Splunk Search

Splunk Search
Community Activity
wsabry
Hello, I have SPL search that returns output in the following format: Device K1 K2 K3 A x1 y1 z1 B ...
by wsabry New Member in Splunk Search 01-15-2020
0 4
0
4
caseygj
My current search string looks like this: index=cisco host=cr0* OR host=SC0* | stats count as daycount by date_month...
by caseygj Explorer in Splunk Search 01-15-2020
0 4
0
4
hbrandt84
Hi, I'm having trouble retrieving my fields from an accelerated data model. The main problem is that most of the fie...
by hbrandt84 Path Finder in Splunk Search 01-15-2020
0 2
0
2
andreguerrero12
Hi i try to changue this result of Active directory : 01/14/2020 08:43:35 PM LogName=Security SourceName=Microsoft...
by andreguerrero12 New Member in Splunk Search 01-15-2020
0 1
0
1
csprice
Hello. I have an index with traffic from 10 devices. I want to generate a lookup that contains the avg EPS over the...
by csprice Path Finder in Splunk Search 01-15-2020
0 5
0
5
aalaa
Hello community , I would like to know where splunk db connect stored data ?
by aalaa Path Finder in Splunk Search 01-15-2020
0 5
0
5
praneeth2050
0
4
aryamehr360
| stats sum("Sum of consumption") as Total_Consumption count as Session I got as a result in splunk / statistics char...
by aryamehr360 New Member in Splunk Search 01-15-2020
0 1
0
1
domgkc
I would like to get configuration items from within a custom search python command. I have created a setup which add...
by domgkc Explorer in Splunk Search 01-15-2020
3 5
3
5
nagar57
**I have a below search query:** | inputlookup splunk_report_test.csv | where report_type="upcoming_offers" | looku...
by nagar57 Communicator in Splunk Search 01-15-2020
0 3
0
3
sharif_ahmmad
Hi community, I am wondering, how can i keep the data of multi value field based in the order it happened, when show...
by sharif_ahmmad Explorer in Splunk Search 01-14-2020
0 4
0
4
nrodrigues
First of all, I apologize if I missed the answer somewhere and for my bad english. I try to supervise my hosts, inde...
by nrodrigues Engager in Splunk Search 01-14-2020
0 1
0
1
pholderness
Definitely a noob, and I must be missing something simple... I have two log files reporting the same error at similar...
by pholderness New Member in Splunk Search 01-14-2020
0 4
0
4
balesh
Hello Folks, I am new to splunk SDK and i am trying to write a code that search and return a search result from the ...
by balesh New Member in Splunk Search 01-14-2020
0 0
0
0
Nilesh3110
I have multiple apps on shcluster, "/application/splunk/etc/shcluster/apps" . I need to check if there are any Knowle...
by Nilesh3110 Explorer in Splunk Search 01-14-2020
0 6
0
6
thomas_porter
I want to extract the top level domain from the CN field of a certificate in Splunk. The CN field may have multiple ...
by thomas_porter Explorer in Splunk Search 01-14-2020
0 3
0
3
EHariharan
Dear All, I am a SplunkAdmin and we are facing significant data low throughput in some of the indexes. There are man...
by EHariharan Explorer in Splunk Search 01-14-2020
0 2
0
2
WoolarCJ
Hello, I am wondering if it possible to do a search within an "if" statement. I have tried what I have in the searc...
by WoolarCJ New Member in Splunk Search 01-14-2020
0 6
0
6
msrama5
Hi, I have saved search below Queryone and want to classify anything not falling under regx pattern for APIFamily in ...
by msrama5 Explorer in Splunk Search 01-14-2020
0 4
0
4
msrama5
I have saved search below FirstQuery which group by values with pattern matching and want to classify anything not fa...
by msrama5 Explorer in Splunk Search 01-14-2020
0 1
0
1
siddharth1479
Hi Community, I'm using the search query to search for the user activity and I get the results with duplicate rows wi...
by siddharth1479 Path Finder in Splunk Search 01-14-2020
0 17
0
17
dscott10
I am trying to create a dashboard that will showcase, between data pulls, the assets that no longer exists in the ind...
by dscott10 New Member in Splunk Search 01-14-2020
0 0
0
0
jkotula
I have a string from a complex JSON event providing an ISO 8601 date/time in UTC. I want to convert it to the local t...
by jkotula New Member in Splunk Search 01-14-2020
0 8
0
8
bojanjanisch
Hi everyone, I have the following dummy search saved as a report: | makeresults count=1 | eval test="Hello" | map ...
by bojanjanisch New Member in Splunk Search 01-14-2020
0 1
0
1
ialahdal
Is it possible to have a mouse over hover in a dashboard with several timecharts that will highlight the exact time o...
by ialahdal Path Finder in Splunk Search 01-14-2020
1 1
1
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...