Splunk Search

Splunk Search
Community Activity
Substance82
When using regex how can I take a field formatted as "0012-4250" and only show the 1st and lat 3 digits? I tried the ...
by Substance82 Path Finder in Splunk Search 06-27-2024
0 3
0
3
Didalready
I am trying to get DeviceName and DeviceToken to var from 365 logfirst I use eval Device =mvindex('ModifiedProperties...
by Didalready Explorer in Splunk Search 06-27-2024
0 3
0
3
fzuazo
Greetings all,I'm trying to search inside a lookup table and I need to use a search command follow by an OR and regex...
by fzuazo Path Finder in Splunk Search 06-27-2024
0 5
0
5
cs97jb
I have a search that returns two results per day (a job's log entry of when it started and when it ended). I want to ...
by cs97jb New Member in Splunk Search 06-27-2024
0 1
0
1
chorn3567
Hi All! First post, super new user to Splunk. Have a search that i modified from a one a team member previously creat...
by chorn3567 Engager in Splunk Search 06-27-2024
0 4
0
4
Bhavika
I am writing a query which will give total time taken by a log/event for execution in milliseconds :index=xyz cluster...
by Bhavika Loves-to-Learn in Splunk Search 06-27-2024
0 1
0
1
kp_pl
Below is one of my fields. Quite complex,  I know It could be divided to more atomic values .. but it is not [Auditi...
by kp_pl Path Finder in Splunk Search 06-27-2024
0 5
0
5
Steve_A200
Hi, I need help in extracting the time gaps in a multi-value field represented as Date.My data output looks like this...
by Steve_A200 Path Finder in Splunk Search 06-26-2024
0 3
0
3
RanjiRaje
Removing FQDN from field valuesHi all, can anyone help me with framing the SPL query for the below requirement.I have...
by RanjiRaje Explorer in Splunk Search 06-26-2024
0 3
0
3
Chris_Urman
I have a lookup that has saved all apps installed on our deployment server. I need a query that checks all apps in th...
by Chris_Urman Engager in Splunk Search 06-26-2024
0 2
0
2
cjoelly
Hello,I have an index with events, where events belong to a transaction (transaction_id). I am interested in transact...
by cjoelly Loves-to-Learn in Splunk Search 06-26-2024
0 1
0
1
echalex
Hi, is there a way of ignoring the time zone in the searches? Currently, Splunk will reinterpret the difference in ti...
by echalex Builder in Splunk Search 06-26-2024
1 3
1
3
GEB
"Find event in one search, get related events by time in another search"Found some related questions but could not fo...
by GEB Explorer in Splunk Search 06-26-2024
0 6
0
6
anna11
Hello Splunk team, I was troubleshooting one query with anomalydetection command (https://docs.splunk.com/Documentati...
by anna11 New Member in Splunk Search 06-26-2024
0 0
0
0
nkavouris
I would like to extract the Message, Timestamp, and serial fieldsThen I would like to plot the target: Temp(315600), ...
by nkavouris Path Finder in Splunk Search 06-26-2024
0 4
0
4
LearningGuy
Let's say I have a database that is pulled from an application on a daily basis into Splunk and accessed via DBXquery...
by LearningGuy Motivator in Splunk Search 06-25-2024
0 1
0
1
SplunkExplorer
Hi Splunkers, currently we are managing an Enterprise Splunk environment previously managed by another company. As sa...
by SplunkExplorer Contributor in Splunk Search 06-25-2024
0 1
0
1
Substance82
How do I format a returned int into a phone number with the hyphen using the eval random function.  What I have so fa...
by Substance82 Path Finder in Splunk Search 06-25-2024
0 4
0
4
kp_pl
Still it find me difficult to understand logic of joining two indexes. Below the query which is almost suits my needs...
by kp_pl Path Finder in Splunk Search 06-25-2024
0 3
0
3
ChristofferK
Hello!I have the following search: | mstats avg(*) as * WHERE index=indexhere host=hosthere span=1 by host |timechart...
by ChristofferK Engager in Splunk Search 06-25-2024
0 1
0
1
rahulmittal2391
index="ss-stg-dkp" cluster_name="*" AND namespace=dcx AND (label_app="composite-*" ) sourcetype="kube:container:main"...
by rahulmittal2391 New Member in Splunk Search 06-25-2024
0 1
0
1
ibralah93
Dears, I am trying to calculate how the total duration each user spends connected through VPN, their total online tim...
by ibralah93 Loves-to-Learn Lots in Splunk Search 06-25-2024
0 7
0
7
parthiban
Hi team,I need to extract the highlighted field in the below messege using regex... I have tried Splunk inbuilt field...
by parthiban Path Finder in Splunk Search 06-24-2024
0 6
0
6
cherrypick
I have a dashboard X consisting of multiple panels (A, B, C) each populated with dynamic tokens. Panel A consists of ...
by cherrypick Path Finder in Splunk Search 06-24-2024
0 2
0
2
OnePiece
Hello everyone, I am a newbie in this field, I am looking forward to your help.I am using Eventgen to create data sam...
by OnePiece Loves-to-Learn Lots in Splunk Search 06-24-2024
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...