Splunk Search

Splunk Search
Community Activity
louismai
Hi all, I have a problem when I tried to parse EventID=1 in wineventlog. The message look like this: 03/05/2020 09:0...
by louismai Path Finder in Splunk Search 03-07-2020
0 3
0
3
numeroinconnu12
Hello, this is my request index=juniper_vpn ID=AUT24803 ( src_user!=ANONYMOUSUSER*) | eval src_user=upper(src_user...
by numeroinconnu12 Path Finder in Splunk Search 03-07-2020
0 2
0
2
andrewwjc
I have a data feed to Splunk that contains number, state and service name. This comes in to Splunk continuously as th...
by andrewwjc Engager in Splunk Search 03-07-2020
0 1
0
1
htkhtk
I have some requests/responses going through my system. I want to get the size of each response. The only informatio...
by htkhtk Path Finder in Splunk Search 03-07-2020
2 8
2
8
to4kawa
| makeresults | eval _raw="Source1_field2,Count dev,6 prod,5 uat,7 qa,8" | multikv forceheader=1 | table Source1_fiel...
by to4kawa Ultra Champion in Splunk Search 03-07-2020
0 15
0
15
aherrington
Hello, I have a field called in_time with example output = 8/31/2018 10:21:59 PM (GMT) I'd like this time (e.g. out...
by aherrington Path Finder in Splunk Search 03-07-2020
0 8
0
8
anooshac
Hi all, i have been trying to use 2 tokens which are calculated from 2 different files in another query. But it is no...
by anooshac Communicator in Splunk Search 03-07-2020
0 5
0
5
jip31
hi I need to understand why I execute the first search I have much more events in "Number of CPU alerts" count than i...
by jip31 Motivator in Splunk Search 03-07-2020
0 3
0
3
genesiusj
Hello, I have a search that generates over 50's rows and 12 columns. I need to create a tile for each row. I thought ...
by genesiusj Builder in Splunk Search 03-06-2020
0 7
0
7
mbasharat
Hi, I have time format as: 2019-10-08 15:24:40.132 UTC I used eval to strip it to: 2019-10-08 15:24:40 I need to c...
by mbasharat Builder in Splunk Search 03-06-2020
0 2
0
2
jip31
hi The search below returns me 558 events `CPU` | stats values(SITE) as SITE count(process_cpu_used_percent) as "N...
by jip31 Motivator in Splunk Search 03-06-2020
0 1
0
1
yepyepyayyooo
Anyone know of a way to only return the matching values of a sub search to the string array field in the parent searc...
by yepyepyayyooo New Member in Splunk Search 03-06-2020
0 4
0
4
rajiv_r
How can i exclude a single value from a field which generates multiple value in the single event.for eg- if in a sing...
by rajiv_r Explorer in Splunk Search 03-06-2020
0 4
0
4
shugup2923
Hi Guys, There is a csv which gets updated every day once with details such as- VMName Group CPU Memory Storage Pow...
by shugup2923 Path Finder in Splunk Search 03-06-2020
0 4
0
4
ketan_chanana
Hi, I need to add colour code wise legend for my Pie chart visualization in a same way that Bar/Column chart has on ...
by ketan_chanana Engager in Splunk Search 03-06-2020
0 2
0
2
tsheets13
I have been asked to create an alert that looks at the index sizes (all indexes) for today, and compare them to the s...
by tsheets13 Communicator in Splunk Search 03-06-2020
0 5
0
5
alekseisaiko
Hi there!I'm running this query index="staging" |eval raw_len=len(_raw) | eval raw_len_gb = raw_len/1024/1024/1024 | ...
by alekseisaiko Path Finder in Splunk Search 03-06-2020
0 5
0
5
mdeterville
Hi SMEs: I would like to define a print event type to differentiate Remote Prints from Office Print jobs. From my p...
by mdeterville Path Finder in Splunk Search 03-05-2020
0 4
0
4
asharmaeqfx
Hi Splukers, I have a requirement to search for some filenames and display the missing files as per the date. Thus, ...
by asharmaeqfx Path Finder in Splunk Search 03-05-2020
0 6
0
6
hagjos43
I have a time in the format of: 3:21:34 AM 12/8/2014 I'm trying to convert this to epoch time. Can anyone lend a h...
by hagjos43 Contributor in Splunk Search 03-05-2020
4 10
4
10
ashanka
2/11/2020 11:49:00 AM 2/11/2020 9:55:00 PM How to convert this into Secs.. Conersion of AM and PM is not working a...
by ashanka Explorer in Splunk Search 03-05-2020
0 2
0
2
drewski3420
I'm trying to convert string data in my fields to proper case e.g. josh smith to Josh Smith. Is there any function in...
by drewski3420 New Member in Splunk Search 03-05-2020
0 7
0
7
tsheets13
I have a value in my events called type, which is a single digit integer (1, 2, 3, etc.) I would like to create a new...
by tsheets13 Communicator in Splunk Search 03-05-2020
0 2
0
2
maria_n
Hi Everyone Sample logs: {"kubernetes":{"container_name":"sign-template-services","namespace_name":"merch-ps-signs-...
by maria_n Explorer in Splunk Search 03-05-2020
0 3
0
3
harishalipaka
Hi All, I have data like below Drive Free_Space C:,D: 500 GB,450 GB E:,D: 25...
by harishalipaka Motivator in Splunk Search 03-05-2020
0 3
0
3
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...