Splunk Search

Splunk Search
Community Activity
sarit_s
Hello i have a raw with 5 columns from the same type and i want to compare the value of the cells of this 5 columns....
by sarit_s Communicator in Splunk Search 05-13-2020
0 7
0
7
ansif
How to pass arguments to a script from inputs.conf? example: shell_script.sh server1 server2
by ansif Motivator in Splunk Search 05-13-2020
0 3
0
3
gurkiratsingh
Hi I am trying to make a time chart visualisation but I want it to be in IST(Indian Standard Time). | eval rece...
by gurkiratsingh Explorer in Splunk Search 05-13-2020
0 3
0
3
punyanit
Hello everyone, I am trying to join using "Table" as common field, here is my query. index=prod source=A | stats...
by punyanit Path Finder in Splunk Search 05-13-2020
0 4
0
4
surekhasplunk
Hi I am trying to add dynamic lookup file as the the date chosen by the user. And then use the same lookup file crea...
by surekhasplunk Communicator in Splunk Search 05-13-2020
0 0
0
0
snix
I am building out a report that lists all the lockouts during a given period of time. If I look at the Windows securi...
by snix Communicator in Splunk Search 05-13-2020
0 3
0
3
kejamder1
I log events from 30 devices every minute, and I'd like to be able to return a simple table of the count of events by...
by kejamder1 New Member in Splunk Search 05-12-2020
0 2
0
2
dgriffioen
We build our own app that only works in Python 3. I would like to know how to force Splunk to use python 3 for this a...
by dgriffioen Engager in Splunk Search 05-12-2020
0 5
0
5
Glasses
So I have the following _json event that I need to wrangle into a more useful format. As you can see there are 2 key...
by Glasses Builder in Splunk Search 05-12-2020
0 0
0
0
trever
I have events that happen in pairs. A request and a response from a server. What I would like to do is be able to eas...
by trever Loves-to-Learn in Splunk Search 05-12-2020
0 1
0
1
vrmandadi
I have *nix add-on installed on all our linux machines and we get all the default data from the add-on , which sourc...
by vrmandadi Builder in Splunk Search 05-12-2020
0 0
0
0
cglowjr
I am having trouble charting some data by hour and consoleID. Below is the search I used. I can use the stats func...
by cglowjr New Member in Splunk Search 05-12-2020
0 6
0
6
sriramsb
I have two indexes indexA and indexB . IndexA contains userID and Salary , IndexB contains userID, Name i want to pr...
by sriramsb New Member in Splunk Search 05-12-2020
0 1
0
1
prettysunshinez
Hi All, Would like to know if something like this will work or will there be any other possible solutions. Chart co...
by prettysunshinez Explorer in Splunk Search 05-12-2020
0 2
0
2
kavyakanne
Attached are my events I want rex to extract the highlighted text from the events and the events are logged under the...
by kavyakanne Engager in Splunk Search 05-12-2020
0 2
0
2
wwhite12
I have json data that comes in tracking ID's. An event is created when an ID is "created" and an event is created whe...
by wwhite12 Path Finder in Splunk Search 05-12-2020
0 4
0
4
sarahnazzar
Hi Splunkers! I'm trying to frame a query which fetches the list of servers that connects my deployment servers but ...
by sarahnazzar Explorer in Splunk Search 05-12-2020
0 7
0
7
sivajiy
Below query i am able to get the snap date. i need to capture correct date and timing. index=vmware-inv sourcetype=...
by sivajiy New Member in Splunk Search 05-12-2020
0 4
0
4
gndivya
Hi, There are 3 events that have been logged exactly at the same time say 2020-04-28 15:39:34. When the search quer...
by gndivya Explorer in Splunk Search 05-12-2020
0 2
0
2
swengroeneveld
Hi all, Since a few days I am in a battle regarding the following and I am on the loosing edge here. So all help is ...
by swengroeneveld Explorer in Splunk Search 05-12-2020
0 1
0
1
vinitpathri
i have a string 14/04/2020|A3|ABC149251|text i really need can i run something which will trim this string from th...
by vinitpathri Path Finder in Splunk Search 05-12-2020
0 6
0
6
pratapa
I am trying to create a souretype "meraki" on the GUI. But it is saying "Sourcetype meraki already exists" source...
by pratapa Explorer in Splunk Search 05-12-2020
0 3
0
3
isabel_ycourbe
When I run my tstat including a CIDR filter with summariesonly=T I got no result, while setting the parameter to fals...
by isabel_ycourbe Path Finder in Splunk Search 05-12-2020
0 4
0
4
cheriemilk
Hi team, I have below query. The base query has 440 events returned, But when I use stats command, tje number is 0...
by cheriemilk Path Finder in Splunk Search 05-11-2020
0 5
0
5
myeatman
I'm trying to report on successful login activity to S/FTP server via the following: host="my-ftp-server" sc_status=...
by myeatman Engager in Splunk Search 05-11-2020
1 2
1
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...