Splunk Search

Splunk Search
Community Activity
sarumathi
1. If the same JobName field name is already exists,Trying to get average of column value of JobName's elapsedtime va...
by sarumathi Loves-to-Learn Lots in Splunk Search 08-02-2020
0 0
0
0
smusunuri
Is there way to move "Open in Search, Inspect, Refresh, and Export" widgets in Splunk Dashboard-tables?
by smusunuri Explorer in Splunk Search 08-02-2020
1 2
1
2
mprad
We have java based rest service A with logfile a.log and another rest service B with log b.logwhen A receives a reque...
by mprad New Member in Splunk Search 08-02-2020
0 1
0
1
cyberfan
I have one txt file, only one column, the txt file has around 60 SHA-256 hashes. these hashes are from malicious file...
by cyberfan Explorer in Splunk Search 08-02-2020
0 1
0
1
cyberfan
there are some malware enabled by word Macro and run VB script to communicate to outside. I want to find out what are...
by cyberfan Explorer in Splunk Search 08-02-2020
0 1
0
1
HeinzWaescher
Hi, is it possible to jump to the next line in the search window, to make the whole search more readable? Thanks H...
by HeinzWaescher Motivator in Splunk Search 08-02-2020
0 6
0
6
awmorris
Imagine the following data set:STUDENTEOY_GRADEGENDERSTUDENT_STATUSAlice96FemaleACTIVEBob94MaleACTIVECandice92FemaleF...
by awmorris Path Finder in Splunk Search 08-01-2020
0 3
0
3
Naren26
Is there any possibility to remove an entire column if all the values of the column are zero?
by Naren26 Path Finder in Splunk Search 08-01-2020
0 4
0
4
mangopickle
I will need an additional day to complete the final quiz for Fundamentals 3 if this doesn’t come up in next couple of...
by mangopickle New Member in Splunk Search 08-01-2020
0 1
0
1
warren_h
I have a scenario where when a device checks in, it sends multiple records of it's inventory with the same time stamp...
by warren_h Observer in Splunk Search 07-31-2020
0 3
0
3
CarbonCriterium
Hello,I am looking to figure out the percentage of times certain value combinations appear in the data.   The field I...
by CarbonCriterium Path Finder in Splunk Search 07-31-2020
0 3
0
3
splunktest_
I have a query statement like so   index=* "account balance:" | rex "blah blah account balance:(?P<balance>(\d{1,3}(,...
by splunktest_ Loves-to-Learn Lots in Splunk Search 07-31-2020
0 2
0
2
kvallala
I am looking at setting up Search/Alert if i see an only "ERROR OGG-01296", however don't want to receive any alert w...
by kvallala Explorer in Splunk Search 07-31-2020
0 2
0
2
hirschel
HI, I am looking for something that is the 'opposite' of dedup; where the duplicate events are kept, and singular eve...
by hirschel New Member in Splunk Search 07-31-2020
0 1
0
1
gpSplunk123
hi, i'm trying to use an eval variable in my search. i've tried many different things and i've failed, and i'm sure t...
by gpSplunk123 Engager in Splunk Search 07-31-2020
0 3
0
3
splunktest_
I'm a noobie here, and I'm trying to figure out how to search for all outward bound data. How does one accomplish thi...
by splunktest_ Loves-to-Learn Lots in Splunk Search 07-31-2020
0 1
0
1
chris94089
I want to test an HEC script that is hosted remotely by pointing it to the Splunk instance at my desk.Up to this poin...
by chris94089 Path Finder in Splunk Search 07-31-2020
0 1
0
1
djohnson99
Hi there We presently have a setup where error codes are extracted and put into their own field.  The way it's been s...
by djohnson99 Explorer in Splunk Search 07-31-2020
0 2
0
2
deepakaakula
Hi,I have alerts when the number goes above certain % of the disk usage. So there are alerts at 70, 80, 90. It works ...
by deepakaakula Explorer in Splunk Search 07-31-2020
0 8
0
8
puppy0723
Hi, I am a beginner of SPLUNK and SPL. Recently I am asked to replace my statistic table from excel  into SPLUNK to c...
by puppy0723 New Member in Splunk Search 07-31-2020
0 0
0
0
cbakes
I am trying to use the results of dnslookup to pivot the results to query my index.| makeresults| eval domain="google...
by cbakes New Member in Splunk Search 07-31-2020
0 1
0
1
kgrahamLM
Can I use the map command with the variable being the index and/or sourcetype?| makeresults| eval User = "12345", ind...
by kgrahamLM Observer in Splunk Search 07-31-2020
0 7
0
7
shravanikarale
I want to display earliest invested amount based on type (stock,fd,mutual fund,etc) over a month and want to keep num...
by shravanikarale Loves-to-Learn Lots in Splunk Search 07-31-2020
0 0
0
0
shugup2923
Hi All,We have a dashboard which uses three layers of tabs- (please refer attached screenshot)Issue- when we load the...
by shugup2923 Path Finder in Splunk Search 07-31-2020
0 1
0
1
jwebster0000
Currently when building a pivot table the default time is set to "All Time". Is it possible to set it to some other v...
by jwebster0000 Engager in Splunk Search 07-31-2020
2 8
2
8
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...