Splunk Search

Splunk Search
Community Activity
moystard
Hello all, I have been banging my head on a problem for the past 24 hours and I am in great need of your help. I am...
by moystard New Member in Splunk Search 01-19-2020
0 6
0
6
ChrisCLewis
Good morning I need to replace special characters with a line return command but I am having difficulty getting the r...
by ChrisCLewis Communicator in Splunk Search 01-19-2020
0 6
0
6
harshparikhxlrd
Hello, I am trying to extract data, specifically time data in hh:mm:ss:nn format and put it on a table. When I do, I...
by harshparikhxlrd Path Finder in Splunk Search 01-19-2020
0 7
0
7
jmartens
I can extract multi value fields from a field in events like these: 079184/Query key: ((0008,0016)) SOP Class UID [1...
by jmartens Path Finder in Splunk Search 01-19-2020
0 2
0
2
x_tivity
I have two query... index=xxx_prod host="foo.org" 5032 submit | rex "id=PO:(?<PO>\d*)" | dedup PO | table PO _time ...
by x_tivity Engager in Splunk Search 01-18-2020
0 2
0
2
infcl
I have one log like: log1 tid=,"tid":"abcd"; And another log like: log2 userid=11 tid=abcd I want to get the count ...
by infcl Explorer in Splunk Search 01-18-2020
0 8
0
8
lwass
Hello, I am trying to pull out the last 24 hours worth of results for an alert using loadjob, with the following se...
by lwass Explorer in Splunk Search 01-18-2020
0 3
0
3
sachinrathod
HI, I am able to use curl command as create search job and exuecte the result by sid but not able to convert curl cal...
by sachinrathod New Member in Splunk Search 01-18-2020
0 1
0
1
dpatiladobe
I am trying to extract 2 different time from extend event logs 1. Processing time taken by Server. ( "Finished proces...
by dpatiladobe Explorer in Splunk Search 01-17-2020
0 1
0
1
itsmevic
Hello, For some reason, my search is not returning all of the columns that I'd like to include in my search. It's...
by itsmevic Communicator in Splunk Search 01-17-2020
0 3
0
3
jrprez1804
index=notable |rename src as ip | stats count by ip | JOIN type=inner ip [search index="abcd" "tags.Dev:"cluster1 OR...
by jrprez1804 Path Finder in Splunk Search 01-17-2020
0 3
0
3
hollybross1219
I'm selecting data from two sourcetypes. There is a field in each sourcetype that is the same, but named differently ...
by hollybross1219 Path Finder in Splunk Search 01-17-2020
0 8
0
8
brajaram
I have events with large strings of text being output per event Sample Text: {"userDetails":{"uuid": "Lots of diffe...
by brajaram Communicator in Splunk Search 01-17-2020
0 11
0
11
iamniks
There is a field JOB_NAME. i want to extract this field contents using an IF statement. If JOB_NAME=TEST then some r...
by iamniks Explorer in Splunk Search 01-17-2020
1 2
1
2
winknotes
This may actually be 2 questions, but I have 3 metrics I'd like to compare based on how they're trending. So...... ...
by winknotes Path Finder in Splunk Search 01-17-2020
0 3
0
3
mail2uharishp
HI All, My name group extracts date time filed in the below format E.g: 21/Jan/2019 09:35:25 UTC I would like to c...
by mail2uharishp Observer in Splunk Search 01-17-2020
0 6
0
6
dtccsundar
Required Output : • Matrix: Total Findings by Assessment Group by Engage, Title Fields - Engage - Title - Tota...
by dtccsundar Path Finder in Splunk Search 01-17-2020
0 9
0
9
stephenreece
morning all, I am struggling with the logic around doing this. I am trying to run a report from 01/01/2018 to toda...
by stephenreece New Member in Splunk Search 01-17-2020
0 2
0
2
ricotries
I am trying to capture the logging of any martian packets on a Linux system, so I decided to set a monitor in /var/lo...
by ricotries Communicator in Splunk Search 01-17-2020
1 9
1
9
dugalle
Hi! I have create a search that uses a dynamic lookup to find events in some index looking at the raw: ...............
by dugalle New Member in Splunk Search 01-17-2020
0 4
0
4
mailtosnsolutio
Hello Team, Could you please help to parse this data while pushing this in source type data into splunk. Issue is i...
by mailtosnsolutio Explorer in Splunk Search 01-16-2020
0 2
0
2
TitanAE
Trying to write a simple query in Splunk 7.0. The idea is that it would count all the unique ip addresses based on a...
by TitanAE New Member in Splunk Search 01-16-2020
0 2
0
2
keldridg2
Is there a website on Splunk docs that describe interesting fields and what each field is about? What command can I...
by keldridg2 New Member in Splunk Search 01-16-2020
0 3
0
3
Becherer
When I perform a search, the "events tab" count match actual data. Once I add "| geostats latfield=Latitude longfield...
by Becherer Explorer in Splunk Search 01-16-2020
0 3
0
3
pgoldweic
I'm wondering if it is possible to use the chart visualizations from splunkjs to display data that is neither in Splu...
by pgoldweic Communicator in Splunk Search 01-16-2020
0 0
0
0
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors