Splunk Search

Splunk Search
Community Activity
zacksoft
Adding stylesheet=dark.css does make my dashboard dark. However , not all users like dark mode. Can we have a button ...
by zacksoft Contributor in Splunk Search 01-09-2020
0 1
0
1
alejandrome
Hello all, I have the following query: index=someIndex "attr1"=aConstant attr2="aValue" filterCriteria="Criteria1" ...
by alejandrome New Member in Splunk Search 01-09-2020
0 2
0
2
ricotries
I am currently testing forwarding logs from a file I am monitoring, but the software that generates those logs create...
by ricotries Communicator in Splunk Search 01-09-2020
0 1
0
1
poddraj
Hi Team, I have a simple search with index=test which is returning 2587 events with Timeframe of Week to Date. Same ...
by poddraj Explorer in Splunk Search 01-09-2020
0 0
0
0
pratapa
How to construct the URL from the following curl command /usr/bin/curl -s -k -u user1:passwd https://splunk.ce.c...
by pratapa Explorer in Splunk Search 01-09-2020
0 1
0
1
SathyaNarayanan
Hi Team, I have table with 10 column, but want to show the column depends on the Splunk role. Sample xml for my req...
by SathyaNarayanan Path Finder in Splunk Search 01-09-2020
0 4
0
4
shayhibah
Hi, I have log in the following format: time=12345678|hostname=shayh|product=blade1<>blade2<>blade3|username:sha@gm...
by shayhibah Path Finder in Splunk Search 01-09-2020
0 7
0
7
ranjitbrhm1
Hello All, i am trying to customize a sophos TA and i have an issue with EVAL and field alias. My props are like bel...
by ranjitbrhm1 Communicator in Splunk Search 01-09-2020
0 1
0
1
fsaporito
Hello, I have this checkbox in my dashboard: <input type="multiselect" token="t_case" searchWhenChanged="true"> ...
by fsaporito Explorer in Splunk Search 01-08-2020
0 2
0
2
iTechEvent
I have data like this... Date - Hour - Sample Number05/01/2014 - 10 - 20005/01/2014 - 11 - 20105/01/2014 - ...
by iTechEvent Explorer in Splunk Search 01-08-2020
0 3
0
3
vikas_gopal
Hi Experts , I am preparing a very simple dashboard this will have 2 input text box elements and one table which has...
by vikas_gopal Builder in Splunk Search 01-08-2020
0 2
0
2
373782073
Hi, I have incoming syslog events for which I've used the Field Extraction wizard in SPLUNK to separate a the filenam...
by 373782073 Explorer in Splunk Search 01-08-2020
0 4
0
4
lucas4394
We have more than 90% of skipping rate from our datamodel acceleration searches, and most of them show like 99.96% co...
by lucas4394 Path Finder in Splunk Search 01-08-2020
0 0
0
0
nick405060
I want to be able to put a token in my alert title that is derived from a field NOT in the displayed results table. ...
by nick405060 Motivator in Splunk Search 01-08-2020
1 3
1
3
constantinetabs
How do I get the ratio for two values of the same field? When I run the following command: host=web_app action=* fi...
by constantinetabs New Member in Splunk Search 01-08-2020
0 1
0
1
pavanae
I have a query which displays some statistical results. Now I want to add a column macro_match which contains the mat...
by pavanae Builder in Splunk Search 01-08-2020
0 1
0
1
utkarsh_s
Join below 2 indexes on basis of user index=_internal sourcetype=splunkd_ui_access q!="" | rex field=uri_query "disp...
by utkarsh_s New Member in Splunk Search 01-08-2020
0 1
0
1
dbashyam
Hi, How to convert this sumologic query to splunk _collector="M2" "Memory Monitor" | parse ",DB Job-Connection-Poo...
by dbashyam Explorer in Splunk Search 01-08-2020
0 3
0
3
sarwshai
I am using this query "index=oswin* source="WinEventLog:System" (EventCode=6005 OR EventCode=1074 OR EventCode=6006) ...
by sarwshai Communicator in Splunk Search 01-08-2020
0 1
0
1
ftonen
EDIT: The below search suddenly did work, so my issue is solved! So I have two searches in a dashobard, but resultin...
by ftonen Explorer in Splunk Search 01-08-2020
0 7
0
7
martinnepolean
We are trying to do field extraction of the aws dns events, currently we are getting the events with below indexname,...
by martinnepolean Explorer in Splunk Search 01-08-2020
0 6
0
6
sharif_ahmmad
Hello, i have been trying to expand multi value fields from different source-type. Problem is that when i do expand ...
by sharif_ahmmad Explorer in Splunk Search 01-07-2020
0 3
0
3
secuc2r83
Hi, I upgrade in 7.3.3 and i have a problem with one fieldalias I know the ASNEW settings since 7.2.4 restore old b...
by secuc2r83 Path Finder in Splunk Search 01-07-2020
0 0
0
0
siddharth1479
Hi Community, I've been using Splunk enterprise search and reporting since a month now and now when I try to search w...
by siddharth1479 Path Finder in Splunk Search 01-07-2020
0 8
0
8
raj00350
I have 2 columns. First column has values on which my splunk line chart is dependent on. Second column has values onl...
by raj00350 New Member in Splunk Search 01-07-2020
0 2
0
2
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...