Splunk Search

Splunk Search
Community Activity
lstewart_splunk
I have this data_timeEventCodeMessage2020-06-16T19:48:53+00:004136Too late now2020-06-16T19:49:53+00:001234I don't kn...
by lstewart_splunk Splunk Employee Splunk Employee in Splunk Search 08-18-2020
0 3
0
3
codichulo
Heres what i'm trying to accomplish: requestID               status123456                   errored321654            ...
by codichulo Loves-to-Learn in Splunk Search 08-18-2020
0 3
0
3
vrulev_algn
Hi,I can't grasp the concept of dedup_splitvals. I was writing search for a pie chart on my dashboard, something like...
by vrulev_algn Loves-to-Learn in Splunk Search 08-18-2020
0 0
0
0
vinod0313
Helloi got result like below from the splunk queryABC123DEF456GHI789But i want to show like belowABCDEFGHI
by vinod0313 Explorer in Splunk Search 08-18-2020
0 3
0
3
bapun18
Below is my existing query :i want to add ceratin common feilds with different value for the respective indexes .How ...
by bapun18 Communicator in Splunk Search 08-18-2020
0 2
0
2
vinod0313
HelloI have a log like this:ABC=true,DEF=false,GHI=false,JKL=trueI want to show only ABC and JKL in the result,becaus...
by vinod0313 Explorer in Splunk Search 08-18-2020
0 3
0
3
Abhi89
This is the search i am using to extract key/value from the field  "RID" with multivalued "DEF"| rex max_match=0 fiel...
by Abhi89 New Member in Splunk Search 08-18-2020
0 2
0
2
dieguiariel
Hi, ive successfully blacklisted the windows event 4658 with this line_blacklist2 = $XmlRegex="<EventID>4658<\/EventI...
by dieguiariel Path Finder in Splunk Search 08-18-2020
0 3
0
3
driva
Hi guys,I'd like to be able to allow 'insecure' logins for my dashboards to be used with an internal signage solution...
by driva Path Finder in Splunk Search 08-18-2020
0 2
0
2
mpaw
Hi All,I am trying to extract fields using spath command. I noticed that fields with period in it cannot be extracted...
by mpaw Explorer in Splunk Search 08-17-2020
0 4
0
4
normand1
I'm trying to create a search that always looks for the responses from the latest version of my app. The `version` fi...
by normand1 Engager in Splunk Search 08-17-2020
0 2
0
2
splunker12er
Is there any online regex tool to create regular expressions for given sample data ?
by splunker12er Motivator in Splunk Search 08-17-2020
2 11
2
11
hugohctint
Hello, I have a Field with Oracle SQL_BIND and a second field with the SQL_TEXT, the SQL_BIND contains the values wh...
by hugohctint Loves-to-Learn Lots in Splunk Search 08-17-2020
0 9
0
9
weidertc
I have an issue where logs contain timestamps in zulu and the server uses local time for its index.  I need to calcul...
by weidertc Contributor in Splunk Search 08-17-2020
0 13
0
13
tromero3
I have a saved search which runs every month and looks at my vulnerability events and outputs the results into a look...
by tromero3 Path Finder in Splunk Search 08-17-2020
0 4
0
4
ssaini5
Hello,I have a raw data file from which I am trying to extract data and create a dashboard out of it. From this raw f...
by ssaini5 Explorer in Splunk Search 08-17-2020
0 1
0
1
skahal_personal
Hello I have noticed that in some of my dashboards, especially the more complicated ones with multiple sub searches t...
by skahal_personal New Member in Splunk Search 08-17-2020
0 0
0
0
sphiwee
Can someone show me what the regex expression for the below extract would be? & can you show me how you arrived to th...
by sphiwee Contributor in Splunk Search 08-17-2020
0 5
0
5
sahilarora
Hi Guys,I have a .csv lookup file that maintain the 'inactive' accounts list. can anyone help me with a query to remo...
by sahilarora Loves-to-Learn in Splunk Search 08-17-2020
0 1
0
1
Abraham1234
Hey, I am using splunk 6.x and on another system splunk 8.x with similar data backends.  when I do a search for:index...
by Abraham1234 Loves-to-Learn Lots in Splunk Search 08-17-2020
0 2
0
2
suraj44
I have a data file , this source file does not contain any data on most days .. Its a valid scenario only . But since...
by suraj44 Engager in Splunk Search 08-17-2020
0 2
0
2
anil15694
Hi,In order to remove an index, how can we be sure that the index is not getting used?What should we check before rem...
by anil15694 Explorer in Splunk Search 08-17-2020
0 2
0
2
Lucie99
Hi everyone,I need to put in these fix values on the Interval_tolerance column. Has somebody an idea ? Thanks
by Lucie99 Explorer in Splunk Search 08-17-2020
0 3
0
3
vdalvi
Hi,Below is my search query:index=abc host=xyz source=abcdef| rename size AS RootObject.size topicName AS RootObject....
by vdalvi Explorer in Splunk Search 08-17-2020
0 2
0
2
gn694
I am trying to create a field extraction for events from the source: WinEventLog:Microsoft-Windows-TerminalServices-G...
by gn694 Communicator in Splunk Search 08-17-2020
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...