Splunk Search

Splunk Search
Community Activity
rain979
I have this search: index=xxx sourcetype="yyy" earliest=01/27/2020:08:00:00 latest=01/27/2020:18:00:00 | timechart ...
by rain979 New Member in Splunk Search 02-05-2020
0 3
0
3
calebwidmer
We're writing Simple XML dashboards that utilize summary indexes for the aggregated data, but that is getting too big...
by calebwidmer Explorer in Splunk Search 02-04-2020
2 6
2
6
Mohsin123
Hi team, say i have a column like this : _time A 11pm 30 10pm 40 I have to subtract 40-30 and store in a new...
by Mohsin123 Path Finder in Splunk Search 02-04-2020
0 3
0
3
hrs2019
Hi All, How i can merge two row value in one field. i am trying with case but i am not getting the output.
by hrs2019 Path Finder in Splunk Search 02-04-2020
0 6
0
6
alpsplunkuser
I have a message that consists of key-value pairs: "status=BLOCKED, identifier=123422dsd13, userId=12344, name=John" ...
by alpsplunkuser Engager in Splunk Search 02-04-2020
0 3
0
3
jdanij
Because of reasons, I need to find a way to find every customized config parameter of an app placed in the local dir....
by jdanij Path Finder in Splunk Search 02-04-2020
0 1
0
1
itsmevic
Does anyone have any SPL that looks at ALL connected network devices? For example, John Doe decides he wants to conn...
by itsmevic Communicator in Splunk Search 02-04-2020
0 0
0
0
chirsf
I hope I explain this well. I have the following tstats search: | tstats max(_time) AS _time WHERE index=_internal s...
by chirsf Explorer in Splunk Search 02-04-2020
0 2
0
2
stephenreece
hi all . I am trying to create a map where I can look at users max duration between logins who register with us betw...
by stephenreece New Member in Splunk Search 02-04-2020
0 3
0
3
yuvarajvelu
How to display what values are missing in my lookup table comparing to actual data? Table.csv SERVER_A,DATA_A SERVER...
by yuvarajvelu New Member in Splunk Search 02-04-2020
0 4
0
4
MonkeyK
Lots of custom commands come with Splunk. 31 in the search app alone. I often see all of those commands and wonder...
by MonkeyK Builder in Splunk Search 02-04-2020
0 6
0
6
d942725
I have a use case where i need to pass the previously performed search query to replace the part of message with empt...
by d942725 New Member in Splunk Search 02-04-2020
0 11
0
11
satya2p
I am trying to pass number from subsearch to main search and find before or after 10 values of number. So if number ...
by satya2p Path Finder in Splunk Search 02-04-2020
0 2
0
2
grundsch
I'm trying to write a new custom search command, more specifically a reporting command. I'm using the Python SDK 1.6....
by grundsch Communicator in Splunk Search 02-04-2020
1 14
1
14
damucka
Hello, I need a help with counting the search results. I cannot use the following: | stats count as Total because...
by damucka Builder in Splunk Search 02-04-2020
0 2
0
2
scottrunyon
I am receiving Syslog data from the firewall and I would like to send a subset of it to the nullQueue. The issue I am...
by scottrunyon Contributor in Splunk Search 02-04-2020
0 3
0
3
D2SI
Hello there, I am trying to dynamically append the content of multiple lookup files but I am not sure it is possible...
by D2SI Communicator in Splunk Search 02-04-2020
0 5
0
5
qbolbk59
Hi, I am trying to list all the events where a user has fired a DNS request to a specific domain mentioned in a look...
by qbolbk59 Path Finder in Splunk Search 02-04-2020
0 6
0
6
dickens8866
Dear All, I'm trying to retrieve and parse windows dns log, the sample looks like this: 1/23/2020 11:59:42 PM 0B50...
by dickens8866 New Member in Splunk Search 02-04-2020
0 1
0
1
thomaap
0
1
anooshac
Hi all I have a json file like this, { "NUM" : "#1", "TIME" : "1/27/2020 12:49:13", "STATUS" : "PASS", "DURATIO...
by anooshac Communicator in Splunk Search 02-03-2020
0 12
0
12
bowesmana
Splunk Cloud We have lookup data that needs to be accessed from Splunk Cloud. This data can either come from an ext...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2020
0 0
0
0
arun_kant_sharm
Hi Experts, I want to store alert search result and the following token in Lookup file app = $app$ description = $...
by arun_kant_sharm Path Finder in Splunk Search 02-03-2020
0 1
0
1
bolaojewale
I am using SSO and I want to be able to edit the error message you get when SSO authenticates, but the user account y...
by bolaojewale Explorer in Splunk Search 02-03-2020
0 0
0
0
sail4lot
I'm seeing lots of dispatch directory threshold errors. Is there an easy way to see what searches or reports are dri...
by sail4lot Path Finder in Splunk Search 02-03-2020
1 3
1
3
Get Updates on the Splunk Community!

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...