Splunk Search

Splunk Search
Community Activity
klhogan
The query below produces the results expected, but if I remove the "table PSID" section (bolded) it fails, saying 22 ...
by klhogan New Member in Splunk Search 01-16-2020
0 2
0
2
sahil237888
How to show count of events by host as well as total count (both per minute in same search)
by sahil237888 Path Finder in Splunk Search 01-16-2020
0 1
0
1
nikos_d
How can I get the splunk SDK API to return results faster than 100 kB / second? Some context: I am trying to create ...
by nikos_d Explorer in Splunk Search 01-16-2020
3 3
3
3
pr0n
When using index=blah | sitimechart dc(field1) by field2 It saves every single element for field1 concatenated into a...
by pr0n Explorer in Splunk Search 01-16-2020
0 3
0
3
plymalebl
I have inherited a Splunk Enterprise and FIPS is on for about half of the environment. My experience has always been ...
by plymalebl Explorer in Splunk Search 01-16-2020
2 0
2
0
NayneshPatel
I have a raw the i extract and filter and table them according to Country _raw [{"Conutry":"America","State":"Nevada...
by NayneshPatel New Member in Splunk Search 01-16-2020
0 2
0
2
pgadhari
I want to compare current top of an hour value with previous top of an hour value. For e.g. between 9 am to 10 am - g...
by pgadhari Builder in Splunk Search 01-15-2020
0 9
0
9
kaungset
Dears; how can I combine Date/Time of two different source as follow; CSV-01(pic-1) and CSV-02(pic-2) input in spl...
by kaungset New Member in Splunk Search 01-15-2020
0 6
0
6
msrama5
Hi , I have the following search query that lookups definition file TeamsLookupDef which has 200 mappings between ap...
by msrama5 Explorer in Splunk Search 01-15-2020
0 3
0
3
wsabry
Hello, I have SPL search that returns output in the following format: Device K1 K2 K3 A x1 y1 z1 B ...
by wsabry New Member in Splunk Search 01-15-2020
0 4
0
4
caseygj
My current search string looks like this: index=cisco host=cr0* OR host=SC0* | stats count as daycount by date_month...
by caseygj Explorer in Splunk Search 01-15-2020
0 4
0
4
hbrandt84
Hi, I'm having trouble retrieving my fields from an accelerated data model. The main problem is that most of the fie...
by hbrandt84 Path Finder in Splunk Search 01-15-2020
0 2
0
2
andreguerrero12
Hi i try to changue this result of Active directory : 01/14/2020 08:43:35 PM LogName=Security SourceName=Microsoft...
by andreguerrero12 New Member in Splunk Search 01-15-2020
0 1
0
1
csprice
Hello. I have an index with traffic from 10 devices. I want to generate a lookup that contains the avg EPS over the...
by csprice Path Finder in Splunk Search 01-15-2020
0 5
0
5
aalaa
Hello community , I would like to know where splunk db connect stored data ?
by aalaa Path Finder in Splunk Search 01-15-2020
0 5
0
5
praneeth2050
0
4
aryamehr360
| stats sum("Sum of consumption") as Total_Consumption count as Session I got as a result in splunk / statistics char...
by aryamehr360 New Member in Splunk Search 01-15-2020
0 1
0
1
domgkc
I would like to get configuration items from within a custom search python command. I have created a setup which add...
by domgkc Explorer in Splunk Search 01-15-2020
3 5
3
5
nagar57
**I have a below search query:** | inputlookup splunk_report_test.csv | where report_type="upcoming_offers" | looku...
by nagar57 Communicator in Splunk Search 01-15-2020
0 3
0
3
sharif_ahmmad
Hi community, I am wondering, how can i keep the data of multi value field based in the order it happened, when show...
by sharif_ahmmad Explorer in Splunk Search 01-14-2020
0 4
0
4
nrodrigues
First of all, I apologize if I missed the answer somewhere and for my bad english. I try to supervise my hosts, inde...
by nrodrigues Engager in Splunk Search 01-14-2020
0 1
0
1
pholderness
Definitely a noob, and I must be missing something simple... I have two log files reporting the same error at similar...
by pholderness New Member in Splunk Search 01-14-2020
0 4
0
4
balesh
Hello Folks, I am new to splunk SDK and i am trying to write a code that search and return a search result from the ...
by balesh New Member in Splunk Search 01-14-2020
0 0
0
0
Nilesh3110
I have multiple apps on shcluster, "/application/splunk/etc/shcluster/apps" . I need to check if there are any Knowle...
by Nilesh3110 Explorer in Splunk Search 01-14-2020
0 6
0
6
thomas_porter
I want to extract the top level domain from the CN field of a certificate in Splunk. The CN field may have multiple ...
by thomas_porter Explorer in Splunk Search 01-14-2020
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors