Splunk Search

Splunk Search
Community Activity
dblagojevic
Hi all, I have .csv file with the multiple columns. But only one will be used to compare results, name of that colu...
by dblagojevic Engager in Splunk Search 03-18-2020
0 4
0
4
jip31
hi I use the serch below wich match the data present in 2 indexes following by host In LastLogonBoot, the field "host...
by jip31 Motivator in Splunk Search 03-17-2020
0 11
0
11
nickrally2009
I have this search, where I am charting usage over id field (which is on x-axis) split by two columns - two values o...
by nickrally2009 Explorer in Splunk Search 03-17-2020
0 6
0
6
reverse
Assuming there are 2 columns - Date & count and there are duplicates date. How to dedup on Date and pick the maximum...
by reverse Contributor in Splunk Search 03-17-2020
0 3
0
3
sriyechuri
eventtype="*" "screen" OR "ui1" | stats count AS TotalEvents by product | appendcols [search eventtype="*" "ui2" OR...
by sriyechuri New Member in Splunk Search 03-17-2020
0 8
0
8
tsheets13
I need to create a search to count the number of events in each geographic are of our network. Each geo area will co...
by tsheets13 Communicator in Splunk Search 03-17-2020
0 6
0
6
panulpet
Related to this question: https://answers.splunk.com/answers/807988/splunk-search-show-results-from-json.html I bas...
by panulpet Loves-to-Learn in Splunk Search 03-17-2020
0 12
0
12
627412
I manage to extract the data from Splunk below: ID SignalStrength TimeStamp 01 3 ...
by 627412 New Member in Splunk Search 03-17-2020
0 1
0
1
khojas02
I have a sample data as below Assigned Analyst Assigned Date John ...
by khojas02 Engager in Splunk Search 03-17-2020
0 8
0
8
jonglim
i'm trying to join these 2 tables. table 1 : index ="A" sourcetype = A WITH fields deviceName, physicalElementId, ph...
by jonglim New Member in Splunk Search 03-17-2020
0 5
0
5
uthornander_spl
Hi I have a dataset that isn't entirely clean so I first do some trim to get rid of a trailing comma (,). That didn't...
by uthornander_spl Splunk Employee Splunk Employee in Splunk Search 03-17-2020
0 3
0
3
nilbak1
I am running below Query | makeresults| eval data="Brand1,File1,123;Brand1,File2,456;Brand2,File1,789;Brand2,File2,1...
by nilbak1 Communicator in Splunk Search 03-16-2020
0 4
0
4
splunk_venkat
Hi, I am working on a splunk query to pull the records from daily basis depends on timinging. For example 30m and 6...
by splunk_venkat New Member in Splunk Search 03-16-2020
0 0
0
0
vikram1583
search 1...|table src_ip search 2: tag=authentication user!=*$ src_ip=xx.xx.xx.xx | head 1 | table user src_ip ...
by vikram1583 Explorer in Splunk Search 03-16-2020
0 2
0
2
khojas02
Hello Everyone!! I have a sample data as below Analyst Span A ...
by khojas02 Engager in Splunk Search 03-16-2020
0 1
0
1
daniel333
All, Member of our management team is concerned about a Splunk Forwarder with a number of processes and threads. Cu...
by daniel333 Builder in Splunk Search 03-16-2020
0 1
0
1
itsmevic
Quick background: I'm looking for SSO logins by users that have authenticated via NTLM. Issue: I copied a snippet...
by itsmevic Communicator in Splunk Search 03-16-2020
0 1
0
1
shivanandbm
Hi all, I am finding duplicate events during search operation. I am bit confused on where the issue is lies and how ...
by shivanandbm Explorer in Splunk Search 03-16-2020
0 7
0
7
frbuser
Query index::dlp | bucket _time span=1d | stats count(EVENT_DESCRIPTION) AS "Count" BY _time,User_Name,EV...
by frbuser Path Finder in Splunk Search 03-16-2020
0 1
0
1
riqbal47010
I have below query index=f5 partition="/Common/-" | rex "Username\s+'(?(.*))'" | eval Username=coalesce(Usernam...
by riqbal47010 Path Finder in Splunk Search 03-16-2020
0 6
0
6
ddrillic
When running an inline search the results limit is high as we have in limits.conf the following. [searchresults] max...
by ddrillic Ultra Champion in Splunk Search 03-16-2020
2 5
2
5
adcon82
Hello Everyone, I'm trying to put together a regex statement that will allow me to select only the XML nodes that co...
by adcon82 Explorer in Splunk Search 03-16-2020
0 9
0
9
piefragnisp
I have a json file with some information regarding soa requests. Basically info such as callee, caller, start and end...
by piefragnisp Explorer in Splunk Search 03-16-2020
0 4
0
4
WXY
If the field value is null, the value is null, and if it is not controlled, it is still the original value I want to...
by WXY Path Finder in Splunk Search 03-16-2020
0 2
0
2
fabrizioalleva
Hi all, is there a way to pass to a report the filename of a csv as variable, to use it as lookup file ? Example: ...
by fabrizioalleva Path Finder in Splunk Search 03-16-2020
0 2
0
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...