Splunk Search

Splunk Search
Community Activity
mastoras
Hello team I would like to merge more events into one, currently my events look like this: 1st part {"log":"feign....
by mastoras Explorer in Splunk Search 04-28-2020
0 2
0
2
aditya22
Hi, I am trying to get the occurence of two strings for every 3 minute interval.Tried this. index=xyz host="hostna...
by aditya22 New Member in Splunk Search 04-28-2020
0 1
0
1
gavinsopra
I would like to change some of the formatting of a Statistics Table in a dashboard, specifically the following: head...
by gavinsopra Engager in Splunk Search 04-28-2020
0 13
0
13
oshirnin
Hello, everybody! I want to ask something that has already been asked several times but there is still no clear solu...
by oshirnin Path Finder in Splunk Search 04-28-2020
0 14
0
14
hrs2019
Hello everyone How I can resize the table length so that the scrolling option I can remove and I can see all the fi...
by hrs2019 Path Finder in Splunk Search 04-27-2020
0 12
0
12
fdevera
Hello, I have some fields that have multiple values in them and I need to split them out into their own rows. The fi...
by fdevera Path Finder in Splunk Search 04-27-2020
0 2
0
2
prabhan
Hi Splunkers, My external lookup working just fine and the results are proper. As mentioned in the below screensho...
by prabhan New Member in Splunk Search 04-27-2020
0 7
0
7
tkerr1357
Hello all, I am new to regex and struggling to get the Actual value field. I only need the number in between the quo...
by tkerr1357 Path Finder in Splunk Search 04-27-2020
0 4
0
4
smitapatankarso
I have some strings like below returned by my splunk base search: "CN=aa,OU=bb,DC=cc,DC=dd,DC=ee" "CN=xx,OU=bb,DC=cc...
by smitapatankarso Explorer in Splunk Search 04-27-2020
0 2
0
2
tom1981
I have the following search set up: search string | fields host raw | fields - _time _indextime _sourcetype _subsec...
by tom1981 Engager in Splunk Search 04-27-2020
0 4
0
4
lzamora33
Hi there, Really basic question but I can't find a detailed answer. Can someone explain the different uses of (), [...
by lzamora33 New Member in Splunk Search 04-27-2020
0 5
0
5
dpdwibedy
Hi , Sorry , if I am asking duplicate question. Looking for something like this.... 1) I have a list of source IPs ...
by dpdwibedy Explorer in Splunk Search 04-27-2020
0 4
0
4
iet_ashish
On running this search, | makeresults count=20 | streamstats count | eval "genie.name"="foo", "genie:id"="...
by iet_ashish Explorer in Splunk Search 04-26-2020
0 2
0
2
kpsg25690
Hello, I'm trying to build a dashboard using Splunk 6.2 and I've hit a snag. I want to color a cell in a table depen...
by kpsg25690 Engager in Splunk Search 04-26-2020
0 10
0
10
kabiraj
Hi Guys. I want to color the cells of my table based on the values that belong to columns other than the first colum...
by kabiraj Path Finder in Splunk Search 04-26-2020
1 3
1
3
nsudha1975
Here is my event log sample below [LOG LEVEL=INFO] [LOGGER=WIFI_ACCESS_INFO] [INTERFACE ID=WIFI_ACCESS] [STEP=START] ...
by nsudha1975 New Member in Splunk Search 04-26-2020
0 1
0
1
bestSplunker
I want to show the number of successes and failures in a single value panel. How should I do this? splunk version: 6...
by bestSplunker Contributor in Splunk Search 04-26-2020
0 1
0
1
ykwon7
Hello, Cloud you give me some tips. Search Query S1 index=S1 | bla bla bla | stats value(dstIP) value(dstPort) val...
by ykwon7 Observer in Splunk Search 04-26-2020
0 2
0
2
iet_ashish
I have this query which when I run, index=*aws_config* resourceType=TERM("AWS::EC2::Volume") | search ARN="arn:aws:...
by iet_ashish Explorer in Splunk Search 04-26-2020
0 2
0
2
raomu
Hello, I have a resultant data like this: Server Name Status Location Owner Email Id A-Z1 ...
by raomu Explorer in Splunk Search 04-26-2020
0 2
0
2
stembot
I have a search that uses the values in temp.csv file to generate an email for each row with specific values. Let's ...
by stembot New Member in Splunk Search 04-26-2020
0 9
0
9
landen99
Let's say that I want a search to run the main search under the time picker selection and then run a join over one da...
by landen99 Motivator in Splunk Search 04-25-2020
0 7
0
7
graju89
Hi, I have some issue with transaction command. It works fine. but sometimes endswith pattern appear and startswith p...
by graju89 Path Finder in Splunk Search 04-25-2020
0 1
0
1
sagartiwari
I am using below query where my A (0012ABC) Component is an alphanumeric and B is a string (ab) but its considering A...
by sagartiwari New Member in Splunk Search 04-25-2020
0 2
0
2
indeed_2000
hi i have log file like below need to extact the section after first "]" to "[" or "." or ":" 2020-04-24 23:59:59,51...
by indeed_2000 Motivator in Splunk Search 04-25-2020
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...