Splunk Search

Splunk Search
Community Activity
jadengoho
Hi All, Is it possible to get the Earliest available date of index and source type . I tried "Tstats" and "Metadata"...
by jadengoho Builder in Splunk Search 02-11-2020
0 3
0
3
fmpa_isaac
Can someone help me include sourcetype to my search below? I am trying to run a report for the past 60 days and need ...
by fmpa_isaac Path Finder in Splunk Search 02-10-2020
0 6
0
6
locose
Hello I'm trying to run a rex command to extract "is set to expire" Relying party trust 'ButterCup Games - Test' xx...
by locose Path Finder in Splunk Search 02-10-2020
0 2
0
2
urana
I am trying to see if its possible to run nslookup -q=TXT domain 8.8.8.8 so i can compare the results of the output t...
by urana Engager in Splunk Search 02-10-2020
0 3
0
3
morethanyell
We're trying to extract fields that match this [ FIELD_NAME = S0m3 Valu3 w\ reaLLy $pec!aL ch*rac+3rs ] and write th...
by morethanyell Builder in Splunk Search 02-10-2020
0 9
0
9
joaopcarvalho
Hello all, We are having some problems defining a time-based kvstore lookup on Splunk 6.2.0. We tried defining a sim...
by joaopcarvalho Explorer in Splunk Search 02-10-2020
0 17
0
17
dmcintosh1972
Hi Please give me any feedback . ideas as to whether I am following the best action. I have a database table that is...
by dmcintosh1972 Explorer in Splunk Search 02-10-2020
0 1
0
1
chersergei
Hello, I created SPL search, that should pull out the log entries, based on the if-then-else condition, but it does n...
by chersergei New Member in Splunk Search 02-10-2020
0 3
0
3
newsplunker1
I have a couple orphaned searches owned by a user who is no longer with the company ( his user id was deleted ) . Im ...
by newsplunker1 Path Finder in Splunk Search 02-10-2020
0 2
0
2
freern
I'm currently working through each of my companies Java apps and updating their sourcetypes using transforms and rege...
by freern New Member in Splunk Search 02-10-2020
0 3
0
3
sawyer2624
I have a field that contains: CN=Joe Smith,OU=Support,OU=Users,OU=CCA,OU=DTC,OU=ENT,DC=ent,DC=abc,DC=store,DC=corp ...
by sawyer2624 Engager in Splunk Search 02-10-2020
0 4
0
4
pavanae
I have the username filed extraction as follows in the props.conf which extracts the email address:- [sourcetype_X]...
by pavanae Builder in Splunk Search 02-10-2020
0 2
0
2
pavanae
I have the username filed extraction as follows in the props.conf which extracts the username:- [sourcetype_X] EXTRA...
by pavanae Builder in Splunk Search 02-10-2020
0 3
0
3
dinu1701
I need to display multiple rows having the same PART_NUMBER value for each FLIT_COMPONENTS and AMOUNT sourcetype=fli...
by dinu1701 Explorer in Splunk Search 02-10-2020
0 9
0
9
marisstella
Hi everyone, Trying to find out the top 10 values from different host long_message index functionality.. So tried l...
by marisstella Explorer in Splunk Search 02-10-2020
0 5
0
5
bulu
First, let me start by saying I am not a programmer, a Splunk expert, highly experienced with Regex or SED. I say thi...
by bulu New Member in Splunk Search 02-10-2020
0 5
0
5
amrit
I think the title says it all.
by amrit Splunk Employee Splunk Employee in Splunk Search 02-10-2020
6 6
6
6
gagareg
how to remove values from fields highlighted in red index=main | eval description=case(status == 200, "OK", status ...
by gagareg Explorer in Splunk Search 02-10-2020
0 4
0
4
robertlynch2020
I have data in a CSV called 25_million_Linie_Rule.csv (example below) host,source,count "INTERFACES_BUILD","/hp547s...
by robertlynch2020 Influencer in Splunk Search 02-10-2020
0 5
0
5
rsaude
search made before ...| stats values(user) as AllUsers, values(usr_mod) as ModifiedUsers And it returns two lists ...
by rsaude Path Finder in Splunk Search 02-10-2020
0 17
0
17
damucka
Hello, I have a line chart with multiple series in my dashboard. The series names are quite long, so they cut in the...
by damucka Builder in Splunk Search 02-10-2020
0 0
0
0
driva
Hi guys, I'm having trouble making a simple subtraction (well, I thought it would be simple!). Field1 is a number in...
by driva Path Finder in Splunk Search 02-09-2020
0 2
0
2
andrewtrobec
Hello, Working with Splunk 7.3.2. I have two multivalues that have a set of values in common: | makeresults | eval...
by andrewtrobec Motivator in Splunk Search 02-09-2020
0 2
0
2
mitag
A custom web application produces logs in the tomcat format like this: 2020-01-31 18:19:02,091 DEBUG [com.vendor.mak...
by mitag Contributor in Splunk Search 02-09-2020
0 7
0
7
rtakatsuka
I am new to Splunk, and I need to perform arithmetic on some multi-field values. What is the best way to do this? H...
by rtakatsuka Engager in Splunk Search 02-08-2020
0 1
0
1
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...