Splunk Search

Splunk Search
Community Activity
anandhalagaras1
Hi All,We are planning to ingest the SQL login success and failure logs into Splunk. So  in the logs there are lot of...
by anandhalagaras1 Contributor in Splunk Search 08-12-2020
0 5
0
5
uhaq
I'm running Cisco AMP events input on Splunk 8 on python 2.7.17 and received the following error after configuring th...
by uhaq Explorer in Splunk Search 08-12-2020
0 0
0
0
chris_barrett
Cisco eStreamer eNcore Add-on for Splunk v3.6.8 has two EXTRACTs with errors in them. EXTRACT-extract_src and EXTR...
by SplunkTrust SplunkTrust in Splunk Search 08-12-2020
2 1
2
1
zza2009
Hi, I'm using an "eval myvar=case(...)" like the one in the splunk documentation: ... | eval description=case(error ...
by zza2009 Engager in Splunk Search 08-12-2020
3 4
3
4
here2infinity
I have logs that say both contact and non contact. I would like to distinguish them in a search with the complete "no...
by here2infinity Explorer in Splunk Search 08-12-2020
0 1
0
1
ma_anand1984
How can i find index of last occurrence of letter in value of a field string splunk_user microsoft_good_task god_pa...
by ma_anand1984 Contributor in Splunk Search 08-12-2020
0 6
0
6
Snehaan
Hello,I have a search string like below, where it is fetching data from stage and giving out aggregates of Trades for...
by Snehaan Explorer in Splunk Search 08-12-2020
0 16
0
16
georgear7
I have below kind of data.App Name StatusApp1                0App2               0App3               0App4           ...
by georgear7 Communicator in Splunk Search 08-12-2020
0 4
0
4
MJA411
Hello Splunk members!I currently have a search that produces "Users" connecting to certain "hosts" whereas the status...
by MJA411 Explorer in Splunk Search 08-12-2020
0 0
0
0
jameswatts
I have a search that returns the diff of two times, but the user wants it in "1 day 5 hours and 23 minutes" format no...
by jameswatts Explorer in Splunk Search 08-12-2020
0 3
0
3
jodros
I need assistance building a search that looks back in time 5 minutes to check and see if fields are present.  If so ...
by jodros Builder in Splunk Search 08-11-2020
0 6
0
6
pm771
I have an index where each event has unique EventID and Status fields.Each event is progressing through multiple inte...
by pm771 Communicator in Splunk Search 08-11-2020
0 2
0
2
adnankhan5133
All of our Splunk users, including members of our Leadership Team are currently in the US/Eastern time zone. All of t...
by adnankhan5133 Communicator in Splunk Search 08-11-2020
0 3
0
3
sbuxplat
Hi All, I am trying to access Splunk from inside the Azure Databricks instances. I have requirements to run queries f...
by sbuxplat Observer in Splunk Search 08-11-2020
0 0
0
0
bapun18
HiI have a dashboard, my requirement is like when a user will select a value Splunk in a multi-select, my pannel quey...
by bapun18 Communicator in Splunk Search 08-11-2020
0 6
0
6
stoneyhrm
Currently I have splunk injecting AWS logs showing NACL's. Each event has an array that is called network_acl_entries...
by stoneyhrm Observer in Splunk Search 08-11-2020
0 1
0
1
leandromatperei
 Dear, I need to identify some duplicate events that are right after the "Call-ID:", however in Splunk I am not getti...
by leandromatperei Path Finder in Splunk Search 08-11-2020
0 1
0
1
trevorkubheka
struggling to extract underlined items as RUN NAME 
by trevorkubheka New Member in Splunk Search 08-11-2020
0 4
0
4
adnankhan5133
I currently have the following SPL query that generates a table, and appears as follows:Service IDResource NameTransa...
by adnankhan5133 Communicator in Splunk Search 08-11-2020
0 1
0
1
mputtam
Hi Community,I was trying to pull the logs  in the following format _time, src, dest, src_port, dest_port by using st...
by mputtam Path Finder in Splunk Search 08-11-2020
0 1
0
1
wu_weidong
Hi all,I'm trying to set the search period such that "earliest" is a specific day, and "latest" is 7 days after that....
by wu_weidong Path Finder in Splunk Search 08-11-2020
0 1
0
1
lukas
Hi,I have a lookup file like this -users:User1User2User3User4...I need to count the events by user:index=myindex | st...
by lukas Loves-to-Learn in Splunk Search 08-11-2020
0 2
0
2
dkgs
Hello,Below query in wmi.conf file is not returning any events . But other queries are working.Please do suggest if a...
by dkgs Communicator in Splunk Search 08-11-2020
0 0
0
0
wbolten
Hi, The following SPL returns records to me as shown below.   index="uf_basickpi" host!=DS-* (sourcetype="CPU" counte...
by wbolten Path Finder in Splunk Search 08-11-2020
0 2
0
2
shashank_24
Hi, I am stuck at a query problem. So what i need to do is join some events and get the result and for that I am usin...
by shashank_24 Path Finder in Splunk Search 08-11-2020
0 5
0
5
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...