Splunk Search

Splunk Search
Community Activity
johnsasikumar
Hi all, I have a requirement as below, When there is a name field, I want it to be ranked similar names together Na...
by johnsasikumar Path Finder in Splunk Search 03-20-2020
0 2
0
2
mbasharat
Hi, I have two fields in my report. Time_Created and Time_Closed. They are for time an incident ticket was created a...
by mbasharat Builder in Splunk Search 03-20-2020
0 6
0
6
pench2k19
Hi Guys, I have the following query which i am showing line chart in a panel, how ever i want to show the jobnames a...
by pench2k19 Explorer in Splunk Search 03-20-2020
0 1
0
1
hollybross1219
Hi there, I'm trying to create a time series data using streamstats function. Got it figured out, but is there any ...
by hollybross1219 Path Finder in Splunk Search 03-20-2020
0 2
0
2
vpaschalidis
Hello, I have a lookup table that looks like below: dns ip server1 ip1,ip2,ip3 server2 ...
by vpaschalidis Loves-to-Learn in Splunk Search 03-20-2020
0 1
0
1
horsefez
Hi Splunk community, I'm currently trying to correlate different event sources and events with each other. My sear...
by horsefez Motivator in Splunk Search 03-20-2020
0 6
0
6
mariuswal
I have a dashboard that should perform a dynamic number of searches. For this purpose I created a search manager, whi...
by mariuswal New Member in Splunk Search 03-20-2020
0 0
0
0
lozarich007
Hi, I have the following lookup, which is basically a mapping lookup: lookup name: "scoring_rules" source , field...
by lozarich007 New Member in Splunk Search 03-19-2020
0 2
0
2
howardroark
I am looking to plot scatter plot to show all the data points in a particular time. Some how I am not able to get aro...
by howardroark Explorer in Splunk Search 03-19-2020
1 23
1
23
dapitis
In elasticsearch one would do HEAD [index_name] and check if an index exists efficiently. Is it possible to do someth...
by dapitis Engager in Splunk Search 03-19-2020
0 13
0
13
donaldwayne1975
Event data has multiple time values in the Epoch time format. I am able to convert the one used for event timestamp w...
by donaldwayne1975 Path Finder in Splunk Search 03-19-2020
0 3
0
3
bcarr12
Hi all, For a search similar to the following: index=myindex "Search Term" NOT field=value source="mylog.log" | eval...
by bcarr12 Path Finder in Splunk Search 03-19-2020
0 3
0
3
avilandau
I'm storing a few credentials in Splunk keystore using setup.xml endpoint="storage/passwords". I have no problem ex...
by avilandau Path Finder in Splunk Search 03-19-2020
1 16
1
16
mashhoorgulati
Hi, We are getting data from syslog for ssl vpn login. Here is a sample log. ,,"'0'",,"'-'",,"Thor","'Tunnel'","MCU...
by mashhoorgulati Engager in Splunk Search 03-19-2020
0 2
0
2
nick405060
This query kills morejunk even though it should NOT be doing so: | makeresults | eval a="1 2" | eval b="junk" | appe...
by nick405060 Motivator in Splunk Search 03-19-2020
1 5
1
5
khanyag1
Hi, I need help adding b+ c together to get a total, I will then calculate a percentage using a/combined b+c. Is thi...
by khanyag1 New Member in Splunk Search 03-19-2020
0 11
0
11
kirrusk
I'm using summary index to get data and display in timechart. but not able to create a time chart with the data. ind...
by kirrusk Communicator in Splunk Search 03-19-2020
0 4
0
4
HattrickNZ
Looking at understanding better how lookups work in Splunk. As I understand it, there are 3 steps: 1. lookup table...
by HattrickNZ Motivator in Splunk Search 03-19-2020
2 12
2
12
dillardo_2
Hello community, I've installed SA-Eventgen and SPL Examples as directed in the following .conf talk: https://conf.s...
by dillardo_2 Path Finder in Splunk Search 03-19-2020
0 4
0
4
pomazanelvira
Hi! I have this field in my log: callerSipNumber="18121710_text". How should I extract "18121710" and name it "number...
by pomazanelvira New Member in Splunk Search 03-19-2020
0 4
0
4
landen99
I have frequently asked whether the fields are being extracted well. The easiest method to answer this question is t...
by landen99 Motivator in Splunk Search 03-19-2020
1 2
1
2
mockingj
Hello Splunkers, I have a trouble with the result, example i have some data log Goat | alive Goat | dead Goat | ali...
by mockingj New Member in Splunk Search 03-19-2020
0 4
0
4
nathanluke86
This is a little tricky to explain but I have this query: index = active_directory directReports=* sAMAccountName=* ...
by nathanluke86 Communicator in Splunk Search 03-19-2020
0 2
0
2
1014502
お世話になります。 項目名に月の値を入れたいです。現在検討している方法は別カラムに月の値(2020-03)を設定し、【予定】という項目の先頭に月の値(2020-03)をセットして、【2020-03予定】という項目名にしたいのですが、実...
by 1014502 New Member in Splunk Search 03-19-2020
0 3
0
3
Barty
Good morning you lovely lot, I have a theoretically simple regex extraction, but it is slaying me. If one of you wou...
by Barty Explorer in Splunk Search 03-19-2020
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...