Splunk Search

Splunk Search
Community Activity
jhantuSplunk
I am breaking every line in flat file and trying to fetch the field using rex, this is how my events looks like: 98...
by jhantuSplunk New Member in Splunk Search 05-27-2020
0 3
0
3
khanlarloo
I have json logs that I want to extract.I did All items related to field extraction in props.conf file. my log {"expo...
by khanlarloo Explorer in Splunk Search 05-26-2020
0 9
0
9
keyu921
I have following dataemail|country|licenseaa|HK|365E1bb|US|365E2cc|HK|non-officedd|HK|non-officeee|UK|non-office I wo...
by keyu921 Explorer in Splunk Search 05-26-2020
0 3
0
3
chinmay25
We used the inner join command to get the matching files. However, the same command does not work with the current fo...
by chinmay25 Path Finder in Splunk Search 05-26-2020
0 6
0
6
stevenshea
After searching the answered questions, I do not see my question addressed. If I have several indexes that are frozen...
by stevenshea New Member in Splunk Search 05-26-2020
0 3
0
3
hethu
Hi, I am new to splunk and trying to create a timeline with several individual calculated trend lines, but I simply c...
by hethu Path Finder in Splunk Search 05-26-2020
0 3
0
3
nwoolley
Hi! In the Event column, I get the following: 26/05/2020 11:24:51 > Invoice Val Increase on History Report process c...
by nwoolley Engager in Splunk Search 05-26-2020
0 2
0
2
pdantuuri0411
I often see the below entries in the scheduler.log[1] which are getting skipped. We have 15 alerts set in which 2 run...
by pdantuuri0411 Explorer in Splunk Search 05-26-2020
1 3
1
3
user93
Hello, I have a list of strings that are more meaningful when grouped and viewed together by time. This is great and...
by user93 Communicator in Splunk Search 05-26-2020
0 2
0
2
trever
I have a search using timechart count by [value] and I'd like to set up an alert for when any of the values reach mo...
by trever Loves-to-Learn in Splunk Search 05-26-2020
0 0
0
0
ashanka
I have a column duration with this time format: 01:20:00.000000. How do I convert time format from 01:20:00.000000 ...
by ashanka Explorer in Splunk Search 05-26-2020
0 3
0
3
woodcock
I am doing it with Pie Chart and Trellis but that starts paginating at 20 and there is no way to expand that (JIRAs =...
by Esteemed Legend in Splunk Search 05-26-2020
0 11
0
11
xnx_1012
When I run this SPL, the transaction commands gives the correct output index=* source=/var/log/secure* (TERM(sudo) ...
by xnx_1012 Explorer in Splunk Search 05-26-2020
0 1
0
1
gnshah12345
I have 400+ error codes and want to search them. The issue is my search for multiple codes for 5 months freezes (th...
by gnshah12345 Observer in Splunk Search 05-26-2020
0 2
0
2
angersleek
I have the following working Query for a single product AHSDFKSD1 ns=a* DECISION IN (ELIGIBLE, INELIGIBLE) PRODUCT I...
by angersleek Path Finder in Splunk Search 05-26-2020
0 2
0
2
yepyepyayyooo
Good morning Splunkers, I trust everyone is remaining safe. Ultimately, I'm attempting to obtain the overage connecti...
by yepyepyayyooo New Member in Splunk Search 05-26-2020
0 2
0
2
srinivreddy
Hi Team I have requirement to get api's triggered by per custkey in a single query query 1: /token host="test-host-...
by srinivreddy New Member in Splunk Search 05-26-2020
0 4
0
4
raphaalmeida
Hello everyone, We just integrate Splunk with McAfee ePO via DB Connect. We're trying to get some informations from...
by raphaalmeida New Member in Splunk Search 05-26-2020
0 6
0
6
guo_dc
I created an alert w/ a basic search: index=_internal | stats count Cron Expression: */1 * * * * Al...
by guo_dc Explorer in Splunk Search 05-26-2020
0 3
0
3
keyu921
I setup testing.csv lookup as followinghost,location123,HK234,US345,UK I would like to basic search if host matched i...
by keyu921 Explorer in Splunk Search 05-25-2020
0 3
0
3
oxnard
Hi there, I couldn't find this question already on here. Hopefully it's a simple one. I use Splunk regularly in my ...
by oxnard Engager in Splunk Search 05-25-2020
6 6
6
6
pipipipi
Hi all, I have this search: |table a b date |eval c=a-b |stats sum(*) as * by date date a b c 2019-01 5 3 2 2019-02...
by pipipipi Path Finder in Splunk Search 05-25-2020
0 1
0
1
hrs2019
II am using this lookup for bot status. I am using the "submit" button to save the status info. (disconnected or con...
by hrs2019 Path Finder in Splunk Search 05-25-2020
0 5
0
5
prettysunshinez
What does |rename field* AS * do. How to rename the fields when there are more no.of fields. Thanks
by prettysunshinez Explorer in Splunk Search 05-24-2020
0 1
0
1
verbal_666
Hi. I would like to know if there is a simple way, via Splunk XML, to create a "for cycle" like routine, to generate ...
by verbal_666 Builder in Splunk Search 05-24-2020
0 6
0
6
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...