Splunk Search

Splunk Search
Community Activity
ataunk
How do we get event count from 2 dates. Something like this - 2/11/18 3/11/18 4/1...
by ataunk Explorer in Splunk Search 11-23-2019
1 8
1
8
a212830
Hi, I noticed that one of my custom feeds has date fields (date_hour, date_mday...), but other ones, which are nativ...
by a212830 Champion in Splunk Search 11-23-2019
2 4
2
4
nomadichunters
Query: index=data_core sourcetype=data_log is_scheduled=1 | rex max_match=0 field=search "savedsearch\s{0,}\"{1}(?(...
by nomadichunters Explorer in Splunk Search 11-23-2019
0 5
0
5
nirmalya2006
HI All I have a lookup table which is populated by a scheduled search once everyday. The lookup table looks like bel...
by nirmalya2006 Path Finder in Splunk Search 11-23-2019
0 7
0
7
meleschi
Hello! If I run this query, I'll get a graph of the # of queries over time aggregated for all of my hosts. host=* |...
by meleschi Explorer in Splunk Search 11-22-2019
0 4
0
4
kimle
I'm trying to upload a CSV file into Splunk, however, it doesn't seem to parse it correctly for the multiple values f...
by kimle Engager in Splunk Search 11-22-2019
0 3
0
3
Chandras11
Hi All, I have a field "CATEGORY3," with strings for example:- Log 1.2 Bundle With 12 INC Log 1.2 Bundle With 3 INC...
by Chandras11 Communicator in Splunk Search 11-22-2019
0 5
0
5
atatistcheff
Any time I try using the Extract Field option in an event list the next page returns this error: Error in 'rex' comm...
by atatistcheff Explorer in Splunk Search 11-22-2019
0 7
0
7
mbasharat
Hi, I have a field value as below. These are all fixed positions all across. /COMPANY LOCATIONS/PA/PHILADELPHIA/AB...
by mbasharat Builder in Splunk Search 11-22-2019
0 4
0
4
reswob4
I'm collecting DNS logs and I'm trying to drop all logs with sub.domain.com as the query. In my transforms.conf I ha...
by reswob4 Builder in Splunk Search 11-22-2019
0 3
0
3
jasongori
I have a geostats map in version 6.1 and I want to force it to NOT use clustering. I want to see an indicator for eac...
by jasongori Explorer in Splunk Search 11-22-2019
4 12
4
12
hbustam8063
Hi, I am a newbie to SPL. I am trying to write a regex that will extract the unix/windows path from the full_log fiel...
by hbustam8063 New Member in Splunk Search 11-22-2019
0 5
0
5
nkumar6
I have a search string that runs a SQL search and returns two columns (items and count) from DB. I run this search o...
by nkumar6 Explorer in Splunk Search 11-22-2019
0 4
0
4
gravi
Hi, I have a Timestamp field as Fri Nov 22 03:37:15 UTC 2019 and I want to convert into YYYY-MM-DD HH:MM:SS:6Q form...
by gravi Explorer in Splunk Search 11-22-2019
0 3
0
3
raja8220
Need to perform the full audit of all the network and servers.
by raja8220 New Member in Splunk Search 11-22-2019
0 2
0
2
vjzone
How can I make this search efficient? earliest=-1m source="/var/log/aws/opsworks/opsworks-agent.statistics.log" hos...
by vjzone Path Finder in Splunk Search 11-22-2019
0 8
0
8
balash1979
Here is the output of my log message: {"line":"2019-11-21T22:09:29.982Z LCS LCE [abc-75] INFO i.r.queue.poller.S...
by balash1979 Path Finder in Splunk Search 11-22-2019
0 4
0
4
majek81
Good morning to all, I want to add up the IPs in each row under the Affected_IPs field and output the count into the...
by majek81 New Member in Splunk Search 11-22-2019
0 8
0
8
47024
I'm trying to capture occurrences when multiple criteria are true in an event where elements can exist multiple times...
by 47024 New Member in Splunk Search 11-22-2019
0 4
0
4
kcchu01
Original Search sourcetype=xxx | dedup user | timechart span=1d count(user) I found that the results are different ...
by kcchu01 Explorer in Splunk Search 11-22-2019
0 3
0
3
rileyken2
Here is my path: C:\WebLogs\sample.domain.com\W3SVC1\u_ex191121.log I would like to grab just the "sample.domain.c...
by rileyken2 Path Finder in Splunk Search 11-22-2019
0 6
0
6
lavster
Hello, we are seeing some strange results when trying to map RAS connections to our organisation.. The search i am r...
by lavster Path Finder in Splunk Search 11-22-2019
0 1
0
1
splunkitsipoc
I am trying to ingest a doc format file into Splunk but getting it in 00\x00c\x00\x00\x00 format. Can someone help pl...
by splunkitsipoc Explorer in Splunk Search 11-22-2019
0 1
0
1
numeroinconnu12
Hello, I have a problem. This is my request, it works well. index=wineventlog EventID=4624 host=wipr625a OR h...
by numeroinconnu12 Path Finder in Splunk Search 11-22-2019
0 3
0
3
kamaleshwar
I need help in getting multiple field values into single field to compare it and get the match if any. For example, ...
by kamaleshwar Explorer in Splunk Search 11-22-2019
0 5
0
5
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors