Splunk Search

Splunk Search
Community Activity
avanijjain16
Hi, I am new to splunk, I am trying to extract specific message from my log event. The pattern I am looking from belo...
by avanijjain16 Explorer in Splunk Search 09-30-2020
0 4
0
4
msplunk33
SPL query to get the ADHOC search or saved search (with user info) which consumed maximum memory and CPU for the past...
by msplunk33 Path Finder in Splunk Search 09-30-2020
0 2
0
2
SausagePizzza
Hello,Using the o365:management:activity logs, I'm trying to create a search where I:Get a list of users and their IP...
by SausagePizzza Engager in Splunk Search 09-30-2020
0 1
0
1
olivne
HiI have this table: customer | city A | NY B | NY A | LA and I want to replace the value in `cu...
by olivne Engager in Splunk Search 09-30-2020
0 1
0
1
help_me_pls
Hey,I have a splunk instance digesting nmap results. Each host that is found on the network generates an event that h...
by help_me_pls New Member in Splunk Search 09-30-2020
0 1
0
1
dglass0215
I have a csv lookup that has a column with numerical data (specifically integers).  When I do the lookup, splunk is t...
by dglass0215 Path Finder in Splunk Search 09-30-2020
0 1
0
1
rajkskumar
I have the following query used to build a chart. Sometimes, the incoming events do not have the fields set. How coul...
by rajkskumar Explorer in Splunk Search 09-30-2020
0 4
0
4
andrewcg
We recently upgraded to from 7.1.2 to 8.0.3 on on-prem Splunk Enterprise. A previously working saved search is no lo...
by andrewcg Path Finder in Splunk Search 09-30-2020
0 4
0
4
msplunk33
Is there any query to get the list of  all indexes under a specific index cluster.
by msplunk33 Path Finder in Splunk Search 09-30-2020
0 1
0
1
mah
Hi, I have a search ending like this : | chart count over service by environment| where prod>50 OR OR dev>50 It retur...
by mah Builder in Splunk Search 09-30-2020
0 2
0
2
EricFSplunker
Hi, My team will be performing an upgrade from Splunk Cloud. We need to understand how all of our artifact types chan...
by EricFSplunker Engager in Splunk Search 09-30-2020
1 0
1
0
k31453
Hi I have following LARGE lookup with over 1000 entries|host | type ||host1 |            ||host2 |            ||host3...
by k31453 Explorer in Splunk Search 09-30-2020
0 9
0
9
changyu
Is there a way to get the difference between column A and column B and output in column CColumn A.          Column B....
by changyu New Member in Splunk Search 09-30-2020
0 1
0
1
Sasquatchatmars
Hi all! I have been trying to compare a search with a CSV lookup table. So far no luck... The list contains only 1 co...
by Sasquatchatmars Communicator in Splunk Search 09-30-2020
0 4
0
4
vamshiverma
Hello,I want to display the total count of events and failed events count. In my case, it is determined by the field ...
by vamshiverma Explorer in Splunk Search 09-30-2020
0 10
0
10
Sasquatchatmars
Hi all,I have succesfully made a search to populate a CSV file thanks to @gcusello , this file lets me add Usernames ...
by Sasquatchatmars Communicator in Splunk Search 09-30-2020
0 10
0
10
pahujadeep
I have data in below format Data Input 1 :  index=abcTime (YYYY-MM-DD HH24)Count12020-09-30 00102020-09-30 01202020-0...
by pahujadeep Explorer in Splunk Search 09-30-2020
0 1
0
1
TrAnS
Hi, i am trying to do a search which can shows which internal client accessed the web but i have a proxy to access th...
by TrAnS Loves-to-Learn in Splunk Search 09-29-2020
0 1
0
1
tb5821
I'm trying to list out all dates between my time picker and have that as a column in my table. I do both things indiv...
by tb5821 Communicator in Splunk Search 09-29-2020
0 4
0
4
nfdavenport
I have a web application where each incoming request is given a unique requestID so we can see all the logs for that ...
by nfdavenport Observer in Splunk Search 09-29-2020
0 2
0
2
mushkevych
I am trying to make this query work: index="main" | eval host=asset_id | collect index="scanned_app" where asset_id i...
by mushkevych Explorer in Splunk Search 09-29-2020
0 11
0
11
rabrahaham
Hello All,We created a custom search on splunk which calculates a specific metric on all the servers that are part of...
by rabrahaham Engager in Splunk Search 09-29-2020
0 1
0
1
havatz
Hi when i ran this query:  "| tstats count, values(\"Authentication.tag\") as tag from datamodel=Authentication where...
by havatz Explorer in Splunk Search 09-29-2020
0 2
0
2
kevinsteeee
Hi! I'm searching for an appropriate agent to transmit Windows Event log to syslog server. Can Universal Forwarder co...
by kevinsteeee Explorer in Splunk Search 09-29-2020
0 2
0
2
ng87
Hi all Trying to build a query and struggling in "comparing" two fields. Essentially this is what i am trying to do 1...
by ng87 Path Finder in Splunk Search 09-29-2020
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors