Splunk Search

Splunk Search
Community Activity
fabio_lourenco
Currently I am trying to optimize my application and I would like to know if it is possible to use TERM() with a data...
by fabio_lourenco Explorer in Splunk Search 04-29-2020
0 5
0
5
seva98
Hi, I believe that my Splunk's Python has some issue during initialization. This happens whenever I try to run any o...
by seva98 Path Finder in Splunk Search 04-29-2020
0 6
0
6
poddraj
Hi Can someone help me in getting o/p over 1h interval along with Total requests count, Success count, Failure count ...
by poddraj Explorer in Splunk Search 04-29-2020
0 2
0
2
sarvesh_11
Hi Splunkers, Ideally what happens is we set threshold for log file and set some retention. so files do get create l...
by sarvesh_11 Communicator in Splunk Search 04-28-2020
0 2
0
2
ssharma09
Hi Guys, I'm trying to convert events data into metric for CPU, Disk, Memory monitoring for Azure PAAS, using below ...
by ssharma09 Explorer in Splunk Search 04-28-2020
0 1
0
1
ksharma7
If say I have data from December to march in csv every 5 min , and no data from Marc to April.if say in month of nay ...
by ksharma7 Path Finder in Splunk Search 04-28-2020
0 1
0
1
pir8radio
@to4kawa You have helped me a lot the past few weeks, lol you will probably answer this one too!  So i have thes...
by pir8radio Path Finder in Splunk Search 04-28-2020
0 8
0
8
alwagia87
I'm hoping to get help. I have the below errors that are in the same event at in different lines. i would like to g...
by alwagia87 New Member in Splunk Search 04-28-2020
0 1
0
1
nawazns5038
Hi, I would like to extract field values from UI using the field transformations and field extractions from settin...
by nawazns5038 Builder in Splunk Search 04-28-2020
0 12
0
12
mihirpradhan
Hello, I have this subsearch command: [search source="local/data/user/logs/access*" status =5* | table request_id] ...
by mihirpradhan Explorer in Splunk Search 04-28-2020
0 2
0
2
john_dagostino
I've created two accelerated data models. As admin, I can search each of them with |tstats summariesonly=t FROM data...
by john_dagostino Path Finder in Splunk Search 04-28-2020
0 4
0
4
aelliott
I have a list of Cities in a field that are all lower case. Is there a way to capitalize them in search? Example: los...
by aelliott Motivator in Splunk Search 04-28-2020
1 6
1
6
sarit_s
Hello i want to write IF statement as part of my query and want it to run on time frame of 30 days or more... the qu...
by sarit_s Communicator in Splunk Search 04-28-2020
0 2
0
2
rogue670
I am looking for the proper SPL to capitalize the first letter of every word that follows a period. I have tried seve...
by rogue670 Engager in Splunk Search 04-28-2020
0 5
0
5
owie6466
hello splunkers! new to splunk and i am needing to extract a word from a message field. this is the message The Clust...
by owie6466 Explorer in Splunk Search 04-28-2020
0 4
0
4
zachsisinst
Hello, I've gone through a hundred of these types of posts and nothing is working for me. Here is the nested json arr...
by zachsisinst Explorer in Splunk Search 04-28-2020
0 4
0
4
apiprek2
Hi, I'm wondering if it's possible to do an outer/left join two tables on two fields. I have two indexes with the fo...
by apiprek2 Explorer in Splunk Search 04-28-2020
0 2
0
2
rtalcik
Hi All, so i clustered my search heads and added them to my index cluster. However it broke all my lookup tables. ...
by rtalcik Path Finder in Splunk Search 04-28-2020
0 1
0
1
MMCC
Hi all, I have already read several interesting questions regarding this topic. I'd like to verify which approach is...
by MMCC Path Finder in Splunk Search 04-28-2020
0 3
0
3
rtalcik
so in this search the full list is everything in zone A. do is everything in zone b, zoneserialnumbers are a list o...
by rtalcik Path Finder in Splunk Search 04-28-2020
0 6
0
6
indeed_2000
Hi have logs look likes below, and want to define where transaction begin and where finished. for example at ID654321...
by indeed_2000 Motivator in Splunk Search 04-28-2020
0 6
0
6
shivangisharma
for ex: if i am running the report on 5th of may, i will need the data from 1st of November till 30 apri and i l nee...
by shivangisharma New Member in Splunk Search 04-28-2020
0 1
0
1
1sebastinator
I am having trouble extracting individual events from a csv file with the data formatted in the following way. I have...
by 1sebastinator Explorer in Splunk Search 04-28-2020
0 4
0
4
arrangineni
I am trying to get counts of events that match only a particular field value pattern from a multi-valued field. Mul...
by arrangineni Path Finder in Splunk Search 04-28-2020
0 2
0
2
thaheseens
PII Leaked DNS Generator Anomaly Encrypted C and C Command Anomaly Command and Control Repudation Anomaly File Action...
by thaheseens Explorer in Splunk Search 04-28-2020
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...