Splunk Search

Splunk Search
Community Activity
numeroinconnu12
Hello, my research: index="dc_winaudit" host=IN1101D9 OR host=IN1101DA OR host=IN1101DB OR host="IN1101DC" OR host=...
by numeroinconnu12 Path Finder in Splunk Search 11-20-2019
0 3
0
3
martineisenkoel
Hi, Im looking for a way to group and count similar msg strings. I have the following set of data in an transaction ...
by martineisenkoel New Member in Splunk Search 11-20-2019
0 3
0
3
rczone
Hello All, THis might be simple question but need some guidance here: i'm using pattern match like below but not s...
by rczone Path Finder in Splunk Search 11-20-2019
0 6
0
6
Graham_Hanningt
I know how to use Splunk 7.3.0 to overrride source type per event using a backreference. For example, given this snip...
by Graham_Hanningt Builder in Splunk Search 11-20-2019
1 9
1
9
monipinni
Base search | search "body.refundTenderType"=* | search "body.refundTenders{}.paymentType"=* | rename body.refundTend...
by monipinni Explorer in Splunk Search 11-20-2019
0 0
0
0
nukarajusundeep
I am using this query but I am not getting any data | jirarest jqlsearch "project = CHANGE AND issuetype in ("App C...
by nukarajusundeep New Member in Splunk Search 11-20-2019
0 6
0
6
renjujacob88
HI I need to get top 10 values of the src_count on each grouped item. The query which i have is index=palo | st...
by renjujacob88 Path Finder in Splunk Search 11-20-2019
1 4
1
4
abhilashr
Hi, I am a beginner here. We run a prediction platform for network incidents and wish to integrate with Splunk. We w...
by abhilashr New Member in Splunk Search 11-20-2019
0 1
0
1
eliassplunk
Stats count is not showing me the number of counts if there are no events for the particular search. index="myIndex...
by eliassplunk Explorer in Splunk Search 11-20-2019
1 8
1
8
ferenc0521
| makeresults | eval A=" North|WidgetA|1000### South|WidgetA|2000### East|WidgetA|1000### West|WidgetA|300### Nor...
by ferenc0521 New Member in Splunk Search 11-20-2019
0 0
0
0
jip31
Hi I would like to know if there is a way to define a number of line (8 for example) to display in a single panel wit...
by jip31 Motivator in Splunk Search 11-20-2019
0 1
0
1
codedtech
Hello, I'm building a search that tracks the use of memory allocated(mem_alloc), memory in use(mem_used), CPU in use...
by codedtech Path Finder in Splunk Search 11-20-2019
0 3
0
3
harishalipaka
Hi All, When i run this query |rest services/data/lookup-table-files I get a list of CSV data. From that, i want to ...
by harishalipaka Motivator in Splunk Search 11-20-2019
1 4
1
4
duwenhua
How to determine if a value changes with time, the last five values are always incremented, and then set to alarm
by duwenhua New Member in Splunk Search 11-20-2019
0 1
0
1
spisiakmi
Hi, I have 2 different indexes. Index1: _time Fehlermeldungtext 2019-07-01 22:01:30 Streckenüberwachung Auslauf! 20...
by spisiakmi Contributor in Splunk Search 11-20-2019
0 3
0
3
schomar
We are trying to upload a text file with German text, but the German umlaute are not recognized Manual file upload ...
by schomar New Member in Splunk Search 11-20-2019
0 2
0
2
90509
Hi, could you please help me with below info: user service name device abc12...
by 90509 Engager in Splunk Search 11-20-2019
0 5
0
5
mrcassout
Can I place a TAG within a TAG? I am creating different level TAGs, where I have a lower level containing specific s...
by mrcassout New Member in Splunk Search 11-20-2019
0 2
0
2
rohankin
Hi , I want to join the two lookups based on one field that I am creating conditionally in the second lookup. So, Lo...
by rohankin New Member in Splunk Search 11-20-2019
0 3
0
3
mgbersales
I am creating a query to check if a list of accounts owned by our team exists and with correct privilege type in anot...
by mgbersales Loves-to-Learn in Splunk Search 11-20-2019
0 2
0
2
shivam_j
Hi All, I want to extract the log to be extracted from error message till : message : , but not getting it, I have tr...
by shivam_j New Member in Splunk Search 11-19-2019
0 7
0
7
andrewtrobec
Hello, After debugging a search I discovered that the max_mem_usage_mb limit on my system had been reached. A chang...
by andrewtrobec Motivator in Splunk Search 11-19-2019
0 0
0
0
amifune_splunk
Splunk Certified User 認定試験は日本語で受けられますか?
by amifune_splunk Splunk Employee Splunk Employee in Splunk Search 11-19-2019
1 1
1
1
willadams
I am writing a custom dashboard that shows the number of alerts based on severity. The severities are Critical, High...
by willadams Contributor in Splunk Search 11-19-2019
0 5
0
5
oliverj
(Splunk 7.2.3) I have a single windows domain. Inside that domain I have 2 subnets, 192.168.1.x, 192.168.2.x. I have ...
by oliverj Communicator in Splunk Search 11-19-2019
1 6
1
6
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...