Splunk Search

Splunk Search
Community Activity
a508184
I need to display priority data for 7 days with the percentage, however am unable to display it in 7 days. My below q...
by a508184 Explorer in Splunk Search 07-01-2024
0 7
0
7
devsru
Dear All,I want to setup an alert in an event. The event contains three timestamps, New Event time, Last update, and ...
by devsru Explorer in Splunk Search 07-01-2024
0 3
0
3
AliMaher
I Have used the below two events to test the SOURCE_KEY =   <132>1 2023-12-24T09:48:05+00:00 DCSECIDKOASV02 ikeyserve...
by AliMaher Path Finder in Splunk Search 07-01-2024
0 3
0
3
LearningGuy
How to convert CSV lookup to DBXlookup?The lookup using CSV worked just fine.The CSV was moved to the database and wh...
by LearningGuy Motivator in Splunk Search 06-30-2024
0 1
0
1
ralam
Hi Team,What I'm trying to achieve: Find the consecutive failure events followed by a success event. | makeresults | ...
by ralam Explorer in Splunk Search 06-30-2024
0 2
0
2
Cozy
Hello,I need some help with adjusting an alert for detecting a password spray attack using Auth0 logs in Splunk. What...
by Cozy Loves-to-Learn in Splunk Search 06-30-2024
0 3
0
3
Oum
hello i'm beginner in splunk. Currently, i'm working with splunk entreprise i want to retrieve microservices depandan...
by Oum New Member in Splunk Search 06-30-2024
0 5
0
5
jenkinsta
I have an inputlookup called adexport.csv thats big...trying to join and match two fields in the lookup UserName and ...
by jenkinsta Path Finder in Splunk Search 06-29-2024
0 2
0
2
gballanti
I need help regarding a join from events based on different sourcetype (same index) that are related by the same valu...
by gballanti Explorer in Splunk Search 06-28-2024
1 13
1
13
RamMur
Hello,  I'm fairly new to splunk, trying to search using where clause and filter the results. The query is running lo...
by RamMur Explorer in Splunk Search 06-28-2024
0 3
0
3
Mick_OBrien
Hi All,We have an application that gets events in from an external party but occasionally we see out of sequence even...
by Mick_OBrien Path Finder in Splunk Search 06-28-2024
0 3
0
3
ChuckM
I am trying to get a table showing the number of days a user was active in the given time period.  I currently have a...
by ChuckM Engager in Splunk Search 06-28-2024
0 4
0
4
cherrypick
As the title suggests I have a dashboard with various panels and wondering if it's possible to export a single panel ...
by cherrypick Path Finder in Splunk Search 06-27-2024
0 0
0
0
Substance82
When using regex how can I take a field formatted as "0012-4250" and only show the 1st and lat 3 digits? I tried the ...
by Substance82 Path Finder in Splunk Search 06-27-2024
0 3
0
3
Didalready
I am trying to get DeviceName and DeviceToken to var from 365 logfirst I use eval Device =mvindex('ModifiedProperties...
by Didalready Explorer in Splunk Search 06-27-2024
0 3
0
3
fzuazo
Greetings all,I'm trying to search inside a lookup table and I need to use a search command follow by an OR and regex...
by fzuazo Path Finder in Splunk Search 06-27-2024
0 5
0
5
cs97jb
I have a search that returns two results per day (a job's log entry of when it started and when it ended). I want to ...
by cs97jb New Member in Splunk Search 06-27-2024
0 1
0
1
chorn3567
Hi All! First post, super new user to Splunk. Have a search that i modified from a one a team member previously creat...
by chorn3567 Engager in Splunk Search 06-27-2024
0 4
0
4
Bhavika
I am writing a query which will give total time taken by a log/event for execution in milliseconds :index=xyz cluster...
by Bhavika Loves-to-Learn in Splunk Search 06-27-2024
0 1
0
1
kp_pl
Below is one of my fields. Quite complex,  I know It could be divided to more atomic values .. but it is not [Auditi...
by kp_pl Path Finder in Splunk Search 06-27-2024
0 5
0
5
Steve_A200
Hi, I need help in extracting the time gaps in a multi-value field represented as Date.My data output looks like this...
by Steve_A200 Path Finder in Splunk Search 06-26-2024
0 3
0
3
RanjiRaje
Removing FQDN from field valuesHi all, can anyone help me with framing the SPL query for the below requirement.I have...
by RanjiRaje Explorer in Splunk Search 06-26-2024
0 3
0
3
Chris_Urman
I have a lookup that has saved all apps installed on our deployment server. I need a query that checks all apps in th...
by Chris_Urman Engager in Splunk Search 06-26-2024
0 2
0
2
cjoelly
Hello,I have an index with events, where events belong to a transaction (transaction_id). I am interested in transact...
by cjoelly Loves-to-Learn in Splunk Search 06-26-2024
0 1
0
1
echalex
Hi, is there a way of ignoring the time zone in the searches? Currently, Splunk will reinterpret the difference in ti...
by echalex Builder in Splunk Search 06-26-2024
1 3
1
3
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...