Splunk Search

Splunk Search
Community Activity
janitka
Hello, I'm trying to join two searches, and i need to use host in the other one, to be able to table it by DesktopGr...
by janitka Explorer in Splunk Search 11-25-2019
0 9
0
9
jip31
hi I tried to find host from my csv file which have connected in one specific index but never in others I have done t...
by jip31 Motivator in Splunk Search 11-25-2019
0 2
0
2
anem
I have used mcollect command to populate my metric index later i tried to pull up that data via mstats command but fo...
by anem Explorer in Splunk Search 11-25-2019
0 0
0
0
elumpkin_caisgr
A dashboard will export to PDF correctly, but anytime we try to send it via email (be it a test email or scheduled) n...
by elumpkin_caisgr Engager in Splunk Search 11-25-2019
0 8
0
8
k_harini
I have a drop down which I populate with the query and editing field values index="myindex"|stats values(Category) as...
by k_harini Communicator in Splunk Search 11-24-2019
0 6
0
6
datamine
hi All, Am trying to extract the fields for only the text when it contains start or end as my test_status field that...
by datamine Loves-to-Learn Lots in Splunk Search 11-24-2019
0 2
0
2
prannoy93singh
It shows the result in the below format uri 208 400 ... .... ... I want ...
by prannoy93singh Engager in Splunk Search 11-24-2019
0 5
0
5
jip31
Hi I use the search below which works fine but I have an issue with my eval command why i can retrieve the "No SPLUNK...
by jip31 Motivator in Splunk Search 11-24-2019
1 9
1
9
yuanliu
Delta cites an example using sort - _time. Is there a difference in efficiency between this sort and reverse?
by SplunkTrust SplunkTrust in Splunk Search 11-23-2019
1 3
1
3
ataunk
How do we get event count from 2 dates. Something like this - 2/11/18 3/11/18 4/1...
by ataunk Explorer in Splunk Search 11-23-2019
1 8
1
8
a212830
Hi, I noticed that one of my custom feeds has date fields (date_hour, date_mday...), but other ones, which are nativ...
by a212830 Champion in Splunk Search 11-23-2019
2 4
2
4
nomadichunters
Query: index=data_core sourcetype=data_log is_scheduled=1 | rex max_match=0 field=search "savedsearch\s{0,}\"{1}(?(...
by nomadichunters Explorer in Splunk Search 11-23-2019
0 5
0
5
nirmalya2006
HI All I have a lookup table which is populated by a scheduled search once everyday. The lookup table looks like bel...
by nirmalya2006 Path Finder in Splunk Search 11-23-2019
0 7
0
7
meleschi
Hello! If I run this query, I'll get a graph of the # of queries over time aggregated for all of my hosts. host=* |...
by meleschi Explorer in Splunk Search 11-22-2019
0 4
0
4
kimle
I'm trying to upload a CSV file into Splunk, however, it doesn't seem to parse it correctly for the multiple values f...
by kimle Engager in Splunk Search 11-22-2019
0 3
0
3
Chandras11
Hi All, I have a field "CATEGORY3," with strings for example:- Log 1.2 Bundle With 12 INC Log 1.2 Bundle With 3 INC...
by Chandras11 Communicator in Splunk Search 11-22-2019
0 5
0
5
atatistcheff
Any time I try using the Extract Field option in an event list the next page returns this error: Error in 'rex' comm...
by atatistcheff Explorer in Splunk Search 11-22-2019
0 7
0
7
mbasharat
Hi, I have a field value as below. These are all fixed positions all across. /COMPANY LOCATIONS/PA/PHILADELPHIA/AB...
by mbasharat Builder in Splunk Search 11-22-2019
0 4
0
4
reswob4
I'm collecting DNS logs and I'm trying to drop all logs with sub.domain.com as the query. In my transforms.conf I ha...
by reswob4 Builder in Splunk Search 11-22-2019
0 3
0
3
jasongori
I have a geostats map in version 6.1 and I want to force it to NOT use clustering. I want to see an indicator for eac...
by jasongori Explorer in Splunk Search 11-22-2019
4 12
4
12
hbustam8063
Hi, I am a newbie to SPL. I am trying to write a regex that will extract the unix/windows path from the full_log fiel...
by hbustam8063 New Member in Splunk Search 11-22-2019
0 5
0
5
nkumar6
I have a search string that runs a SQL search and returns two columns (items and count) from DB. I run this search o...
by nkumar6 Explorer in Splunk Search 11-22-2019
0 4
0
4
gravi
Hi, I have a Timestamp field as Fri Nov 22 03:37:15 UTC 2019 and I want to convert into YYYY-MM-DD HH:MM:SS:6Q form...
by gravi Explorer in Splunk Search 11-22-2019
0 3
0
3
raja8220
Need to perform the full audit of all the network and servers.
by raja8220 New Member in Splunk Search 11-22-2019
0 2
0
2
vjzone
How can I make this search efficient? earliest=-1m source="/var/log/aws/opsworks/opsworks-agent.statistics.log" hos...
by vjzone Path Finder in Splunk Search 11-22-2019
0 8
0
8
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...