Splunk Search

Splunk Search
Community Activity
willadams
I have a Deploy server application that I use to control my "SYSLOG" server that receives logs from various other sou...
by willadams Contributor in Splunk Search 04-01-2020
0 6
0
6
gmasy
Hello everyone, I am trying to extract some data from the logs. I have created a little search that works well: cus...
by gmasy New Member in Splunk Search 04-01-2020
0 10
0
10
tmanuel1
Hi guys! I am looking to get the number of tickets that are completed in under 14 days, 30 days, 45 days and 45+ days...
by tmanuel1 New Member in Splunk Search 04-01-2020
0 3
0
3
dmenon
Hi - We want to get users connected in 1 hour. When a user connects we get event_id="globalprotectgateway-auth-succ" ...
by dmenon Explorer in Splunk Search 04-01-2020
0 2
0
2
augustocadini
I'm newer of splunk. On my log I've a JSON with two fields of interested: "initialCreationDate":"2020-03-02T00:00:00"...
by augustocadini New Member in Splunk Search 04-01-2020
0 1
0
1
i17065
I have 2 searches for systems & folders. Both searches return a table. The fields systemID & folderID have the same v...
by i17065 Engager in Splunk Search 04-01-2020
0 8
0
8
Justin_Grant
What is the role of props.conf vs. transforms.conf in field extraction? How do they relate to each other in order to ...
by Justin_Grant Contributor in Splunk Search 04-01-2020
4 4
4
4
jacqu3sy
Hi, How do I write a regex to capture whenever I see any combination of 10 digits followed by .zip within a _raw eve...
by jacqu3sy Path Finder in Splunk Search 04-01-2020
0 9
0
9
msyparker
Hello!  I'm tryng to get statistics of groups of 200 events. For instance, I have the following stats: |stats su...
by msyparker Explorer in Splunk Search 04-01-2020
0 1
0
1
prasadmissesu
I have a query like this: | mstats rate(request_total) as request_rate prestats=true WHERE index="index-metrics" AN...
by prasadmissesu New Member in Splunk Search 04-01-2020
0 1
0
1
genesiusj
Hello, I'm having a time conversion issue with any earliest or latest time that is not in epoch. Here is my XML code ...
by genesiusj Builder in Splunk Search 04-01-2020
0 9
0
9
vlape_SCWX
I am at a loss as to why the following is not working. log: 2020-03-31 20:31:19,621 fail2ban.actions [709]...
by vlape_SCWX New Member in Splunk Search 04-01-2020
0 6
0
6
joeybroesky
Need help with bringing together results in a multisearch. Need to match department data from AD to an email address ...
by joeybroesky Path Finder in Splunk Search 04-01-2020
0 22
0
22
sridharlakshman
Hi Team, i have onboarded the Linux CPU logs using Splunk add on for linux. the requirement is , we need send an al...
by sridharlakshman New Member in Splunk Search 04-01-2020
0 3
0
3
net1993
HelloI have use this command to convert from bytes to GB:| eval b = b /1024/1024/1024and this is an example value as ...
by net1993 Path Finder in Splunk Search 04-01-2020
0 4
0
4
dabroma5
I have below log: Service ABCD(blabla_blabla): 365.45.1.87.3.60354 -> remote.234.5 Failure Service DERF(blabla_blabl...
by dabroma5 Explorer in Splunk Search 04-01-2020
0 4
0
4
jiaqya
if a field is missing in output, what is the query to eval another field to create this missing field. below query ca...
by jiaqya Builder in Splunk Search 04-01-2020
0 5
0
5
warmup031
Hello, I would like to Check for each host, its sourcetype and count by Sourcetype.I tried host=* | stats count by ho...
by warmup031 Explorer in Splunk Search 04-01-2020
0 6
0
6
sarit_s
Hello Im running this query: index="prod" | rex field=source "(?<crate>.*?)/" | stats dc(crate)H But the number o...
by sarit_s Communicator in Splunk Search 04-01-2020
0 1
0
1
riqbal47010
I am not seeing extracted field against below query. index=fireeye | eval {flexString2Label} = flexString2 below are ...
by riqbal47010 Path Finder in Splunk Search 04-01-2020
0 1
0
1
YuliyaVassilyev
I have data from Jira in Splunk, and issues (stories in particular) are counted multiple times because of modificatio...
by YuliyaVassilyev Explorer in Splunk Search 04-01-2020
0 3
0
3
Rukmani_Splunk
Hi All, I have counts of some offers for every hour eg 9-10 30 and then 10-11 - it is 40 it should be cumulative...
by Rukmani_Splunk Path Finder in Splunk Search 04-01-2020
0 0
0
0
surekhasplunk
Hi, I am using below query to get a match by SUBNET from B.csv and get the IP filed. And show all fields from A.cs...
by surekhasplunk Communicator in Splunk Search 04-01-2020
0 2
0
2
812456
Hello I am new to Splunk. Would be great if you can help me with this. Once I open the dash board , it has couple of ...
by 812456 New Member in Splunk Search 03-31-2020
0 0
0
0
rayar
How I can move _time column to be the last on the an attached csv file in the email send by scheduled report the que...
by rayar Contributor in Splunk Search 03-31-2020
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...