Splunk Search

Splunk Search
Community Activity
bsaujla131984
I am struggling to fetch the data between curly brackets . Have tried multiple rex searches, however still not gettin...
by bsaujla131984 Path Finder in Splunk Search 03-13-2020
0 3
0
3
zaynaly
I have 2 separate searches. search1 = 17 resultssearch2 = 20 results Key column that exists in both searches is "targ...
by zaynaly Explorer in Splunk Search 03-13-2020
0 1
0
1
raje1
Hi, Can i run a search which specify that these type of logs are blocked in palo alto firewall by specific policy. ...
by raje1 Engager in Splunk Search 03-13-2020
0 3
0
3
matoulas
Hi, I have JSON data format that send to Splunk as below: { "timestamp": "2020-03-12T18:18:48+00:00", "siteid": "CPM-...
by matoulas Path Finder in Splunk Search 03-13-2020
0 9
0
9
tahasefiani
Hello, I have this query | loadjob savedsearch="myquery" | where (strftime(_time, "%Y-%m-%d") >= "2020-02-26") A...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 5
0
5
verbal_666
Hi there. Should we have Indexers issue, or SearchHeads ones? We have many many many (more than 200) scheduled saveds...
by verbal_666 Builder in Splunk Search 03-13-2020
0 5
0
5
pench2k19
Hi Ninjas, I have a radio button with two values as STARTING job and RUNNING jobs. I have different query for each ...
by pench2k19 Explorer in Splunk Search 03-13-2020
0 5
0
5
splunkuser2012
I want to search the whole term like shown below, why is it not working ? Do i need to remove the "<" and "//" ? Wha...
by splunkuser2012 Engager in Splunk Search 03-13-2020
1 4
1
4
tarunmalhotra79
The idea is to show up top 3 CPU Averages in a day for last 7 days. Query Using:- index=os sourcetype=ps host="Host...
by tarunmalhotra79 Engager in Splunk Search 03-13-2020
0 2
0
2
tahasefiani
Hello, This is my query | loadjob savedsearch="myquery" | where strftime(_time, "%Y-%m-%d") >= "2020-02-26" | stat...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 4
0
4
hollybross1219
Hi there! I created a hacky Splunk query for some YOY analysis I'm doing. I was wondering if there was a way to halt...
by hollybross1219 Path Finder in Splunk Search 03-13-2020
0 2
0
2
nathanluke86
............. | rex field=user mode=sed "s/./ /g" | eval user=lower(user) | eval date_hour=strftime(_time, "%...
by nathanluke86 Communicator in Splunk Search 03-13-2020
0 1
0
1
MousumiChowdhur
Hello everyone! I have a static lookup which has two fields/columns State and tag. Default value of State is "Enable...
by MousumiChowdhur Contributor in Splunk Search 03-13-2020
0 1
0
1
skirven
Hi! I'm trying to create a search that would return unique values in a record, but in one list. The search "basesear...
by skirven Communicator in Splunk Search 03-13-2020
0 9
0
9
NeerajDhapola7
Why is Splunk 6.5.1 not able to search when event has data with delimiter ~, while field extraction is working as exp...
by NeerajDhapola7 Path Finder in Splunk Search 03-12-2020
0 5
0
5
maggiesa
Example: Fetch VPN user details from one search and use the username to get details like email addresses from anothe...
by maggiesa New Member in Splunk Search 03-12-2020
0 1
0
1
pradeepk50
I am trying get the max count for the yesterday's but along with this i need to display the date in the report for ye...
by pradeepk50 Loves-to-Learn in Splunk Search 03-12-2020
0 10
0
10
pipipipi
Hi all, how to get difference after using chart command. I did this command. | eval year=strftime(X,"%y") | eval ...
by pipipipi Path Finder in Splunk Search 03-12-2020
0 1
0
1
MOHITJOSHI
I have IIS events which looks like below. looking to compute the total time taken from the splunk timestamp..which in...
by MOHITJOSHI Engager in Splunk Search 03-12-2020
0 4
0
4
liberty5
I am having a problem using a date range. If I run the search below it returns 2 events and a count of 496 index="t...
by liberty5 Explorer in Splunk Search 03-12-2020
0 11
0
11
clehw
I am trying to create a timechart for a query that returns a count for a set of products that where it's lifecycle st...
by clehw Explorer in Splunk Search 03-12-2020
0 7
0
7
cjmckenna
Running into a strange issue that I, nor my Splunk admins, can figure out. We have a filed extraction called "Servic...
by cjmckenna New Member in Splunk Search 03-12-2020
0 15
0
15
charan986
Hi I've two different payloads returned from my search and I need to create a table from values extracted from the pa...
by charan986 Engager in Splunk Search 03-12-2020
0 7
0
7
numeroinconnu12
Hello, This is my query with " dedup Matricule" index=juniper_vpn (ID=AUT22673 OR ID=AUT24803) ......67 | eval sr...
by numeroinconnu12 Path Finder in Splunk Search 03-12-2020
0 3
0
3
tonakano
データの追加で、モニターでディレクトリ指定にしています。 指定したフォルダの中には、同一構成の日付ごとのデータが数か月分格納されています。 インポートを終えて、検索をするのですが、sourceを見ると全ファイルが取り込まれていません...
by tonakano Engager in Splunk Search 03-12-2020
0 1
0
1
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors