Splunk Search

Splunk Search
Community Activity
Vfinney
What would be a command to extract the url and create a new field from Cisco eStreamer logs using the rex command?
by Vfinney Observer in Splunk Search 11-26-2019
0 7
0
7
agodoy
I am trying to break a field based on some regex. Apparently this can be done with the tokenizer option of the makemv...
by agodoy Communicator in Splunk Search 11-25-2019
0 3
0
3
muizash
Why 2 different users using same Searchhead, same app and same query and same permissions get 2 different results? Co...
by muizash Path Finder in Splunk Search 11-25-2019
0 8
0
8
splunk_user_99
Hello guys, Is there any possibility to execute a CLI command within the credentials (username and password)? Like...
by splunk_user_99 Explorer in Splunk Search 11-25-2019
0 3
0
3
mustafag1
Hello all, I will be contacting the sales team as well but for now I wanted to get some clearer idea of the actual c...
by mustafag1 Explorer in Splunk Search 11-25-2019
0 2
0
2
clio706
お世話になります。 勉強し始めたばかりなので、サーチ文の書き方についてご教示ください。 やりたいことは下記の通りです。 ・月次でログの件数をカウントする。 ・前月、前々月でカウント数の比較を行う。 ・比較結果から増加率を算出する...
by clio706 Explorer in Splunk Search 11-25-2019
0 7
0
7
datamine
Hi all, I have a chart displaying 3 line charts based on our test results. Now we would like to show the test start ...
by datamine Loves-to-Learn Lots in Splunk Search 11-25-2019
0 1
0
1
raoul
Is there an example of the correct xml syntax to use to define a bubble chart in a dashboard? I cannot find one in th...
by raoul Path Finder in Splunk Search 11-25-2019
3 3
3
3
david_keough
Splunk 7.2.3 I have been trying to use timechart to graph synthetic transaction application response times. The ca...
by david_keough Explorer in Splunk Search 11-25-2019
0 2
0
2
jlucas4
I came across this bug today when using strptime. Strptime does not work on field names that have spaces or periods. ...
by jlucas4 Explorer in Splunk Search 11-25-2019
0 6
0
6
mrkala
I am new to Splunk and trying to create an alert for a message however I keep getting false positives on the message ...
by mrkala New Member in Splunk Search 11-25-2019
0 3
0
3
monipinni
base search | spath "body.totalTime" | search "body.totalTime"=426287 How to convert milliseconds to minutes or sec...
by monipinni Explorer in Splunk Search 11-25-2019
0 6
0
6
chktlm
Hi. I am trying to get a count on the first field within my logs, of the requestBody json input. Below is an example ...
by chktlm New Member in Splunk Search 11-25-2019
0 2
0
2
janitka
Hello, I'm trying to join two searches, and i need to use host in the other one, to be able to table it by DesktopGr...
by janitka Explorer in Splunk Search 11-25-2019
0 9
0
9
jip31
hi I tried to find host from my csv file which have connected in one specific index but never in others I have done t...
by jip31 Motivator in Splunk Search 11-25-2019
0 2
0
2
anem
I have used mcollect command to populate my metric index later i tried to pull up that data via mstats command but fo...
by anem Explorer in Splunk Search 11-25-2019
0 0
0
0
elumpkin_caisgr
A dashboard will export to PDF correctly, but anytime we try to send it via email (be it a test email or scheduled) n...
by elumpkin_caisgr Engager in Splunk Search 11-25-2019
0 8
0
8
k_harini
I have a drop down which I populate with the query and editing field values index="myindex"|stats values(Category) as...
by k_harini Communicator in Splunk Search 11-24-2019
0 6
0
6
datamine
hi All, Am trying to extract the fields for only the text when it contains start or end as my test_status field that...
by datamine Loves-to-Learn Lots in Splunk Search 11-24-2019
0 2
0
2
prannoy93singh
It shows the result in the below format uri 208 400 ... .... ... I want ...
by prannoy93singh Engager in Splunk Search 11-24-2019
0 5
0
5
jip31
Hi I use the search below which works fine but I have an issue with my eval command why i can retrieve the "No SPLUNK...
by jip31 Motivator in Splunk Search 11-24-2019
1 9
1
9
yuanliu
Delta cites an example using sort - _time. Is there a difference in efficiency between this sort and reverse?
by SplunkTrust SplunkTrust in Splunk Search 11-23-2019
1 3
1
3
ataunk
How do we get event count from 2 dates. Something like this - 2/11/18 3/11/18 4/1...
by ataunk Explorer in Splunk Search 11-23-2019
1 8
1
8
a212830
Hi, I noticed that one of my custom feeds has date fields (date_hour, date_mday...), but other ones, which are nativ...
by a212830 Champion in Splunk Search 11-23-2019
2 4
2
4
nomadichunters
Query: index=data_core sourcetype=data_log is_scheduled=1 | rex max_match=0 field=search "savedsearch\s{0,}\"{1}(?(...
by nomadichunters Explorer in Splunk Search 11-23-2019
0 5
0
5
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...