| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hello all, The question is self explanatory I think. I've seen similar questions that are resolved with an eval, but ...
        
       
         
           by 
           
                
                    
                        andrewtrobec
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-30-2018
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello
  I noticed a lot of the events not the same timestamp as Splunk. Can you tell me how I can compare the date of...
        
       
         
           by 
           
                
                    
                        dfall
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Splunk Search
           
           
              
               07-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Events stream has ID field in every record.  There is a lookup table with a small subset of IDs.The task is to calcul...
        
       
         
           by 
           
                
                    
                        pm771
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        [2020-07-07 12:40:01+0200] workspace_sandbox RUNNING pid 17159, uptime 21 days, 21:43:58
   
  i have this line of lo...
        
       
         
           by 
           
                
                    
                        sphiwee
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               07-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Estou com este comando
  index = raw_maximo GR_RESP = STATUS "OPERACAO MAINFRAME"! = Cancelado | contagem de estatíst...
        
       
         
           by 
           
                
                    
                        Marcosecpinheir
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hello all,
  Looking for some help integrating a lookup table into my failed login search. What I am trying to achiev...
        
       
         
           by 
           
                
                    
                        tkerr357
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Search
           
           
              
               07-01-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Events are not getting generated after the date 15th June, 2019 for the following query.
  index=webmethods_prd sourc...
        
       
         
           by 
           
                
                    
                        pratapa
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-18-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  16
	 
 | |||
| 
      
        hello 
  i begin with splunk and i have Something complex to need i need to index the data coming from the Windows ta...
        
       
         
           by 
           
                
                    
                        jip31
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               06-26-2018
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Anyone come up with a custom sourcetype for Genesys Application logs. ? 
        
       
         
           by 
           
                
                    
                        Stav
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Can anyone tell me how I would replace entire strings if they contain partial strings. As a basic example, in my sear...
        
       
         
           by 
           
                
                    
                        darls15
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        We have a field called number and the field number has both alpha and numeric values like "number=AVAILABLE=25 USD;" ...
        
       
         
           by 
           
                
                    
                        iamsplunker
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        My base query:index=... sourcecode=...  |  timechart span=1m count as number by name useother=f   In the result I hav...
        
       
         
           by 
           
                
                    
                        pm771
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I am having data like this in my Splunk and I wanted to extract the value of status which is Active.
  How can I do i...
        
       
         
           by 
           
                
                    
                        kotig
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I am trying to tune an alert but need to only exclude if 2 of three fields do not contain a string.  My goal is too t...
        
       
         
           by 
           
                
                    
                        byeb1264
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hello, 
  Trying to add several maps to a dashboard. One map for each continent, except North America. 
  How do I lo...
        
       
         
           by 
           
                
                    
                        genesiusj
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi everyone,I am unable to calculate average of the given values. However, I am getting values corresponding to min()...
        
       
         
           by 
           
                
                    
                        Kazi1
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I'm trying to use the python sdk to build a custom search command. In my commands.conf, I have "chunked = true" set. ...
        
       
         
           by 
           
                
                    
                        scottsavareseat
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-29-2020
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        We see lots of alerts right now.  So I thought I would develop a dashboard that quickly searches through the alert co...
        
       
         
           by 
           
                
                    
                        chris94089
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Good morning! I noticed today that a couple of my devices stopped sending logs to Splunk a couple of hours ago. I wan...
        
       
         
           by 
           
                
                    
                        rogueakula
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello!I’m trying to replace product codes with product names like| replace “A1” with “Apple”, “A2” with “Grape”, “A3”...
        
       
         
           by 
           
                
                    
                        maxmukimov
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Here is my search: 
  
   index=database action_id="CR" OR action_id="AL" database_name= "test" NOT (server_principal...
        
       
         
           by 
           
                
                    
                        rnikam1412
                    
                
           
             
             
               Loves-to-Learn Everything
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        The goal is to compare the events from this hour vs the past hour. And then display a table by sourcetype, host, perc...
        
       
         
           by 
           
                
                    
                        catherineang
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               10-03-2018
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I have the same problem as in the link below: 
  [https://answers.splunk.com/answers/336929/how-can-i-get-time-picker...
        
       
         
           by 
           
                
                    
                        christoffertoft
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               11-10-2017
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  12
	 
 | |||
| 
      
        Good afternoon,I am trying to Masking an email address at the search head level I have tried using Rex and sed but ca...
        
       
         
           by 
           
                
                    
                        joe06031990
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               07-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I have a boat load of log files, whose name contains the timestamp, like this :  /DATA/show_cpu.2016101908.gz /DATA/s...
        
       
         
           by 
           
                
                    
                        gent79
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Search
           
           
              
               10-20-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 |