Splunk Search

Splunk Search
Community Activity
robertlynch2020
@MuS I would like to give access to some user to do refresh, i know they need admin role. However admin has 99 capa...
by robertlynch2020 Influencer in Splunk Search 11-28-2019
1 2
1
2
trojan_81
Within Splunk cloud 7.2.6 - If I run a search without specifying index or sourcetype it will search the main index b...
by trojan_81 Path Finder in Splunk Search 11-28-2019
0 4
0
4
HattrickNZ
I have the following bit of code that does a search. The results of that search populates a tickbox input. I wrote it...
by HattrickNZ Motivator in Splunk Search 11-28-2019
0 3
0
3
sarnagar
Hi, Im getting this error although I do not have any duplicate values. Below is the screenshot and my xml: <form> ...
by sarnagar Contributor in Splunk Search 11-28-2019
9 4
9
4
Svill321
Hi everyone, I'm trying to dynamically populate a dropdown menu with error codes. Obviously, I don't want duplicat...
by Svill321 Path Finder in Splunk Search 11-28-2019
1 6
1
6
tmtcollins
I have a list of article IDs and their corresponding article view counts for a given day. I want to see what percen...
by tmtcollins Explorer in Splunk Search 11-28-2019
0 3
0
3
pacifikn
Greetings!! I would like to ask about this vulnerability : https://www.bleepingcomputer.com/news/security/splunk-fac...
by pacifikn Communicator in Splunk Search 11-28-2019
0 1
0
1
abhilashr
Hi All, We have a prediction platform and we have developed a connector that can explore Splunk SDK for search and d...
by abhilashr New Member in Splunk Search 11-28-2019
0 4
0
4
jip31
hi I use the scheduled search below `winevent` (sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" AND...
by jip31 Motivator in Splunk Search 11-27-2019
1 9
1
9
stepheneardley
I've been investigating this error which is appearing 6 times per search (1 for each indexer in the cluster) for a wh...
by stepheneardley Path Finder in Splunk Search 11-27-2019
0 7
0
7
kourbeh
New to Splunk and trying to learn it: sorry for the dumb question. So I am trying to filter out a list of POS device...
by kourbeh New Member in Splunk Search 11-27-2019
0 1
0
1
jeniemmanuel
I used sourcetype-perfmon:process and i could get fields - counter/instance/object which refers process name
by jeniemmanuel New Member in Splunk Search 11-27-2019
0 2
0
2
joesrepsolc
I have a sourcetype that I'm working with and trying to break up the events by any line that says "Job start time: yy...
by joesrepsolc Communicator in Splunk Search 11-27-2019
0 5
0
5
bhavlik
I am setting up a dashboard that monitors count of events on a daily basis and a previous 30 day average by customer....
by bhavlik Path Finder in Splunk Search 11-27-2019
0 5
0
5
pavanraghav
| eval e="$time_token.earliest$", l=$time_token.latest$"| eval e=case(match(e,"^\d+$"),e,e="" OR e="now" , "0" , true...
by pavanraghav Explorer in Splunk Search 11-27-2019
0 4
0
4
whitehaven
Hi all, I've searched around a bit and I can't seem to find the answer after failing to figure it out myself. The d...
by whitehaven Explorer in Splunk Search 11-27-2019
0 7
0
7
vikashperiwal
Hi , I have a scenario where i am using KV store to get the events generated. But my query is taking 5hr to run whi...
by vikashperiwal Path Finder in Splunk Search 11-27-2019
0 4
0
4
ben_leung
In my query before, I was using the outputcsv search command, and then I had a monitoring input stanza to upload it t...
by ben_leung Builder in Splunk Search 11-27-2019
0 7
0
7
vengat4043
We have the Actual Generation Data from the Machine and also having the Set Points of the Particular Parameter. we n...
by vengat4043 Path Finder in Splunk Search 11-27-2019
0 4
0
4
akarivaratharaj
I was going through the Release note which was updated into Splunk Docs recently. https://docs.splunk.com/Documentati...
by akarivaratharaj Communicator in Splunk Search 11-27-2019
0 1
0
1
Puvi
hi, i have a string like: AAA TEST BBB 1000 CCC DDD EEE FFF GG 11111 i need to extract all the values separa...
by Puvi New Member in Splunk Search 11-27-2019
0 1
0
1
adolfus1982
Hi everybody Trying to index a multivalue field with more than 6000 characters approx. With the same sourcetype we ha...
by adolfus1982 New Member in Splunk Search 11-26-2019
0 2
0
2
test4u
Hi all, I am trying to do crud of a lookup. I ahve been following this link:- https://www.hurricanelabs.com/splunk-t...
by test4u Path Finder in Splunk Search 11-26-2019
0 5
0
5
geraldcontreras
Hi All, I cant seem to get this right. I am trying to use regex to blacklist 4656 events where: The account name en...
by geraldcontreras Path Finder in Splunk Search 11-26-2019
0 2
0
2
leandromatperei
Hello everyone. I have a code below where each event is determined by the line break. I am wanting to take the value...
by leandromatperei Path Finder in Splunk Search 11-26-2019
0 3
0
3
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Solution Authors