Splunk Search

Splunk Search
Community Activity
kimle
I'm trying to upload a CSV file into Splunk, however, it doesn't seem to parse it correctly for the multiple values f...
by kimle Engager in Splunk Search 11-22-2019
0 3
0
3
Chandras11
Hi All, I have a field "CATEGORY3," with strings for example:- Log 1.2 Bundle With 12 INC Log 1.2 Bundle With 3 INC...
by Chandras11 Communicator in Splunk Search 11-22-2019
0 5
0
5
atatistcheff
Any time I try using the Extract Field option in an event list the next page returns this error: Error in 'rex' comm...
by atatistcheff Explorer in Splunk Search 11-22-2019
0 7
0
7
mbasharat
Hi, I have a field value as below. These are all fixed positions all across. /COMPANY LOCATIONS/PA/PHILADELPHIA/AB...
by mbasharat Builder in Splunk Search 11-22-2019
0 4
0
4
reswob4
I'm collecting DNS logs and I'm trying to drop all logs with sub.domain.com as the query. In my transforms.conf I ha...
by reswob4 Builder in Splunk Search 11-22-2019
0 3
0
3
jasongori
I have a geostats map in version 6.1 and I want to force it to NOT use clustering. I want to see an indicator for eac...
by jasongori Explorer in Splunk Search 11-22-2019
4 12
4
12
hbustam8063
Hi, I am a newbie to SPL. I am trying to write a regex that will extract the unix/windows path from the full_log fiel...
by hbustam8063 New Member in Splunk Search 11-22-2019
0 5
0
5
nkumar6
I have a search string that runs a SQL search and returns two columns (items and count) from DB. I run this search o...
by nkumar6 Explorer in Splunk Search 11-22-2019
0 4
0
4
gravi
Hi, I have a Timestamp field as Fri Nov 22 03:37:15 UTC 2019 and I want to convert into YYYY-MM-DD HH:MM:SS:6Q form...
by gravi Explorer in Splunk Search 11-22-2019
0 3
0
3
raja8220
Need to perform the full audit of all the network and servers.
by raja8220 New Member in Splunk Search 11-22-2019
0 2
0
2
vjzone
How can I make this search efficient? earliest=-1m source="/var/log/aws/opsworks/opsworks-agent.statistics.log" hos...
by vjzone Path Finder in Splunk Search 11-22-2019
0 8
0
8
balash1979
Here is the output of my log message: {"line":"2019-11-21T22:09:29.982Z LCS LCE [abc-75] INFO i.r.queue.poller.S...
by balash1979 Path Finder in Splunk Search 11-22-2019
0 4
0
4
majek81
Good morning to all, I want to add up the IPs in each row under the Affected_IPs field and output the count into the...
by majek81 New Member in Splunk Search 11-22-2019
0 8
0
8
47024
I'm trying to capture occurrences when multiple criteria are true in an event where elements can exist multiple times...
by 47024 New Member in Splunk Search 11-22-2019
0 4
0
4
kcchu01
Original Search sourcetype=xxx | dedup user | timechart span=1d count(user) I found that the results are different ...
by kcchu01 Explorer in Splunk Search 11-22-2019
0 3
0
3
rileyken2
Here is my path: C:\WebLogs\sample.domain.com\W3SVC1\u_ex191121.log I would like to grab just the "sample.domain.c...
by rileyken2 Path Finder in Splunk Search 11-22-2019
0 6
0
6
lavster
Hello, we are seeing some strange results when trying to map RAS connections to our organisation.. The search i am r...
by lavster Path Finder in Splunk Search 11-22-2019
0 1
0
1
splunkitsipoc
I am trying to ingest a doc format file into Splunk but getting it in 00\x00c\x00\x00\x00 format. Can someone help pl...
by splunkitsipoc Explorer in Splunk Search 11-22-2019
0 1
0
1
numeroinconnu12
Hello, I have a problem. This is my request, it works well. index=wineventlog EventID=4624 host=wipr625a OR h...
by numeroinconnu12 Path Finder in Splunk Search 11-22-2019
0 3
0
3
kamaleshwar
I need help in getting multiple field values into single field to compare it and get the match if any. For example, ...
by kamaleshwar Explorer in Splunk Search 11-22-2019
0 5
0
5
dani9
The value of env var SPLUNK_OS_USER, "splunk", does not match any user on this system; Error: Success This command ...
by dani9 Explorer in Splunk Search 11-21-2019
0 1
0
1
yuanliu
Update: I found this question https://answers.splunk.com/answers/610037/my-search-string-is-truncated-after-a-questio...
by SplunkTrust SplunkTrust in Splunk Search 11-21-2019
0 2
0
2
majek81
Hello everyone, I am trying to extract strings containing SAMM #2222-A-1111 from other strings in a field named SA...
by majek81 New Member in Splunk Search 11-21-2019
0 3
0
3
Regleston
I am trying to extract the "Time taken" from this field. 2019-11-20 09:38:22,157 INFO Time taken: 01:35:53.514 The...
by Regleston New Member in Splunk Search 11-21-2019
0 3
0
3
shwetamis
I have a log below and I want to get the value of Description under :- Calling Checklist1003 How do I do that ?? Me...
by shwetamis Explorer in Splunk Search 11-21-2019
0 21
0
21
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...