Splunk Search

Splunk Search
Community Activity
utk123
For my logs with IP and Vulnerability ID (VID), I have few duplicate values. Which I can easily remove with "dedup IP...
by utk123 Path Finder in Splunk Search 04-16-2020
0 9
0
9
area34
Hi, I tried to made a timechart (call duration) , the value I onyl have is the Users and the methods and the call ti...
by area34 New Member in Splunk Search 04-16-2020
0 4
0
4
indeed_2000
Hi I want to create chart that compare single values daily. for example want to compare (about 30 different product ...
by indeed_2000 Motivator in Splunk Search 04-16-2020
0 14
0
14
thomas_scheideg
We need to monitor multiple dynamic queues, queues are generated and removed. I have tried using "jms://queue/dynamic...
by thomas_scheideg Observer in Splunk Search 04-16-2020
0 0
0
0
zacksoft
I can't comprehend what 'eventstats' is. I went thru the splunk docs.I wanna use math functions like avg.. etc.. not ...
by zacksoft Contributor in Splunk Search 04-16-2020
1 3
1
3
stephenreece
hi all, bit of a strange one... The business has put a descriptor of the product as a field name and it would be ...
by stephenreece New Member in Splunk Search 04-15-2020
0 3
0
3
praveenkpatidar
Hello, I have one requirement in which certain columns have to be grouped together on a table. I have XSL sheet da...
by praveenkpatidar Explorer in Splunk Search 04-15-2020
0 3
0
3
mbasharat
Hi, I have vulnerability scanner that scans all device on our network every day. The agent of vulnerability scanner i...
by mbasharat Builder in Splunk Search 04-15-2020
0 5
0
5
jerinvarghese
I have below output from the splunk querry. Hostname INC Number Urgency Time_CST Description 1 CMPS3 ...
by jerinvarghese Communicator in Splunk Search 04-15-2020
0 2
0
2
keithdriver
Hi, I have two text columns finding_id and device manufacturer, and a count of events containing both. I'd like a s...
by keithdriver New Member in Splunk Search 04-15-2020
0 3
0
3
ryankub
I have a field that I know is an indexed field because I can specify on my search myfield::somevalue and get results....
by ryankub New Member in Splunk Search 04-15-2020
0 0
0
0
madhu06
I am having a issue tracker for tracking all opened issues and the query for the same is below: search issue_status=...
by madhu06 Engager in Splunk Search 04-15-2020
0 1
0
1
Thuan
I am working in an environment where there are several different constituencies. Each has different needs in terms o...
by Thuan Explorer in Splunk Search 04-15-2020
0 0
0
0
rarangarajanspl
Hello - I am new to Splunk. I would like to check whether it's feasible to format a table. In the screen shot 1, i ha...
by rarangarajanspl Explorer in Splunk Search 04-15-2020
0 5
0
5
manish095
I have a table having many multi-value fields. For example: items, cp and sp are multivalue fields. Using the followi...
by manish095 New Member in Splunk Search 04-15-2020
0 8
0
8
ataunk
I want to write a query to take the count if two non-consecutive string occurs in a statement. I am trying to do some...
by ataunk Explorer in Splunk Search 04-15-2020
0 5
0
5
tinpelayee
Hello plp, I have this problem, i need to extract 2 fields of this event. [14/04/2020 16:17:49][INFO][http-8080-36][a...
by tinpelayee Engager in Splunk Search 04-15-2020
0 1
0
1
tmontney
Here's what I got so far: index="myindex" (host="192.168.0.100" OR host="192.168.0.101") (msg="login OK" OR msg="log...
by tmontney Builder in Splunk Search 04-15-2020
0 5
0
5
vijaysubramania
Hi, Need help in extracting the values from the below mentioned tags divisionID - Value:...
by vijaysubramania Path Finder in Splunk Search 04-15-2020
0 6
0
6
ayushmaan_22
Hi all, I have the following command:- | savedsearch issue_with_lookup team="$token$" team_from_roster="$token$" te...
by ayushmaan_22 Explorer in Splunk Search 04-15-2020
0 4
0
4
ram254481493
Hi , I looked the daily ingestion for an index i am seeing total data ingested in last 7 days to an index is 800 GB....
by ram254481493 Explorer in Splunk Search 04-15-2020
0 0
0
0
briancronrath
I have a lookup that recently stopped auto extracting fields. What I've noticed is that if I do a join, I can join i...
by briancronrath Contributor in Splunk Search 04-14-2020
0 1
0
1
ilya_resh
Hi, I need to extract multiple fields (from events that are coming via HEC) and assign an index based on the concaten...
by ilya_resh Engager in Splunk Search 04-14-2020
0 4
0
4
mitag
A number of applications and services in our environment use LOG4J for logging. Is there a CIM (Common Information Mo...
by mitag Contributor in Splunk Search 04-14-2020
0 8
0
8
amomchilov
I have a dataset of Nginx (a web server) request logs. Each entry contains a client_ip. I want to impose some rate li...
by amomchilov Explorer in Splunk Search 04-14-2020
0 5
0
5
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...