Splunk Search

Splunk Search
Community Activity
nlisle
Hello, I currently have a search against our firewalls, below is the current search. index=(my index) sourcetype="m...
by nlisle New Member in Splunk Search 02-11-2020
0 4
0
4
leandromatperei
Hi, I have the following log format, How can I break this multiline event on condition that "2020-01-23 03:50:49,06...
by leandromatperei Path Finder in Splunk Search 02-11-2020
0 1
0
1
Allampally
I have field values as below , field1=value1 filed2=server1 field1=service/value2/a1 field2=server2...
by Allampally Path Finder in Splunk Search 02-11-2020
0 1
0
1
lukepatrick
I have an existing search that finds fields named "RunDate" "StartTime" "EndTime" stored as part of test run summarie...
by lukepatrick Explorer in Splunk Search 02-11-2020
0 4
0
4
jankowsr
Is there any way to enable event sampling in a search? I know this can be enabled in a GUI using dropdown list under ...
by jankowsr Path Finder in Splunk Search 02-11-2020
1 4
1
4
jip31
hi I use a search wich add a unit value at the end of the result (GB) | eval FreeSpace=FreeSpace." GB", TotalSpace=...
by jip31 Motivator in Splunk Search 02-11-2020
0 4
0
4
harrywren86
Hi, I'm looking at possibly integrating certain of my Splunk dashboards with Power Bi hopefully using a REST API. ...
by harrywren86 Observer in Splunk Search 02-11-2020
0 0
0
0
jadengoho
Hi All, Is it possible to get the Earliest available date of index and source type . I tried "Tstats" and "Metadata"...
by jadengoho Builder in Splunk Search 02-11-2020
0 3
0
3
fmpa_isaac
Can someone help me include sourcetype to my search below? I am trying to run a report for the past 60 days and need ...
by fmpa_isaac Path Finder in Splunk Search 02-10-2020
0 6
0
6
locose
Hello I'm trying to run a rex command to extract "is set to expire" Relying party trust 'ButterCup Games - Test' xx...
by locose Path Finder in Splunk Search 02-10-2020
0 2
0
2
urana
I am trying to see if its possible to run nslookup -q=TXT domain 8.8.8.8 so i can compare the results of the output t...
by urana Engager in Splunk Search 02-10-2020
0 3
0
3
morethanyell
We're trying to extract fields that match this [ FIELD_NAME = S0m3 Valu3 w\ reaLLy $pec!aL ch*rac+3rs ] and write th...
by morethanyell Builder in Splunk Search 02-10-2020
0 9
0
9
joaopcarvalho
Hello all, We are having some problems defining a time-based kvstore lookup on Splunk 6.2.0. We tried defining a sim...
by joaopcarvalho Explorer in Splunk Search 02-10-2020
0 17
0
17
dmcintosh1972
Hi Please give me any feedback . ideas as to whether I am following the best action. I have a database table that is...
by dmcintosh1972 Explorer in Splunk Search 02-10-2020
0 1
0
1
chersergei
Hello, I created SPL search, that should pull out the log entries, based on the if-then-else condition, but it does n...
by chersergei New Member in Splunk Search 02-10-2020
0 3
0
3
newsplunker1
I have a couple orphaned searches owned by a user who is no longer with the company ( his user id was deleted ) . Im ...
by newsplunker1 Path Finder in Splunk Search 02-10-2020
0 2
0
2
freern
I'm currently working through each of my companies Java apps and updating their sourcetypes using transforms and rege...
by freern New Member in Splunk Search 02-10-2020
0 3
0
3
sawyer2624
I have a field that contains: CN=Joe Smith,OU=Support,OU=Users,OU=CCA,OU=DTC,OU=ENT,DC=ent,DC=abc,DC=store,DC=corp ...
by sawyer2624 Engager in Splunk Search 02-10-2020
0 4
0
4
pavanae
I have the username filed extraction as follows in the props.conf which extracts the email address:- [sourcetype_X]...
by pavanae Builder in Splunk Search 02-10-2020
0 2
0
2
pavanae
I have the username filed extraction as follows in the props.conf which extracts the username:- [sourcetype_X] EXTRA...
by pavanae Builder in Splunk Search 02-10-2020
0 3
0
3
dinu1701
I need to display multiple rows having the same PART_NUMBER value for each FLIT_COMPONENTS and AMOUNT sourcetype=fli...
by dinu1701 Explorer in Splunk Search 02-10-2020
0 9
0
9
marisstella
Hi everyone, Trying to find out the top 10 values from different host long_message index functionality.. So tried l...
by marisstella Explorer in Splunk Search 02-10-2020
0 5
0
5
bulu
First, let me start by saying I am not a programmer, a Splunk expert, highly experienced with Regex or SED. I say thi...
by bulu New Member in Splunk Search 02-10-2020
0 5
0
5
amrit
I think the title says it all.
by amrit Splunk Employee Splunk Employee in Splunk Search 02-10-2020
6 6
6
6
gagareg
how to remove values from fields highlighted in red index=main | eval description=case(status == 200, "OK", status ...
by gagareg Explorer in Splunk Search 02-10-2020
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors