Splunk Search

Splunk Search
Community Activity
michaelsplunk1
Can the cluster command cluster based on more than one field? I know we can change which field to cluster by, but can...
by michaelsplunk1 Path Finder in Splunk Search 07-13-2020
0 2
0
2
jerinvarghese
HI All,need your help in below query. I use below query to get below output.Query : index=nw_syslog| rex field=_raw "...
by jerinvarghese Communicator in Splunk Search 07-13-2020
0 3
0
3
sivaranjiniG
Will a parentheses Surrounded SPL queries make any difference?For Example:(index IN (“indexA*”,”indexB*”) source=”sou...
by sivaranjiniG Communicator in Splunk Search 07-13-2020
0 5
0
5
caplog
Hallo,I would like to investigate the login behaviour of users. I use this search:I receive the following example log...
by caplog Engager in Splunk Search 07-13-2020
0 1
0
1
Madhuranthakan
Dear Folks,I've the below two different type of events, the matching attributes from first event to second event are,...
by Madhuranthakan Loves-to-Learn Lots in Splunk Search 07-13-2020
0 0
0
0
pwild_splunk
Hi,I'm after suggestions on how to best approach this problem.I want to track over time how often I am seeing a mac a...
by pwild_splunk Splunk Employee Splunk Employee in Splunk Search 07-13-2020
0 1
0
1
rock_s
Hi Experts, I have data as shown below, Whenever we run the search, if the current time is greater than start time we...
by rock_s Engager in Splunk Search 07-13-2020
0 13
0
13
sphiwee
I have the query below, but i i dont want the services to like this.. how can i get the names of the services to be v...
by sphiwee Contributor in Splunk Search 07-13-2020
0 1
0
1
skodak
AccountName FAILURE SUCCESS IMPACT LOSS% TotalAccount120001490.111.3310804Account220812620.109.552043Account316301554...
by skodak Explorer in Splunk Search 07-12-2020
0 5
0
5
Nidd
My log sample looks like this: testServiceName,testTransName,DEVTEST,,,3375598402,15,754,5,2020-07-11 18:41:31.982,20...
by Nidd Path Finder in Splunk Search 07-12-2020
0 2
0
2
thl8490123
Hi, I manage to get the view i want using below search command.  May I know how to group the events by Month_Year for...
by thl8490123 New Member in Splunk Search 07-12-2020
0 4
0
4
Noob_splunker
Hi,How do I compare dates and exclude the event if it is older?I have here my table from transaction command. I want ...
by Noob_splunker Explorer in Splunk Search 07-11-2020
0 3
0
3
adamsimpsondevo
Our universal forwarders can no longer connect to the indexer, seemingly after upgrading openssl to the newest versio...
by adamsimpsondevo Engager in Splunk Search 07-11-2020
1 2
1
2
skodak
statussuccesssuccess failurefailureerrorerror I want output like status         status 1 status2success   failure    ...
by skodak Explorer in Splunk Search 07-10-2020
0 3
0
3
rome75
I have a field called lookup_key that contains either a host name or an IP address.  I am trying to get a lookup on t...
by rome75 Engager in Splunk Search 07-10-2020
0 1
0
1
to4kawa
https://github.com/splunk/botsv3https://www.splunk.com/en_us/blog/security/botsv3-dataset-released.htmlI'm starting t...
by to4kawa Ultra Champion in Splunk Search 07-10-2020
0 1
0
1
felipesodre
Hi Everyone. Thanks in advance for any help.I am trying to extract some fields (Status, RecordsPurged)  from a JSON o...
by felipesodre Path Finder in Splunk Search 07-10-2020
0 4
0
4
maxmukimov
Hi, I’m trying to get product count for yesterday and 7 days ago from yesterday in two separate fields, results are c...
by maxmukimov Explorer in Splunk Search 07-10-2020
0 6
0
6
michaelsplunk1
Is there a way to set the maximum cluster size for the clusters generated by the "cluster" command?
by michaelsplunk1 Path Finder in Splunk Search 07-10-2020
0 1
0
1
dv2323
I'd like to display stats based on a custom string within a log entry.  Below is sample of the log entry.  I'd like t...
by dv2323 Explorer in Splunk Search 07-10-2020
0 6
0
6
nesslee
Hello, I would like to set up statistics on the visited websites by the users. I would like to find all users who vis...
by nesslee Observer in Splunk Search 07-10-2020
0 2
0
2
nesslee
Hello everyone,When a user visits a website, it can make hundreds of separate requests related to advertising. So i w...
by nesslee Observer in Splunk Search 07-10-2020
0 1
0
1
mah
Hi,My issue is : I want to create a field from random data string (always the same) which is not present in all logs....
by mah Builder in Splunk Search 07-09-2020
0 3
0
3
mkhan_splunk
I want to remove spaces from starting and ending of field I was trying to achieve this using ... | rex mode=sed fie...
by mkhan_splunk New Member in Splunk Search 07-09-2020
0 8
0
8
promukh
Hello  Splunkers,Please advise how to use regex to extract the below specific fields from _raw data and also add/rena...
by promukh Path Finder in Splunk Search 07-09-2020
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...