Splunk Search

Splunk Search
Community Activity
kjonesdba_lm
These rows have a field that begins and ends with a quote, but have different meanings between the backslashes. 1st a...
by kjonesdba_lm Explorer in Splunk Search 06-04-2020
1 14
1
14
prakashmca05
Hi, I have to extract the sum of particular search output from my query and the same needs to be compared with previ...
by prakashmca05 Explorer in Splunk Search 06-04-2020
0 3
0
3
spkriyaz
I have a column called "message" which has duplicate records in it. I want to create a new column named "serial" besi...
by spkriyaz Path Finder in Splunk Search 06-04-2020
0 1
0
1
uagraw01
My query index=main source=secure.log sourcetype=* | stats earliest(_time) as start, latest(_time) as stop | eval ...
by uagraw01 Motivator in Splunk Search 06-04-2020
0 1
0
1
ferivas
Hi Splunk colleagues, I'm having a problem with multiselect in my dashboards. Here's the code of the multiselect: <in...
by ferivas New Member in Splunk Search 06-04-2020
0 2
0
2
admin12345678
Hi,I am having some problem to understand the usage of "(?msi)" with rex command,please help me regarding that?
by admin12345678 Path Finder in Splunk Search 06-04-2020
0 3
0
3
vdalvi
Hi, How can I display the actual value of the difference in a new column? The value is "cts16k1sacc". Row 1 in attac...
by vdalvi Explorer in Splunk Search 06-04-2020
0 4
0
4
Mike6960
I am trying to make an overview with different counts. The message always starts with : logger="blahblah-main.Start*"...
by Mike6960 Path Finder in Splunk Search 06-04-2020
0 3
0
3
jmasat
There are approximately 1.5 Billion ingested entries from 40 forwarders.Performing a search with any criteria on Wind...
by jmasat Observer in Splunk Search 06-04-2020
0 5
0
5
ludoz13
Hi all, I'd like to get value on a field to my previous event to compare this same field with the current value Expla...
by ludoz13 Path Finder in Splunk Search 06-04-2020
0 6
0
6
wgawhh5hbnht
I would like to take the following search that generates the hashes and outputs the lookup: index=windows source="Xml...
by wgawhh5hbnht Communicator in Splunk Search 06-04-2020
0 3
0
3
mbasharat
Hi, I have dateset that contains IP addresses. IP Addresses are coming in variations due to ranges they are assigned...
by mbasharat Builder in Splunk Search 06-04-2020
0 7
0
7
agrandville
Hi everybody, When parsing a long string containing escaped double-quotes I get this error: Error in 'rex' command: r...
by agrandville Explorer in Splunk Search 06-04-2020
0 8
0
8
hjainreddy
What is the use of command modifier in layman terms, please I don't know what it does apart from the understanding th...
by hjainreddy New Member in Splunk Search 06-04-2020
0 3
0
3
williamhardykim
I am unable to whitelist input, I do not understand why, my Splunk is ingesting data from a c-icap server logfile and...
by williamhardykim New Member in Splunk Search 06-04-2020
0 4
0
4
richard_bragg
We have a set of logs from different hosts that specify a metric. I want to display a line graph over a user-selectab...
by richard_bragg New Member in Splunk Search 06-04-2020
0 12
0
12
ellstream44
I have one search that checks for entries with duration >= 50000 (responses for requests) source="abc.log" | regex "\...
by ellstream44 Explorer in Splunk Search 06-03-2020
0 12
0
12
MarianaPereira
Hello!!! I need to calculate the percentage between the rows in my table, like this, for example: Search: | bucket sp...
by MarianaPereira New Member in Splunk Search 06-03-2020
0 2
0
2
vinitpathri
i have a field "add_time" with the values as "05-27-2020 08:57:34.024" i want to create a field which will show 45 da...
by vinitpathri Path Finder in Splunk Search 06-03-2020
0 4
0
4
englab
I would like to search for AWS non-active users, who have not logged in or using their Access Key ID for more than 60...
by englab New Member in Splunk Search 06-03-2020
0 0
0
0
sbuchenberger
I recently left a company where I had taken some Splunk training through the Splunk account the company gave me.I now...
by sbuchenberger New Member in Splunk Search 06-03-2020
0 3
0
3
tmaltizo
I am currently grabbing a date (openDate, actualenddate) and using strptime in order to reformat it to Splunk's expec...
by tmaltizo Path Finder in Splunk Search 06-03-2020
0 4
0
4
govardha
I am new to Splunk. The cluster command gives me results that I am looking for and some. I would like to filter th...
by govardha Path Finder in Splunk Search 06-03-2020
0 0
0
0
DEAD_BEEF
I am trying to create a dashboard that graphs the parsing queue size for a HF by ingest_pipe. I noticed that most of...
by DEAD_BEEF Builder in Splunk Search 06-03-2020
0 3
0
3
shivareddysompa
my data Name spent income A 10 20 B 20 40 C 30 60 A 40 8...
by shivareddysompa Explorer in Splunk Search 06-03-2020
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...