Splunk Search

Splunk Search
Community Activity
abhishekpatel2
We have datamodel which has 2 level DataSet(Datamodel-> Parent Dataset -> Child Dataset). We have defiend a field in ...
by abhishekpatel2 Explorer in Splunk Search 06-06-2024
0 5
0
5
JKEverything
I have a field payload containing the following JSON: { "cacheStats": { "lds:UiApi.getRecord": { ...
by JKEverything New Member in Splunk Search 06-06-2024
0 3
0
3
orendado
I'm considering loading readable/textual  files , from different formats, into splunk for getting the benefits of ind...
by orendado Loves-to-Learn in Splunk Search 06-06-2024
0 3
0
3
jbv
Hi,Is there a way to get current time on Splunk and then convert it to epoch? Im trying to create a dashboard to show...
by jbv Engager in Splunk Search 06-06-2024
0 4
0
4
jhuysing
I can create a query and produce a time chart so I can see the load across the set of cpu |timechart values(VALUE) sp...
by jhuysing Explorer in Splunk Search 06-05-2024
0 3
0
3
orendado
Hi,Let's say I'm ingesting different types of logs files from different type(some are txt,csv,json,xml....) to the sa...
by orendado Loves-to-Learn in Splunk Search 06-05-2024
0 3
0
3
rrovers
Events longer than 15.000 characters are truncated now. We wonder if there is a limit for this (so for example in the...
by rrovers Contributor in Splunk Search 06-05-2024
0 1
0
1
ClubMed
Hey,I had discovered you can emulate the mvexpand function to avoid its limitation configured by the limits.conf You ...
by ClubMed Path Finder in Splunk Search 06-05-2024
1 2
1
2
DATT
My org is pulling in vuln data using the Qualys TA and I am trying to put together a handful of searches and dashboar...
by DATT Path Finder in Splunk Search 06-04-2024
0 2
0
2
VijaySrrie
Hi Team, I need to create 3 calculated fields | eval action= case(error="invalid credentials", "failure", ((like('re...
by VijaySrrie Builder in Splunk Search 06-04-2024
0 1
0
1
cshihua
Hello Everyone,I would want to ask a question, is there any way for main search get the index return from subsearch? ...
by cshihua Engager in Splunk Search 06-04-2024
0 4
0
4
OriP
Trying to understand what is the time field after tstats. We have the _time field for every event, thats how tstats f...
by OriP New Member in Splunk Search 06-04-2024
0 2
0
2
RamMur
trying to use rex to get the contents for the field letterIdAndDeliveryIndicatorMap.For example, Logged string letter...
by RamMur Explorer in Splunk Search 06-04-2024
0 4
0
4
splunker12er
WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer. Possibilities :...
by splunker12er Motivator in Splunk Search 06-04-2024
1 14
1
14
JMPP
Hi Cummunity team, I have a complex query to gather the data below, but a new request came up, it was asked to me to ...
by JMPP Explorer in Splunk Search 06-04-2024
0 3
0
3
seaofdreams1978
Hi All, We run searches against logs that return, as part of the dataset, IP addresses. We basically want to know wha...
by seaofdreams1978 Engager in Splunk Search 06-04-2024
0 3
0
3
Anud
How to add a dummy row to the table in the Splunk dashboard.We are receiving 2 files everyday 4 times in between 6-7:...
by Anud Path Finder in Splunk Search 06-04-2024
0 3
0
3
tdavison76
Hello, I've been asked to provide a list of all Alerts/Reports/Dashboards that contain the value "You Found a bug!"  ...
by tdavison76 Path Finder in Splunk Search 06-04-2024
0 3
0
3
AL3Z
Hi all,How to give the range to that first and last if the date is in between last 3weeks till today which matches to...
by AL3Z Builder in Splunk Search 06-04-2024
0 5
0
5
mclog
Hello,I've a couple of detailed dashboards, all indicating the health status of my systems. Instead of opening each d...
by mclog New Member in Splunk Search 06-04-2024
0 2
0
2
Roy_9
Hi,can someone help me with splunk search to identify browsers installed on a machine, im looking for a specific fiel...
by Roy_9 Motivator in Splunk Search 06-04-2024
0 4
0
4
nisheethbaxi
I have a splunk query that has following text in message field - "message":"sypher:[tokenized] build successful -\xxx...
by nisheethbaxi Loves-to-Learn in Splunk Search 06-03-2024
0 4
0
4
avikc100
My Log data looks like: i am using this query: index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/ins...
by avikc100 Path Finder in Splunk Search 06-03-2024
0 1
0
1
karthi2809
Hi All, I want to filter out null values.In my field the ImpCon having null values.Now i want to filter the values wh...
by karthi2809 Builder in Splunk Search 06-03-2024
0 11
0
11
marco_massari11
Hello, I'm trying to write a Splunk search for detecting unusual behavior in emails sending, here is the spl query: |...
by marco_massari11 Communicator in Splunk Search 06-03-2024
0 8
0
8
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...