Splunk Search

Splunk Search
Community Activity
rkmaggidi
Hi All, I have situation where I want to show a message instead of empty cell. I am using below query to get some d...
by rkmaggidi New Member in Splunk Search 01-23-2020
0 2
0
2
migquinn
I have two time fields in a single event that I need to calculate the difference between and then display said differ...
by migquinn Engager in Splunk Search 01-23-2020
0 2
0
2
twh1
I have two different fields (DB_INSTANCE_NAME & INSTANCE_NAME ) in two source types. These fields contain a similar v...
by twh1 Communicator in Splunk Search 01-23-2020
0 2
0
2
robert2138
How to get a distinct count across two different fields. I have webserver request logs containing browser family and ...
by robert2138 Engager in Splunk Search 01-23-2020
2 5
2
5
Kendo213
I have a lookup file which contains various fields, including the username and corresponding SID (pulled from AD). I...
by Kendo213 Communicator in Splunk Search 01-23-2020
0 2
0
2
limalbert
How can I create a regex query up to a Specific word? For example, the specific word below is "Index". Example data: ...
by limalbert Path Finder in Splunk Search 01-23-2020
0 1
0
1
Bbyers3
I'm Having issues with my case statement. index=sti_123 source=rss_servers active = "1" status = "Being Commissione...
by Bbyers3 New Member in Splunk Search 01-23-2020
0 3
0
3
itsmevic
Hello fellow Splunkers ( : Does anyone have some SPL laying around that shows network traffic that is NOT United St...
by itsmevic Communicator in Splunk Search 01-23-2020
0 2
0
2
ashwinkhai
I am trying to pull list of different URLs from a splunk query. The data is like below. Sample data: 1. Need to gro...
by ashwinkhai Engager in Splunk Search 01-23-2020
0 3
0
3
mansimarkaur
I am trying to send logcat logs to Splunk mint. I added this code Mint.initAndStartSession(this.getApplication(), "5...
by mansimarkaur New Member in Splunk Search 01-23-2020
0 0
0
0
leekeener
I have a search results I want to show in a table. I noticed that the events were not sorted by time so I added the s...
by leekeener Path Finder in Splunk Search 01-23-2020
0 8
0
8
ashanka
index= aab sourcetype=topconnections earliest=-10m latest=-5m | table SESSION_AUTH_ID , CONNECTION_COUNT | addcoltota...
by ashanka Explorer in Splunk Search 01-23-2020
0 4
0
4
tjago11
Doing an extraction in Splunk Stream and get an error when trying to use (?i) in my regex: (?i)x-forwarded-for([:\s]...
by tjago11 Communicator in Splunk Search 01-23-2020
0 2
0
2
surekhasplunk
Hi i am using below query to get the results for Ip index=shinken sourcetype=shinken_alarms Level=HARD Status!=UP S...
by surekhasplunk Communicator in Splunk Search 01-23-2020
0 0
0
0
yasaswinipotta
I am trying to solve a query and I came across a time modifier with len() function. I did not understand the behavior...
by yasaswinipotta New Member in Splunk Search 01-23-2020
0 2
0
2
newportknight
Hi, I am playing around with SA-Eventgen to generate data in a Dev environment but I find if I make a change to the ...
by newportknight Loves-to-Learn in Splunk Search 01-23-2020
0 3
0
3
tdoSplunk
Hi, perhaps it is the wrong approach, but i try to use an inputlookup within a search and pass a value to this subse...
by tdoSplunk Path Finder in Splunk Search 01-23-2020
0 6
0
6
rkmaggidi
TransID AppName timestamp Messagge 1 App1 2019-12-16 18:18:43.731 +0000 Message…… 1 App1 2019-1...
by rkmaggidi New Member in Splunk Search 01-23-2020
0 2
0
2
pwguinto
I'm currently setting up an alert using a CSV lookup file with wildcard entries. I followed the instructions provided...
by pwguinto New Member in Splunk Search 01-23-2020
0 2
0
2
suzuki_caica
DBConectデータを取り込んだところ、 indexのrententionは一日(a day ago)にもかかわらず、 5日分保持されております。 splunk cloudではrentention以上の期間を保持するものでしょうか。...
by suzuki_caica New Member in Splunk Search 01-23-2020
0 0
0
0
balcv
What is the best way to define a "group" of ip subnets called server_subnet then use that in searches. I have about ...
by balcv Contributor in Splunk Search 01-22-2020
0 1
0
1
spammenot66
Is there a way to search and list all attributes from a data model in a search? For example if my data model consists...
by spammenot66 Contributor in Splunk Search 01-22-2020
0 5
0
5
rtrived
Hi, I am trying to connect to Splunk from tableau and getting the attached error. All the drivers are present in the ...
by rtrived New Member in Splunk Search 01-22-2020
0 1
0
1
HiroshiSatoh
Hello! Can All-In-One be set as a search peer? Although the status is set to UP when set, the search returns 0 resu...
by HiroshiSatoh Champion in Splunk Search 01-22-2020
0 4
0
4
nagar57
I want to hide the blank space acquired by a TABLE TITLE as my table title is empty and occupying extra space on the ...
by nagar57 Communicator in Splunk Search 01-22-2020
1 3
1
3
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...
Top Solution Authors