Splunk Search

Splunk Search
Community Activity
alancalvitti
I'd like to (1) use a subquery to extract a list of deviceId's then (2) search the same index for all events containi...
by alancalvitti Path Finder in Splunk Search 12-11-2019
0 4
0
4
rvalley
I am searching for AD accounts that are created and deleted in a short period, but we have a multiple forest environm...
by rvalley New Member in Splunk Search 12-11-2019
0 5
0
5
satyenshah
Edit 2019-11-28: Splunk has released a better fix-it app than the one below. Edit 2019-11-25: I didn't notice the mo...
by satyenshah Path Finder in Splunk Search 12-11-2019
2 9
2
9
clintla
trying to calculate groupings of VMs capacity growth over time but a chart or table looks to be the best answer if yo...
by clintla Contributor in Splunk Search 12-11-2019
0 23
0
23
essibong1
Hello, I had requested for anyone to provide me with a good search to monitor after hour employee login and I was pro...
by essibong1 New Member in Splunk Search 12-11-2019
0 1
0
1
essibong1
Hello, I had requested help with a "search language that could determine system logins after core hours" and one of t...
by essibong1 New Member in Splunk Search 12-11-2019
0 3
0
3
gtidd
I know I am missing something simple here, but I cannot seem to figure this out. I am trying to search my logs for t...
by gtidd Explorer in Splunk Search 12-11-2019
0 5
0
5
indeed_2000
I have log file like this: A[1020/09/09] B[1013/09/09] C[05-07-00000000-000-A-B-C] want to extract field of A, B, ...
by indeed_2000 Motivator in Splunk Search 12-11-2019
0 5
0
5
spluzer
hello all, I have a lookup with two fields sourcetype and interval ( like below) ..some of the intervals are in seco...
by spluzer Communicator in Splunk Search 12-11-2019
0 4
0
4
woodcock
I get asked some form of this question often and I know what my answer is but I am curious about others. What is you...
by Esteemed Legend in Splunk Search 12-11-2019
1 8
1
8
jospina2
Hello, I am trying to use transforms/props to filter a service from being indexed This is what I have: /etc/system...
by jospina2 Explorer in Splunk Search 12-11-2019
1 2
1
2
pacifikn
How to download existing lookup file? and how to add new row and modify existing lookup file table?
by pacifikn Communicator in Splunk Search 12-11-2019
1 2
1
2
sheikhazad
Hello, My following search results records for Account: index="X" AND (sourcetype="A:Proxy" OR sourcetype="A:orderpu...
by sheikhazad New Member in Splunk Search 12-11-2019
0 13
0
13
idzjuba
Hi, I need to group events where the first event begins with "Receive message" and grouped by thread id. But then nee...
by idzjuba Engager in Splunk Search 12-11-2019
0 4
0
4
niks987
Hi All, Hope you all are doing good. I am stuck with 2 questions may be due to my Splunk query knowledge, hope you ...
by niks987 Explorer in Splunk Search 12-11-2019
0 0
0
0
whitewolf332512
When I run the below search I can see 94 indexes available. | eventcount summarize=false index=* index=_*| dedup ind...
by whitewolf332512 New Member in Splunk Search 12-10-2019
0 3
0
3
Nadhiya_Dubai
/data/scripts/esx/output_crc/dc1-ch1-esxi05.dca.com-vmnic0-20191211-10:40:40.txt I need to extract the field "dc1-ch...
by Nadhiya_Dubai Explorer in Splunk Search 12-10-2019
0 1
0
1
Nadhiya_Dubai
/data/scripts/esx/outfile/dc1-ch1-esxi05.dca.com-vmnic0.txt I need to extract the dc1-ch1-esxi05.dca.com-vmnic0 fro...
by Nadhiya_Dubai Explorer in Splunk Search 12-10-2019
0 3
0
3
matoulas
How do I change a bar chart color base on the syslog severity level. Example: Informational to blue color, warning to...
by matoulas Path Finder in Splunk Search 12-10-2019
0 4
0
4
wti
Hello, I have a timechart search (search code snippet below), everything works great. The chart shows up and the le...
by wti Engager in Splunk Search 12-10-2019
0 1
0
1
rhugo
From the screenshot, i would like to achieve the below; LCU04 = 500 x 00000 LCU03 = 500 x 01985 LCU02 = 500 x 01985 ...
by rhugo Observer in Splunk Search 12-10-2019
0 3
0
3
clintla
I've tried various attempts at this with no joy. I'm simply trying to create a chart where I can specify w/ the time ...
by clintla Contributor in Splunk Search 12-10-2019
0 8
0
8
gravi
Hi I have Splunk messages that gives the information on course and student enrolled. My sample message as follows ...
by gravi Explorer in Splunk Search 12-10-2019
0 2
0
2
bullbo
Getting the following error on many of my previously working searches, any ideas on how to fix it? 3 errors occurre...
by bullbo Engager in Splunk Search 12-10-2019
0 1
0
1
govindparashar1
I have below data ` { [-] context: { [+] } level: INFO logger: x.x.x.xxx.service.xxxService msg: Fi...
by govindparashar1 New Member in Splunk Search 12-10-2019
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...
Top Solution Authors