Splunk Search

Splunk Search
Community Activity
rbw78
Hello, I have some events into splunk which I would like to compare with today's date less than 30 days. I want to e...
by rbw78 Communicator in Splunk Search 04-21-2020
5 10
5
10
sridharlakshman
Hi Folks, we are ingested the aws vpc flow logs in splunk and able to see the data while searching with index but wh...
by sridharlakshman New Member in Splunk Search 04-21-2020
0 14
0
14
3DGjos
Hello, i'm doing a report (splunk 7.3) in which I need to append some counts in the first row of the table im generat...
by 3DGjos Communicator in Splunk Search 04-21-2020
0 3
0
3
s_kandula
Hi I have two events with following fields Event 1 Log.Status : IN TransactionTime : IN time Tracking id: Unique ID...
by s_kandula Observer in Splunk Search 04-21-2020
0 3
0
3
rizwan0683
Looking to exclude certain values for field instance. How can I achieve this? Propose code (not working) index=abc so...
by rizwan0683 Path Finder in Splunk Search 04-21-2020
0 3
0
3
yepyepyayyooo
I do not have any admin privilege in my Splunk instance and cannot change any configuration. Need to search an index ...
by yepyepyayyooo New Member in Splunk Search 04-21-2020
0 3
0
3
Shashank_87
Hi, I have a list column with different values and i want to count the number of occurence of a specific value. For e...
by Shashank_87 Explorer in Splunk Search 04-21-2020
0 4
0
4
user93
Hello, I've always had trouble with automatic lookups and every time I manage to do it it seems that I do it differe...
by user93 Communicator in Splunk Search 04-21-2020
0 0
0
0
codedtech
I have a search that looks at the output of a few scripts and lets me know if they are not running. These scripts c...
by codedtech Path Finder in Splunk Search 04-21-2020
0 1
0
1
danielbb
We have the following code: | stats count min(_time) as min, max(_time) as max by src, .... | eval delta = (max - mi...
by danielbb Motivator in Splunk Search 04-21-2020
1 2
1
2
treverce
I have a dashboard (form) that I'm trying to allow a text field to accept single values or comma separated values tha...
by treverce Explorer in Splunk Search 04-21-2020
0 5
0
5
jiaqya
i have a table data where in a row has 0's . i need to replace those 0 only for that row ex: rowname:data one:5 two...
by jiaqya Builder in Splunk Search 04-21-2020
0 3
0
3
indeed_2000
on splunk when i want to do field extraction ask me source type. and when I open this listbox show files on that path...
by indeed_2000 Motivator in Splunk Search 04-21-2020
0 0
0
0
joepjisc
I cannot find this question being asked this way round, so hopefully its not a duplicate. I have a lookup CSV like t...
by joepjisc Path Finder in Splunk Search 04-21-2020
0 5
0
5
splunkuser2127
I have 3 fields: "Runtime_A", "Runtime_B", and "guid". My current query is: search | chart values(guid) AS "Guid", ...
by splunkuser2127 Loves-to-Learn in Splunk Search 04-20-2020
0 2
0
2
splunkbeginner
the search (thanks for who provided this) is: | tstats count where host=linux01 sourcetype="linux:audit" by _time sp...
by splunkbeginner Engager in Splunk Search 04-20-2020
0 8
0
8
MwayneSmith
someone suggested a join, but as a newbie...... Don't know how to do this. I believe I would need two searches, 1 b...
by MwayneSmith Explorer in Splunk Search 04-20-2020
0 1
0
1
pkeller
Given a list of CIDR ranges ... 10.198.68.132/30, 10.244.18.150/31, 10.48.37.96/24 Is there a search that could extr...
by pkeller Contributor in Splunk Search 04-20-2020
0 2
0
2
splunkuser2127
I have 3 extraction fields: "guid", "runtime_general", "runtime_specific". There is also a value "A" that I will sea...
by splunkuser2127 Loves-to-Learn in Splunk Search 04-20-2020
0 0
0
0
nocostk
I'm trying to use the field extraction tool. The problem is that the field I want to extract is about 18 lines down ...
by nocostk Communicator in Splunk Search 04-20-2020
0 4
0
4
bntdumas
Hello All, I spent a lot of time trying to figure out how to fill out missing data with approximations based on the ...
by bntdumas Engager in Splunk Search 04-20-2020
0 6
0
6
loc_spl
Hi folks, I'm having a hard time with this one. Maybe I need more coffee. Say I have several events like this: Event...
by loc_spl New Member in Splunk Search 04-20-2020
0 1
0
1
warmup031
Hello, I would like to know how to find searchs that do not succeed (no results or with errors) ? Some users complain...
by warmup031 Explorer in Splunk Search 04-20-2020
0 2
0
2
malgru
Hello I am trying to get a regex to work in splunk but without success, perhaps someone here can help me? This work...
by malgru New Member in Splunk Search 04-20-2020
0 3
0
3
wfskmoney
We want to parse highly nested jsons into expanded tables. We found that the following code works, given we apply the...
by wfskmoney Path Finder in Splunk Search 04-20-2020
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors