Splunk Search

Splunk Search
Community Activity
DATEVeG
Hello Splunk Community, in order to honour privacy policies we need to limit the searches of most users/roles of an ...
by DATEVeG Path Finder in Splunk Search 01-21-2020
0 2
0
2
PC00128849
Hello, I would like to create a table in below format in splunk. should display first value in first cell of first c...
by PC00128849 New Member in Splunk Search 01-21-2020
0 3
0
3
rhornung
Hi, i'm getting stuck an weird using Splunk to show me am Timechart for the last 30 days with open connection per pro...
by rhornung Explorer in Splunk Search 01-20-2020
0 10
0
10
d4rk_sp1d3r
I have firewall logs where the field "user" has multiple user id's including guest and unknown. I need to count all ...
by d4rk_sp1d3r Loves-to-Learn Lots in Splunk Search 01-20-2020
0 4
0
4
pacifikn
Hello!!!! I can't collect logs in Splunk after Splunk configuration I have done all configuration but I still not g...
by pacifikn Communicator in Splunk Search 01-20-2020
0 3
0
3
mikeoks
Im trying to create a simple Pie chart from a csv file or indexed data and cant seem to configure the Pie chart corre...
by mikeoks New Member in Splunk Search 01-20-2020
0 1
0
1
GersonGarcia
I believe the latest MS updates changed something that is preventing Splunk to open. The error message does not say m...
by GersonGarcia Path Finder in Splunk Search 01-20-2020
0 2
0
2
DEAD_BEEF
I am looking through my firewall logs and would like to find the total byte count between a single source and a singl...
by DEAD_BEEF Builder in Splunk Search 01-20-2020
0 4
0
4
mdeterville
Hi Everyone: I'd like to extract everything before the first "=" below (starting from the right): sender=john&uid=j...
by mdeterville Path Finder in Splunk Search 01-20-2020
0 4
0
4
francoisternois
Hello guys, I'm currently using Splunk_TA_Windows (v5.0.1). I'd like to add the user who launched each processes. Is...
by francoisternois Path Finder in Splunk Search 01-20-2020
0 0
0
0
tonniea
In the definition of a datamodel, I would like to use a regular expression with argument max_match=10 or max_match=0....
by tonniea Explorer in Splunk Search 01-20-2020
0 7
0
7
andrewpagans
Hello All, I would like to reuse repetitive query in a sub-search. Could you please help me to retrieve the base quer...
by andrewpagans Path Finder in Splunk Search 01-20-2020
0 1
0
1
romainbouajila
Hi, I would like to break my logs at every time + log level but it is not working as expected. Here's my props.conf :...
by romainbouajila Path Finder in Splunk Search 01-20-2020
0 13
0
13
naliniasb
Have 2 DB connection and i want to compare the DB1 connection HRA field keeping as primary key say here in this examp...
by naliniasb Explorer in Splunk Search 01-20-2020
0 4
0
4
krylov
Good afternoon! I need to do the following: 1. Using a search result that finds the last timestamp in a certain time...
by krylov Explorer in Splunk Search 01-20-2020
0 3
0
3
ashish198511
I am running following query in Splunk index=appName build=xyz logLevel=ERROR | timechart span=1d count As value. if...
by ashish198511 Explorer in Splunk Search 01-20-2020
1 14
1
14
damucka
Hello, I would like to reduce the license consumption and therefore think of installing HF and applying filtering th...
by damucka Builder in Splunk Search 01-20-2020
0 2
0
2
fvegdom
I have a dashboard with the following base search: <search id="CreatedDossierCount"> <query>index="customer1-clo...
by fvegdom Path Finder in Splunk Search 01-20-2020
0 2
0
2
montydo
From the splunk windows_TA guide "The following keys are equivalent to the fields which appear in the text of the ac...
by montydo Explorer in Splunk Search 01-20-2020
0 2
0
2
gndivya
I have a multivalue field which is got from a stats function. using mvfind function, how to write regex for this. qu...
by gndivya Explorer in Splunk Search 01-20-2020
0 4
0
4
salmiakki
I have a webpage with a few splunk reports embedded to it using the embed option from the Embed page of splunk. Works...
by salmiakki New Member in Splunk Search 01-20-2020
0 3
0
3
sherins
I have 2 indexes and need to get only a records of field that exists in both indexes. One of the index has to filter ...
by sherins New Member in Splunk Search 01-20-2020
0 3
0
3
ansif
How can we forward internal,_audit ,* indexes to both target groups? In outputs.conf, create stanzas for each receiv...
by ansif Motivator in Splunk Search 01-20-2020
0 2
0
2
zahrasidhpuri
The documentation for 'restmap.conf' can be obtained here: https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/R...
by zahrasidhpuri Engager in Splunk Search 01-19-2020
0 0
0
0
vrmandadi
I am trying to see how can we return 0 if no results are found using timechart for a span of 30minutes.i tried using ...
by vrmandadi Builder in Splunk Search 01-19-2020
0 7
0
7
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...