Splunk Search

Splunk Search
Community Activity
Nilesh3110
I have multiple apps on shcluster, "/application/splunk/etc/shcluster/apps" . I need to check if there are any Knowle...
by Nilesh3110 Explorer in Splunk Search 01-14-2020
0 6
0
6
thomas_porter
I want to extract the top level domain from the CN field of a certificate in Splunk. The CN field may have multiple ...
by thomas_porter Explorer in Splunk Search 01-14-2020
0 3
0
3
EHariharan
Dear All, I am a SplunkAdmin and we are facing significant data low throughput in some of the indexes. There are man...
by EHariharan Explorer in Splunk Search 01-14-2020
0 2
0
2
WoolarCJ
Hello, I am wondering if it possible to do a search within an "if" statement. I have tried what I have in the searc...
by WoolarCJ New Member in Splunk Search 01-14-2020
0 6
0
6
msrama5
Hi, I have saved search below Queryone and want to classify anything not falling under regx pattern for APIFamily in ...
by msrama5 Explorer in Splunk Search 01-14-2020
0 4
0
4
msrama5
I have saved search below FirstQuery which group by values with pattern matching and want to classify anything not fa...
by msrama5 Explorer in Splunk Search 01-14-2020
0 1
0
1
siddharth1479
Hi Community, I'm using the search query to search for the user activity and I get the results with duplicate rows wi...
by siddharth1479 Path Finder in Splunk Search 01-14-2020
0 17
0
17
dscott10
I am trying to create a dashboard that will showcase, between data pulls, the assets that no longer exists in the ind...
by dscott10 New Member in Splunk Search 01-14-2020
0 0
0
0
jkotula
I have a string from a complex JSON event providing an ISO 8601 date/time in UTC. I want to convert it to the local t...
by jkotula New Member in Splunk Search 01-14-2020
0 8
0
8
bojanjanisch
Hi everyone, I have the following dummy search saved as a report: | makeresults count=1 | eval test="Hello" | map ...
by bojanjanisch New Member in Splunk Search 01-14-2020
0 1
0
1
ialahdal
Is it possible to have a mouse over hover in a dashboard with several timecharts that will highlight the exact time o...
by ialahdal Path Finder in Splunk Search 01-14-2020
1 1
1
1
ialahdal
I want to make a search that will return a count of session_id based on the following fields logged_out, logged_in I ...
by ialahdal Path Finder in Splunk Search 01-14-2020
0 4
0
4
ialahdal
I have an event that is in an HTML tag format, I'd like to extract data within it in a specific manner, as follows: <...
by ialahdal Path Finder in Splunk Search 01-14-2020
0 2
0
2
cheriemilk
Hi Team, I have below appendpipe clause | appendpipe [| eventstats first(eval("step3".mvindex(list_behavio...
by cheriemilk Path Finder in Splunk Search 01-14-2020
0 1
0
1
rupeshn
Hi, I was trying to get amount of data getting indexed in particular index per day and analyze it as a trend. I used...
by rupeshn Explorer in Splunk Search 01-13-2020
0 4
0
4
mgbersales
I have a saved search of the following format ServerName Metric1 Metric2 Metric3 Metric4 Server1 Error Erro...
by mgbersales Loves-to-Learn in Splunk Search 01-13-2020
0 1
0
1
373782073
Hi, Apologies for the unclear title. I could not think of a logical description for the problem statement. I have cr...
by 373782073 Explorer in Splunk Search 01-13-2020
0 4
0
4
wkelsey
Hi, My database has two data sources. Data source 1 sends a string with a list of expected values, so the field mig...
by wkelsey Explorer in Splunk Search 01-13-2020
0 11
0
11
myoung54
Hello all, I feel kind of dumb even asking this question, but I've been up and down these forums looking for an answe...
by myoung54 Explorer in Splunk Search 01-13-2020
0 2
0
2
reverse
1/5/2020 1/12/2020 6/16/2019 6/23/2019 6/30/2019 7/7/2019 7/14/2019 7/21/2019 7/28/2019 8/4/2019 8/11/2019 8/18/2019 ...
by reverse Contributor in Splunk Search 01-13-2020
0 5
0
5
leifab
How to extract a specific field from an event, like "awk '{print $13}'", In this example I want to extract field 13 (...
by leifab New Member in Splunk Search 01-13-2020
0 1
0
1
hogan24
I've found some previous posts with similar questions but the results dont seem to be correct so I'm hoping someone c...
by hogan24 Path Finder in Splunk Search 01-13-2020
6 28
6
28
swazimodo
In a splunk dashboard you can click a data point which will navigate the current page to the results that drove that....
by swazimodo Path Finder in Splunk Search 01-13-2020
0 3
0
3
hawifaris11
I have a two lookup files events_lookup and risky_events_lookup . I have the following search; | inputlookup events_...
by hawifaris11 Engager in Splunk Search 01-13-2020
0 0
0
0
riqbal47010
I have many events against session_id. but I am interested to only list down three type of events 1- AD authenticat...
by riqbal47010 Path Finder in Splunk Search 01-13-2020
0 2
0
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...