Splunk Search

Splunk Search
Community Activity
bullriser
Hello, i have a splunk query like this  index=someindex container_name=app ( cookie=*cookie1" OR cookie="cookie2" ) e...
by bullriser New Member in Splunk Search 07-22-2020
0 1
0
1
chris94089
I'm performing a REST Search that ends with a | table command When I configure the script to csv format, I get 5 even...
by chris94089 Path Finder in Splunk Search 07-22-2020
0 1
0
1
lifekis
I have a problem with parsing, so I want to change the sourcetype. ex) index=A sourcetype=A  →  index=A sourcetype=B ...
by lifekis Explorer in Splunk Search 07-22-2020
0 8
0
8
MBashiri
Hi As you know one of the latest vulnerability was CVE-2020-0688 on microsoft exchange server. so I'm trying free spl...
by MBashiri New Member in Splunk Search 07-22-2020
0 2
0
2
renanprado96
I saw an explanation of the "refresh", up the .conf files and I found the _bump command, but do not know what it is f...
by renanprado96 Path Finder in Splunk Search 07-22-2020
0 3
0
3
jwalzerpitt
I have a generic search that is looking for logins and there is a field that has two values – “authentication” for a ...
by jwalzerpitt Influencer in Splunk Search 07-22-2020
0 3
0
3
ryastrebov
Hello! I need to provide search only in earliest source in my sourcetype. I use this search request for this purpose...
by ryastrebov Communicator in Splunk Search 07-22-2020
1 6
1
6
Username1
So suppose that everyday Splunk takes in a report that houses 9 different fields, one of which is called 'status'. St...
by Username1 Path Finder in Splunk Search 07-22-2020
0 2
0
2
paxo
Hi all, I need to show the number of concurrent logged users within the last 30 days. What I would like to have is a ...
by paxo Loves-to-Learn Lots in Splunk Search 07-22-2020
0 1
0
1
davietch
Hello,Let me give you an example. I've got the following table to work with:src_groupdest_groupcountAB10BA21AC32BZ6 I...
by davietch Path Finder in Splunk Search 07-22-2020
0 9
0
9
vvvinamer
Getting incomplete (lesser number of events as results ) when using rest API. The same search i run in the splunk ent...
by vvvinamer Engager in Splunk Search 07-22-2020
0 4
0
4
rahul2gupta
Hi @gcusello ,When I am running the following  query it is working fine .|dbquery wmsewprd "select REC_TYPE, CODE_TYP...
by rahul2gupta Path Finder in Splunk Search 07-22-2020
0 9
0
9
mani
I have a date field in "%m/%d/%Y" format.I need to find the week number of this date and find the same week number of...
by mani Explorer in Splunk Search 07-22-2020
1 2
1
2
veerendra_modi
Not able to see my lookup while creating an automatic lookup.While creating an automatic lookup i am not able to see ...
by veerendra_modi Loves-to-Learn in Splunk Search 07-22-2020
0 0
0
0
nadlurinadluri
HI Splunkers, I am looking for some help on loops in splunk. I have a lookup file like below.from,toparent,child1pare...
by nadlurinadluri Communicator in Splunk Search 07-22-2020
0 4
0
4
vvvinamer
If i run a post search method, it returns a sid. How would i come to know that the search is complete and that when i...
by vvvinamer Engager in Splunk Search 07-22-2020
0 4
0
4
kiru2992
Hello,  I have events with id, status that is collected everyday for all the ids. I would like to know when the time(...
by kiru2992 Path Finder in Splunk Search 07-22-2020
0 5
0
5
jasoneaton
I have a query that I'm trying to get the amount of time a transaction takes to execute. I was selecting only a piece...
by jasoneaton Engager in Splunk Search 07-21-2020
0 3
0
3
ddelmont
Splunkers,I sure hope this is just user error and I am myopic today! Have a simple macro: collectevents(2) args=index...
by ddelmont Explorer in Splunk Search 07-21-2020
0 2
0
2
aravindsurya77
My query looks like thisindex=* sourcetype="MYSOURCE"  | table company_id | dedup company_id | where company_id != "-...
by aravindsurya77 Observer in Splunk Search 07-21-2020
0 3
0
3
john_snow
I am using below query index=aws earliest=-12h eventName=AuthorizeSecurityGroupIngress "items{}.cidrIp"="0.0.0.0/0" A...
by john_snow Engager in Splunk Search 07-21-2020
0 1
0
1
Nadeige
Hello,I have some log events that are structured like that:<timestamp> - [INFO] <serialnumber 1><timestamp> - [INFO] ...
by Nadeige New Member in Splunk Search 07-21-2020
0 2
0
2
leandromatperei
I have the result below in a table, but for some technical reasons I need to check these values ​​in a bar chart, but...
by leandromatperei Path Finder in Splunk Search 07-21-2020
0 1
0
1
fsiemons
Hi there, I have a bit of a tough one.I have a log with multiple entries of the same field, basically a list of value...
by fsiemons Engager in Splunk Search 07-21-2020
0 1
0
1
joe06031990
How do I extract a string of numbers using Rex to work the AVG out from a string to a number As it is showing as blan...
by joe06031990 Communicator in Splunk Search 07-21-2020
0 5
0
5
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...