Splunk Search

Splunk Search
Community Activity
ChristofferK
Hello!I have the following search: | mstats avg(*) as * WHERE index=indexhere host=hosthere span=1 by host |timechart...
by ChristofferK Engager in Splunk Search 06-25-2024
0 1
0
1
rahulmittal2391
index="ss-stg-dkp" cluster_name="*" AND namespace=dcx AND (label_app="composite-*" ) sourcetype="kube:container:main"...
by rahulmittal2391 New Member in Splunk Search 06-25-2024
0 1
0
1
ibralah93
Dears, I am trying to calculate how the total duration each user spends connected through VPN, their total online tim...
by ibralah93 Loves-to-Learn Lots in Splunk Search 06-25-2024
0 7
0
7
parthiban
Hi team,I need to extract the highlighted field in the below messege using regex... I have tried Splunk inbuilt field...
by parthiban Path Finder in Splunk Search 06-24-2024
0 6
0
6
cherrypick
I have a dashboard X consisting of multiple panels (A, B, C) each populated with dynamic tokens. Panel A consists of ...
by cherrypick Path Finder in Splunk Search 06-24-2024
0 2
0
2
OnePiece
Hello everyone, I am a newbie in this field, I am looking forward to your help.I am using Eventgen to create data sam...
by OnePiece Loves-to-Learn Lots in Splunk Search 06-24-2024
0 4
0
4
bmanikya
index=XXX sourcetype=XXX [|inputlookup Edge_Nodes_All.csv where Environment="*" AND host="*" |fields host] |fields cl...
by bmanikya Loves-to-Learn Everything in Splunk Search 06-24-2024
0 4
0
4
dataisbeautiful
Hi allI have a search that works for a range of a few days (eg earliest=-7d@d), but when running for alltime it break...
by dataisbeautiful Communicator in Splunk Search 06-24-2024
0 3
0
3
thaghost99
hi, i currently have this data and i would like to see if i can extract the date and time and see if it can display t...
by thaghost99 Path Finder in Splunk Search 06-24-2024
0 4
0
4
mclane41
I see some post about rules for splunk logs.But I don't find a list of rules. My applications logs a  lot of lines fo...
by mclane41 Explorer in Splunk Search 06-24-2024
0 2
0
2
Dharani
Hi, I want to create alert based on file received. Everyday at randomly we used to receive files. ex. file name: file...
by Dharani Path Finder in Splunk Search 06-24-2024
0 6
0
6
smp8644
I am trying to write a splunk search to pull what rules a particular user is hitting. This search is helping with tha...
by smp8644 Loves-to-Learn in Splunk Search 06-22-2024
0 3
0
3
Rao_KGY
Hello Everyone, I have built a Splunk query (shared below) recently & I noticed that when apply search condition App_...
by Rao_KGY Loves-to-Learn in Splunk Search 06-21-2024
0 2
0
2
kirkj
I'm trying to create a search where I take a small list of IPs from sourcetype A and compare them against a larger se...
by kirkj Observer in Splunk Search 06-21-2024
0 3
0
3
splunkingsid
Hoping to find a solution here for my rex query (new to rex) I have an event that looks like this time="2024-06-22T00...
by splunkingsid Engager in Splunk Search 06-21-2024
0 1
0
1
newbie77
Field1=Start Field2=Finish Field1 and Field2 have multiple events with values Start and Finish for a given uid respe...
by newbie77 Engager in Splunk Search 06-21-2024
0 2
0
2
Substance82
Stuck again and not sure what I'm missing... I have the first two steps, but cannot figure out the syntax to use Time...
by Substance82 Path Finder in Splunk Search 06-21-2024
0 2
0
2
kp_pl
below is my scenario described by Oracle DBA I have two indexesINDEXAfieldAfieldBfieldCINDEXBfieldAfieldXfieldYfield...
by kp_pl Path Finder in Splunk Search 06-21-2024
0 3
0
3
Siddharthnegi
Hello , How can I know the start time and the latest time  coming of data of all index .meaning that when was the fir...
by Siddharthnegi Contributor in Splunk Search 06-21-2024
0 3
0
3
Splunk_sid
Hi Team,We have onboarded csv data into Splunk and each row in csv is ingested into _raw field . I need to bring this...
by Splunk_sid Explorer in Splunk Search 06-21-2024
0 5
0
5
Kadae
Hi, I have the results of an append operation as follows:IDCol3col4col5a  abcaabcNo axyzYes b  abcb  xyzbxyzNo bfghYe...
by Kadae Splunk Employee Splunk Employee in Splunk Search 06-20-2024
0 3
0
3
runiyal
I have a logfile like this - 2024-06-14 09:34:45,504 INFO [com.mysite.core.repo.BaseWebScript] [http-nio-8080-exec-4...
by runiyal Path Finder in Splunk Search 06-20-2024
0 3
0
3
Sophie6
I have two query tablestable 1index="k8s_main" namespace="app02013" "EConcessionItemProcessingStartedHandler.createRm...
by Sophie6 New Member in Splunk Search 06-20-2024
0 1
0
1
paulcurry
I have a search that returns all of my correlation searches for a given app.   | rest splunk_server=local count=0 /se...
by paulcurry Path Finder in Splunk Search 06-20-2024
0 3
0
3
Substance82
How do I add a  new field and set the value to seven days ago from the current date, snapped to thebeginning of the c...
by Substance82 Path Finder in Splunk Search 06-20-2024
0 2
0
2
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors