Splunk Search

Splunk Search
Community Activity
felipesodre
{<!-- --> "DbMaintenanceDailyRoutineSummary": {<!-- --> "success": [ {<!-- --> "server-002": [ {<!-- --> "vacuum"...
by felipesodre Path Finder in Splunk Search 06-29-2020
0 7
0
7
assennikolov
I have the following case: I have 3 different indexes (A, B and C). My goal is to find what percentage of the devices...
by assennikolov Explorer in Splunk Search 06-29-2020
0 4
0
4
Zakary_n
Hello, was looking at this topic : https://answers.splunk.com/answers/112838/how-can-you-restrict-a-timechart-to-di...
by Zakary_n Path Finder in Splunk Search 06-29-2020
0 6
0
6
Sam1
Hi,I've created a search which is based on 1 field value but I need the search to run over many field values.  Rather...
by Sam1 Explorer in Splunk Search 06-28-2020
0 2
0
2
sharathk0525
I have a repeating j son payload appearing in my logs.I am interested in capturing the last payload from the logs.rig...
by sharathk0525 Observer in Splunk Search 06-28-2020
0 5
0
5
Shashank_87
Hi, I am trying to show a comparison of traffic on my website for today, yesterday and last week. I am using below qu...
by Shashank_87 Explorer in Splunk Search 06-28-2020
0 3
0
3
Inayath_khan
Hi Folks, Can anyone please help in forming the query for internal splunk components up and downtime reporting, i f...
by Inayath_khan Path Finder in Splunk Search 06-28-2020
0 2
0
2
smahuja
Hi, I have two different queries, I want to join two columns.Below is my query: &#96;macro&#96;msg&#61;"Finish import*" OR msg &#61; ...
by smahuja Explorer in Splunk Search 06-28-2020
0 1
0
1
thedonaldblake
Hello - I am a Splunk newbie.datetimeSrc_machine_nameCol1Col31/1/2020Machine1Value1Value21/2/2020Machine1Value1Value5...
by thedonaldblake Engager in Splunk Search 06-28-2020
0 1
0
1
vplunk
Is there a method to do "AND" while writing regex instead of "OR" . As when i write a reg and add to regex _raw&#61;"expr...
by vplunk Explorer in Splunk Search 06-28-2020
0 2
0
2
rakes568
Lets say my data is like this: 8/27/12 10:30:00.000 AM server&#61;test1 and status&#61;Down 8/27/12 10:29:00.000 AM server&#61;t...
by rakes568 Explorer in Splunk Search 06-28-2020
1 5
1
5
snagatho
Hellois there a length limit in the search.? I have been using NOT operator in my query extensively due to error code...
by snagatho New Member in Splunk Search 06-27-2020
0 1
0
1
whoami_root
I'm trying to delete dups using this method here: https://community.splunk.com/t5/Splunk-Search/How-to-delete-duplica...
by whoami_root Observer in Splunk Search 06-27-2020
0 1
0
1
seva98
I have list of around 100 hosts that are sending data to index and I would love to return a table with hostname and s...
by seva98 Path Finder in Splunk Search 06-26-2020
0 2
0
2
spkriyaz
Hi,I have used the below saved search to append the data every 15 mins into the lookup file. I use the lookup file in...
by spkriyaz Path Finder in Splunk Search 06-26-2020
0 6
0
6
sideview
(I am reposting this question from email, with permission from the person who emailed)I need to basically join 3 inde...
by SplunkTrust SplunkTrust in Splunk Search 06-26-2020
0 5
0
5
john_byun
I have the following query for PAN firewall logs:index&#61;pan app&#61;ssl| stats count by srcThis would give me a list of al...
by john_byun Path Finder in Splunk Search 06-26-2020
0 3
0
3
gopiven
Hi Splunk ExpertsI've created a summary index where it contains 6 eval cases, for example:eval 1&#61;case(match(something...
by gopiven Explorer in Splunk Search 06-26-2020
0 3
0
3
Wheresmydata
Hi Splunkers,I have different queries that get the age of a ticket only counting the business hours. I need to do dif...
by Wheresmydata Explorer in Splunk Search 06-26-2020
0 3
0
3
clgzcom
This site can’t be reached localhost refused to connect. Did you mean http://localhost8000.com/? Search Google for lo...
by clgzcom New Member in Splunk Search 06-26-2020
0 12
0
12
mrhodes93
Considering the following two messages: sourcetype&#61;"PCF:log" cf_app_name&#61;app1 msg&#61;"launch processing started" UserID:...
by mrhodes93 Explorer in Splunk Search 06-26-2020
0 3
0
3
medsy
how can i read or get data from .txt file without monitoring(indexing) the file data.
by medsy Explorer in Splunk Search 06-26-2020
0 1
0
1
kirrusk
Trying to display Percentages on Timechart , but it's not working. Base search | fields APP Usage_kb | eval Usage_gb&#61;...
by kirrusk Communicator in Splunk Search 06-26-2020
0 3
0
3
kuriakose
aid                              SHAabc                          12345                                  12345ujdk    ...
by kuriakose Explorer in Splunk Search 06-26-2020
0 2
0
2
priyaramki16
Hi,I am writing a search to create 3 columns of data P,F and C based on Teams.The table which I expect is thisTeamsPC...
by priyaramki16 Path Finder in Splunk Search 06-26-2020
0 2
0
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors