Splunk Search

Splunk Search
Community Activity
kvanwagoner
I'm sure this will be easy for you guys but I"m struggling with it.. I need to modify this query to look for both the...
by kvanwagoner New Member in Splunk Search 12-06-2019
0 3
0
3
lucas4394
I wonder what the difference between last and max in timestamp if I want to return the most recent time from a lookup...
by lucas4394 Path Finder in Splunk Search 12-06-2019
0 2
0
2
unitedmarsupial
We have periodic events of the same kind and I want to count the time (duration) and the number of other events (even...
by unitedmarsupial Path Finder in Splunk Search 12-06-2019
0 3
0
3
Tylerdygert
Hello, I am running into an issue with some spath and mvexpand functions in splunk. I get the following error: "outp...
by Tylerdygert Path Finder in Splunk Search 12-06-2019
0 9
0
9
danielbb
The following works just fine - | makeresults | eval temp="IP-Group={xxxx} {yyyy} {zzz}" | rex field=temp max_...
by danielbb Motivator in Splunk Search 12-06-2019
0 3
0
3
bullbo
I have a search that displays new accounts created over the past 30 days and another that displays accounts deleted o...
by bullbo Engager in Splunk Search 12-06-2019
0 4
0
4
prettysunshinez
Hi, I have lookup file with the columns(fields) Name SubName. Now I wanted to run a query,which looks for the presen...
by prettysunshinez Explorer in Splunk Search 12-06-2019
0 4
0
4
pschildein
Hi, I have a large CSV lookup (~200MB and 6+ million lines). As I need the lookup information for eventtypes I tried...
by pschildein Explorer in Splunk Search 12-06-2019
1 0
1
0
rajeshjlnt
I am building a table query to list down tickets against applications. Where tickets are stored in sourcetype 'a' and...
by rajeshjlnt Path Finder in Splunk Search 12-06-2019
0 10
0
10
essibong1
Can any one help with a search language that could determine full disks and system logins after core hours?
by essibong1 New Member in Splunk Search 12-06-2019
0 1
0
1
arrowecssupport
This is my search I am trying to use in an event type so I can tag my events. index = mail | eval Subject=coalesce(S...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 6
0
6
arrowecssupport
I am running the search "index="os_var_log" | stats count" and getting this error after upgrading to Version 8 From v...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 0
0
0
gravi
Hi, I have nested json with Payload and the payload values are not consistent . First Format: { Activity: Logger...
by gravi Explorer in Splunk Search 12-06-2019
0 3
0
3
aswin_asok
i, One of my value in table is being passed as an Boolean expression as below (assignment_group = 1213App_Developmen...
by aswin_asok Explorer in Splunk Search 12-06-2019
0 0
0
0
user93
I want to search an exact phrase, but surronded by wildcards. I want to be able to do this with and without specifyin...
by user93 Communicator in Splunk Search 12-06-2019
0 2
0
2
rcastello
Hello, How can I compile a stats list of what servers a user account has logged into within a specific time period? ...
by rcastello Explorer in Splunk Search 12-05-2019
0 1
0
1
curlly88
I'm tasked with searching for all users that have been disabled in the last thirty days, these are employees no longe...
by curlly88 New Member in Splunk Search 12-05-2019
0 1
0
1
wu_weidong
I'm trying to check if the first occurrence of an event is today using the query below. However, I keep getting resul...
by wu_weidong Path Finder in Splunk Search 12-05-2019
0 1
0
1
cheriemilk
Hi Team, I have below events, want to find out the latest event for each kf7 value, and then stats count based on kt...
by cheriemilk Path Finder in Splunk Search 12-05-2019
0 1
0
1
danieldu
After I updated an app, why am I getting these search errors? The limit has been reached for log messages in info.cs...
by danieldu Engager in Splunk Search 12-05-2019
10 4
10
4
phoenixdigital
Hi All, I have a Search Head Cluster and I am trying to update a global lookup file in a particular app, but am havi...
by phoenixdigital Builder in Splunk Search 12-05-2019
2 4
2
4
prettysunshinez
Hi All, I require help in extracting the words that appear right before the word. Example: Null.set.error Nullerror S...
by prettysunshinez Explorer in Splunk Search 12-05-2019
0 8
0
8
mstark31
I have a situation where I want to run a main search of one index over a time period driven by the time picker on a d...
by mstark31 Path Finder in Splunk Search 12-05-2019
0 7
0
7
contactdipesh
I have got two different tables in my Splunk dashboard and both came from different searches. Is it possible to dow...
by contactdipesh New Member in Splunk Search 12-05-2019
0 2
0
2
chaga
Can anyone tell me which ports should listen on Splunk server and on the Target server (Client)? From where to where...
by chaga New Member in Splunk Search 12-05-2019
0 1
0
1
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors