Splunk Search

Splunk Search
Community Activity
joe06031990
How do I extract a string of numbers using Rex to work the AVG out from a string to a number As it is showing as blan...
by joe06031990 Communicator in Splunk Search 07-21-2020
0 5
0
5
summerura
Hi Splunkers! This is just an example from splunk. And it is a just similar visualization what i want to. Except a po...
by summerura Explorer in Splunk Search 07-21-2020
0 1
0
1
joe06031990
Hello, I am using the stats command however the AVG shows as being blank yet min and max works fine: Index=index_ tes...
by joe06031990 Communicator in Splunk Search 07-21-2020
0 8
0
8
bidhanjena13
Hi,I have a sample data as following, for multiple date, separate space stats.{"object":"DOC1","date":"2020-06-13","w...
by bidhanjena13 Engager in Splunk Search 07-21-2020
0 1
0
1
chris94089
Searching for events in _audit is special because when I run a search, my own ad-hoc search gets added to the returne...
by chris94089 Path Finder in Splunk Search 07-21-2020
0 5
0
5
avni26
Hi,I have field as Jan , Feb ,Mar .... Dec with values for each month and I want to take sum of current month and las...
by avni26 Explorer in Splunk Search 07-21-2020
0 1
0
1
stefan1988
What should I use to put a TAB literally in a regex replacement within transforms.conf? I've tried \t but that's not...
by stefan1988 Path Finder in Splunk Search 07-21-2020
0 4
0
4
akkaraju
Hi All,I have a query where I am passing one field from the output( outer query )to the another query  using subsearc...
by akkaraju Explorer in Splunk Search 07-21-2020
0 6
0
6
nagas
Hi All,how to get data from starting day of this week till today and starting day of last week till same day in last ...
by nagas Explorer in Splunk Search 07-21-2020
0 4
0
4
nandhiniG
HI , I have a log message like " total accounts for user is 11 retrieved in 67 milliseconds". How to extract 11 as to...
by nandhiniG Explorer in Splunk Search 07-21-2020
0 2
0
2
jotaforense
I would like to obtain the results of two tables.| dbxquery query = "select * from table1 " connection = "Connection1...
by jotaforense Explorer in Splunk Search 07-20-2020
0 4
0
4
cheriemilk
Hi team,I have below 2 events:C_BN="[{pmRating:3},{riskOfLoss:9}]"C_BN="[{sysOverallPerformance:3},{sysOverallPotenti...
by cheriemilk Path Finder in Splunk Search 07-20-2020
0 2
0
2
xiangli9
We have 5 host and 3 on west 2 on east, and each of them take x% of request, the stats we have right now looks like:h...
by xiangli9 Observer in Splunk Search 07-20-2020
0 1
0
1
aaroncherian
Hello, I have a search running that shows the custom "Sign-on_Time" field in a table. I want to format it to a more r...
by aaroncherian Path Finder in Splunk Search 07-20-2020
0 8
0
8
brytox
HIIm trying to get data from an object containing an array, and my search returns some of the results but i cant see ...
by brytox New Member in Splunk Search 07-20-2020
0 1
0
1
gnoriega
Hi,I'm trying to detect brute force activity by detecting multiple auth failures followed by success.  I started with...
by gnoriega Explorer in Splunk Search 07-20-2020
0 5
0
5
rbal_splunk
 there has been a huge spike in the number of uploads, resulting in many more failed uploads from throttling than we ...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 07-20-2020
0 1
0
1
shravanikarale
I want to convert a column of text values into  percentage.STATUSontimelateontimelate
by shravanikarale Loves-to-Learn Lots in Splunk Search 07-20-2020
0 3
0
3
Itai5468
Hi everyone,I have some data with a lot of fields.Some fields represent the same data, but with different field names...
by Itai5468 New Member in Splunk Search 07-20-2020
0 1
0
1
MLGSPLUNK
Hi All.I have a local instance on my laptop for demo purposes, so no complex deployment on this machine.I have create...
by MLGSPLUNK Path Finder in Splunk Search 07-20-2020
0 15
0
15
amerineni
index= base search | stats count, avg(ElapsedTime) as duration,  by requestName, LogType, errorMessage, HttpStatus, i...
by amerineni Loves-to-Learn in Splunk Search 07-19-2020
0 3
0
3
Janani_Krish
Hello,I have tried the following command to forecast recipient using predict command and Forecast time series assista...
by Janani_Krish Path Finder in Splunk Search 07-19-2020
0 2
0
2
bcusick
Hi, I'm trying to compare events from two sources to show where the outliers are (they "should" be the same but we k...
by bcusick Communicator in Splunk Search 07-19-2020
0 9
0
9
mztopp
All users are located under POP_Address. If the POP_Address = 192.168.* or 172.16.*, etc, we consider them to be inte...
by mztopp Explorer in Splunk Search 07-19-2020
0 3
0
3
oompaloompa
Seems pretty simple, but it's kicking my butt so here I am. I've tried more variations than I'd like, but I have a to...
by oompaloompa Loves-to-Learn Lots in Splunk Search 07-19-2020
0 11
0
11
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors