Splunk Search

Splunk Search
Community Activity
vigneshtv
I have categories.csv that contains list of sub-categories in each category Category,Sub_category Biology,Botany Bio...
by vigneshtv Explorer in Splunk Search 03-14-2020
0 5
0
5
vmeleco
I have 2 searches. Search A produces a table output of "UserIP" Search B produces a table output of "FailedDestina...
by vmeleco New Member in Splunk Search 03-14-2020
0 7
0
7
splunk_learner_
I am new to Splunk and still learning.. I have more than 100 queries to run when asked during a daily activity and i...
by splunk_learner_ New Member in Splunk Search 03-14-2020
0 3
0
3
pratapa
User complained that following query is not displaying any events. index=main sourcetype=wms_oracle_sessions | bucke...
by pratapa Explorer in Splunk Search 03-14-2020
0 6
0
6
mmccul_fe
Data resembles this pattern. | makeresults | eval _raw="{\"foo\": [{\"randstring1\": {\"fqdn\" : \"ibar.example.c...
by mmccul_fe Explorer in Splunk Search 03-14-2020
0 5
0
5
vn_g
Query : index=systemdetails source=sytemdetails* Condition = 0 | eval [ search index=systemdetails source=syte...
by vn_g Path Finder in Splunk Search 03-14-2020
0 3
0
3
kirrusk
I'm trying to count values of field in a time chart with every particular point of time using dedup. like this , inde...
by kirrusk Communicator in Splunk Search 03-14-2020
0 1
0
1
bsaujla131984
I am struggling to fetch the data between curly brackets . Have tried multiple rex searches, however still not gettin...
by bsaujla131984 Path Finder in Splunk Search 03-13-2020
0 3
0
3
zaynaly
I have 2 separate searches. search1 = 17 resultssearch2 = 20 results Key column that exists in both searches is "targ...
by zaynaly Explorer in Splunk Search 03-13-2020
0 1
0
1
raje1
Hi, Can i run a search which specify that these type of logs are blocked in palo alto firewall by specific policy. ...
by raje1 Engager in Splunk Search 03-13-2020
0 3
0
3
matoulas
Hi, I have JSON data format that send to Splunk as below: { "timestamp": "2020-03-12T18:18:48+00:00", "siteid": "CPM-...
by matoulas Path Finder in Splunk Search 03-13-2020
0 9
0
9
tahasefiani
Hello, I have this query | loadjob savedsearch="myquery" | where (strftime(_time, "%Y-%m-%d") >= "2020-02-26") A...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 5
0
5
verbal_666
Hi there. Should we have Indexers issue, or SearchHeads ones? We have many many many (more than 200) scheduled saveds...
by verbal_666 Builder in Splunk Search 03-13-2020
0 5
0
5
pench2k19
Hi Ninjas, I have a radio button with two values as STARTING job and RUNNING jobs. I have different query for each ...
by pench2k19 Explorer in Splunk Search 03-13-2020
0 5
0
5
splunkuser2012
I want to search the whole term like shown below, why is it not working ? Do i need to remove the "<" and "//" ? Wha...
by splunkuser2012 Engager in Splunk Search 03-13-2020
1 4
1
4
tarunmalhotra79
The idea is to show up top 3 CPU Averages in a day for last 7 days. Query Using:- index=os sourcetype=ps host="Host...
by tarunmalhotra79 Engager in Splunk Search 03-13-2020
0 2
0
2
tahasefiani
Hello, This is my query | loadjob savedsearch="myquery" | where strftime(_time, "%Y-%m-%d") >= "2020-02-26" | stat...
by tahasefiani Explorer in Splunk Search 03-13-2020
0 4
0
4
hollybross1219
Hi there! I created a hacky Splunk query for some YOY analysis I'm doing. I was wondering if there was a way to halt...
by hollybross1219 Path Finder in Splunk Search 03-13-2020
0 2
0
2
nathanluke86
............. | rex field=user mode=sed "s/./ /g" | eval user=lower(user) | eval date_hour=strftime(_time, "%...
by nathanluke86 Communicator in Splunk Search 03-13-2020
0 1
0
1
MousumiChowdhur
Hello everyone! I have a static lookup which has two fields/columns State and tag. Default value of State is "Enable...
by MousumiChowdhur Contributor in Splunk Search 03-13-2020
0 1
0
1
skirven
Hi! I'm trying to create a search that would return unique values in a record, but in one list. The search "basesear...
by skirven Communicator in Splunk Search 03-13-2020
0 9
0
9
NeerajDhapola7
Why is Splunk 6.5.1 not able to search when event has data with delimiter ~, while field extraction is working as exp...
by NeerajDhapola7 Path Finder in Splunk Search 03-12-2020
0 5
0
5
maggiesa
Example: Fetch VPN user details from one search and use the username to get details like email addresses from anothe...
by maggiesa New Member in Splunk Search 03-12-2020
0 1
0
1
pradeepk50
I am trying get the max count for the yesterday's but along with this i need to display the date in the report for ye...
by pradeepk50 Loves-to-Learn in Splunk Search 03-12-2020
0 10
0
10
pipipipi
Hi all, how to get difference after using chart command. I did this command. | eval year=strftime(X,"%y") | eval ...
by pipipipi Path Finder in Splunk Search 03-12-2020
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...