Splunk Search

Splunk Search
Community Activity
wfskmoney
We want to parse highly nested jsons into expanded tables. We found that the following code works, given we apply the...
by wfskmoney Path Finder in Splunk Search 04-20-2020
0 2
0
2
iet_ashish
Hello there, Is there a way to address all fields case insensitively. To illustrate my point I have this query, ind...
by iet_ashish Explorer in Splunk Search 04-20-2020
0 1
0
1
coolkris
I am trying to create a result set out of 2 search queries with a common field.I have tried multiple solutions provid...
by coolkris New Member in Splunk Search 04-20-2020
0 3
0
3
iet_ashish
I have a query which essentially looks like this, | makeresults count=1 | eval host="host1, host2, host3, host4, ho...
by iet_ashish Explorer in Splunk Search 04-20-2020
0 5
0
5
navap123
I have 6 sources with json event in the following structure (each source with different data of tests): "tests": [...
by navap123 Explorer in Splunk Search 04-20-2020
0 3
0
3
mpd202004
Hello community, I am using search to get the values for ‘runtime’ and trying to get overall stats for a runtime va...
by mpd202004 New Member in Splunk Search 04-20-2020
0 3
0
3
a212830
Hi, I'm testing out some features in 6.3, and looking at increasing our search and index throughput. One of the set...
by a212830 Champion in Splunk Search 04-19-2020
1 6
1
6
manakin
There is a dropdown filter on the dashboard. How can I select multiple values ​​for that filter?
by manakin New Member in Splunk Search 04-19-2020
0 2
0
2
kulwindersandhu
I have a logic which I want to implement in Splunk, but I'm getting confused with the syntax.Let me explain what I am...
by kulwindersandhu New Member in Splunk Search 04-19-2020
0 1
0
1
Testeur971
Hi, I wonder test different pattern matching (format spl) dynamically with a field value without use the command "ma...
by Testeur971 New Member in Splunk Search 04-19-2020
0 13
0
13
tkdguq0110
I just want to create csv file automatically everyday for example, today just is created 20200417.csv tomorrow will ...
by tkdguq0110 Path Finder in Splunk Search 04-19-2020
0 4
0
4
motaghis
There are three conditions in my eval: 1) date=2019-Present, '"/2019","/2020"' 2) date=2019, " /2019" 3) date=2020,...
by motaghis Explorer in Splunk Search 04-18-2020
0 6
0
6
asoma0707
Hi, I am novice to splunk and trying to learn explore things in it. Currently I am stuck with one problem while extr...
by asoma0707 New Member in Splunk Search 04-18-2020
0 5
0
5
bsaujla131984
I am trying to create an alert which will check how many messages are stuck in the queue and whats the age of message...
by bsaujla131984 Path Finder in Splunk Search 04-18-2020
0 8
0
8
valkyrie
After manually installing splunkforwarder-5.0.3-163460-x64-release.msi on Windows Server 2008 R2 and specifying index...
by valkyrie Engager in Splunk Search 04-18-2020
3 2
3
2
mbasharat
Hi, I have data that contains Sessions ID labeled as (SES) and User ID labeled as (ABC). When I look at the events...
by mbasharat Builder in Splunk Search 04-18-2020
0 6
0
6
riqbal47010
I have a sample data from email logs where we have from and message size. how can I extract "Top ten sending address...
by riqbal47010 Path Finder in Splunk Search 04-18-2020
0 2
0
2
dshpritz
When I run a search in Splunk 6.x, the results come back quickly, but it seems like a lot of time is spent on "Finali...
by SplunkTrust SplunkTrust in Splunk Search 04-18-2020
8 18
8
18
pargupta1234
As of now, we use CSV lookups but some of the lookups are around 2 GB which is creating a problem in SH replication. ...
by pargupta1234 New Member in Splunk Search 04-18-2020
0 0
0
0
remartins
I am very new with Splunk. I started lerning it with on line courses. I need to configure Forwarding in heavy forwa...
by remartins New Member in Splunk Search 04-18-2020
0 1
0
1
genesiusj
Hello, I want to change the field "other(n)" in a pie chart within the search results, not in a dashboard panel. Inst...
by genesiusj Builder in Splunk Search 04-17-2020
0 0
0
0
echalex
Hi, Short explanation of my problem: I'm investigating a problem where two file downloads are apparently interrupted...
by echalex Builder in Splunk Search 04-17-2020
1 11
1
11
gvssaicharan
I built a regular expression to extract fields from a log file. However, after extracting I am not able to display th...
by gvssaicharan Engager in Splunk Search 04-17-2020
0 3
0
3
ddrillic
A similar question as in Is there a way to prevent users from saving knowledge objects in the Searching and Reporting...
by ddrillic Ultra Champion in Splunk Search 04-17-2020
0 7
0
7
wwhite12
Is there a way to rename the extracted fields in the Interesting Fields section? Example would be Interesting Fields...
by wwhite12 Path Finder in Splunk Search 04-17-2020
0 3
0
3
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors