)) AS Gigabytes BY date The resulting...
by CarbonCriterium Path Finder in Splunk Search 10-07-2020
0 3
0
3
solson3
We're looking to identify the users that connect the most within a 60 second window. Currently our search looks like ...
by solson3 New Member in Splunk Search 10-07-2020
0 4
0
4
unifirst101
Hi, I am using Splunk to grab disk drive metrics but often times I am pulling metrics for drives I don't care about. ...
by unifirst101 Engager in Splunk Search 10-07-2020
0 3
0
3
havatz
  HelloIm trying to run this query from Splunk API and getting this error:'rex' is not recognized as an internal or e...
by havatz Explorer in Splunk Search 10-07-2020
0 0
0
0
joemarty82
Hello, I have been banging my head on a problem. What I am trying to do is run a first query to get a list of assets,...
by joemarty82 Explorer in Splunk Search 10-07-2020
0 0
0
0
2chs
Hi There, we have a search which covers multiple values as below (each field has a single value)| chartcount(serviceN...
by 2chs Explorer in Splunk Search 10-07-2020
0 3
0
3
diconium
Hi.I created the following search which reports events of Active Directory users being locked aggregated by username:...
by diconium Explorer in Splunk Search 10-07-2020
0 7
0
7
igschloessl
I have a search which counts all ids events of the last 12 months by the severity. This search needs really long to r...
by igschloessl Explorer in Splunk Search 10-07-2020
0 1
0
1
arjit
Hi All, In our distributed deployment we are getting the issue where 100% schedule searches are skipped failing due t...
by arjit Path Finder in Splunk Search 10-07-2020
0 2
0
2
bowesmana
I have a saved search that does:   | from datamodel:"Performance.Storage"   But, I am trying to make this saved searc...
by SplunkTrust SplunkTrust in Splunk Search 10-06-2020
0 2
0
2
promukh
Hello Experts,I  am having a search as below   |search | eval _time=new_t | timechart span=1mon sum(alloc) as used | ...
by promukh Path Finder in Splunk Search 10-06-2020
0 2
0
2
adj24
Hi, I have the following search:search| spath input=rawJsonData output=UserActionAttributes path=UserActionAttributes...
by adj24 Engager in Splunk Search 10-06-2020
1 2
1
2
antaeuslogan
Good evening,I am trying to configure two radio buttons. I want the first radio button (a csv file in a table form wi...
by antaeuslogan New Member in Splunk Search 10-06-2020
0 1
0
1
splunkcol
 I know that someone may have asked this, but the truth is I did not find anything similar.I need to create a query f...
by splunkcol Builder in Splunk Search 10-06-2020
0 2
0
2
MattPainting
I am trying to figure out how to get data out of the event and into a field. I need to get all the data in brackets.S...
by MattPainting New Member in Splunk Search 10-06-2020
0 2
0
2
MarcRiese
Usually I find an individual alert, i.e., a saved search, among a large number of alerts by searching for it by name....
by MarcRiese Explorer in Splunk Search 10-06-2020
0 1
0
1
adrianrepublic
I have a set of devices that are identified by a very long 15 number. The first 8 numbers are just a prefix which we ...
by adrianrepublic Explorer in Splunk Search 10-06-2020
1 3
1
3
jdmclemore
Today is 10/2/2020. I need to execute 6 searches using relative time for last month (earliest= & latest=) that are ea...
by jdmclemore Path Finder in Splunk Search 10-06-2020
1 6
1
6
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...