Splunk Search

Splunk Search
Community Activity
Tylerdygert
Hello, I am running into an issue with some spath and mvexpand functions in splunk. I get the following error: "outp...
by Tylerdygert Path Finder in Splunk Search 12-06-2019
0 9
0
9
danielbb
The following works just fine - | makeresults | eval temp="IP-Group={xxxx} {yyyy} {zzz}" | rex field=temp max_...
by danielbb Motivator in Splunk Search 12-06-2019
0 3
0
3
bullbo
I have a search that displays new accounts created over the past 30 days and another that displays accounts deleted o...
by bullbo Engager in Splunk Search 12-06-2019
0 4
0
4
prettysunshinez
Hi, I have lookup file with the columns(fields) Name SubName. Now I wanted to run a query,which looks for the presen...
by prettysunshinez Explorer in Splunk Search 12-06-2019
0 4
0
4
pschildein
Hi, I have a large CSV lookup (~200MB and 6+ million lines). As I need the lookup information for eventtypes I tried...
by pschildein Explorer in Splunk Search 12-06-2019
1 0
1
0
rajeshjlnt
I am building a table query to list down tickets against applications. Where tickets are stored in sourcetype 'a' and...
by rajeshjlnt Path Finder in Splunk Search 12-06-2019
0 10
0
10
essibong1
Can any one help with a search language that could determine full disks and system logins after core hours?
by essibong1 New Member in Splunk Search 12-06-2019
0 1
0
1
arrowecssupport
This is my search I am trying to use in an event type so I can tag my events. index = mail | eval Subject=coalesce(S...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 6
0
6
arrowecssupport
I am running the search "index="os_var_log" | stats count" and getting this error after upgrading to Version 8 From v...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 0
0
0
gravi
Hi, I have nested json with Payload and the payload values are not consistent . First Format: { Activity: Logger...
by gravi Explorer in Splunk Search 12-06-2019
0 3
0
3
aswin_asok
i, One of my value in table is being passed as an Boolean expression as below (assignment_group = 1213App_Developmen...
by aswin_asok Explorer in Splunk Search 12-06-2019
0 0
0
0
user93
I want to search an exact phrase, but surronded by wildcards. I want to be able to do this with and without specifyin...
by user93 Communicator in Splunk Search 12-06-2019
0 2
0
2
rcastello
Hello, How can I compile a stats list of what servers a user account has logged into within a specific time period? ...
by rcastello Explorer in Splunk Search 12-05-2019
0 1
0
1
curlly88
I'm tasked with searching for all users that have been disabled in the last thirty days, these are employees no longe...
by curlly88 New Member in Splunk Search 12-05-2019
0 1
0
1
wu_weidong
I'm trying to check if the first occurrence of an event is today using the query below. However, I keep getting resul...
by wu_weidong Path Finder in Splunk Search 12-05-2019
0 1
0
1
cheriemilk
Hi Team, I have below events, want to find out the latest event for each kf7 value, and then stats count based on kt...
by cheriemilk Path Finder in Splunk Search 12-05-2019
0 1
0
1
danieldu
After I updated an app, why am I getting these search errors? The limit has been reached for log messages in info.cs...
by danieldu Engager in Splunk Search 12-05-2019
10 4
10
4
phoenixdigital
Hi All, I have a Search Head Cluster and I am trying to update a global lookup file in a particular app, but am havi...
by phoenixdigital Builder in Splunk Search 12-05-2019
2 4
2
4
prettysunshinez
Hi All, I require help in extracting the words that appear right before the word. Example: Null.set.error Nullerror S...
by prettysunshinez Explorer in Splunk Search 12-05-2019
0 8
0
8
mstark31
I have a situation where I want to run a main search of one index over a time period driven by the time picker on a d...
by mstark31 Path Finder in Splunk Search 12-05-2019
0 7
0
7
contactdipesh
I have got two different tables in my Splunk dashboard and both came from different searches. Is it possible to dow...
by contactdipesh New Member in Splunk Search 12-05-2019
0 2
0
2
chaga
Can anyone tell me which ports should listen on Splunk server and on the Target server (Client)? From where to where...
by chaga New Member in Splunk Search 12-05-2019
0 1
0
1
bmorgenthaler
I'm trying to do the following query index=main earliest=-60m latest="12/4/2019:12:31:41" So 60 minutes before a s...
by bmorgenthaler Path Finder in Splunk Search 12-05-2019
0 3
0
3
samtechy
Hi, I have a transaction ,begin and complete like below with session id. Want to generate an alert if the event not ...
by samtechy Engager in Splunk Search 12-05-2019
0 2
0
2
cheriemilk
Hi team, I got error 'Error in 'eval' command: The expression is malformed. ' when running below query. Guess it's b...
by cheriemilk Path Finder in Splunk Search 12-05-2019
0 3
0
3
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...