Splunk Search

Splunk Search
Community Activity
dude49
Hey guys, I am working a report that needs to show any new employees coming into the company for the last 30 days. Ri...
by dude49 Explorer in Splunk Search 05-14-2024
0 2
0
2
IAskALotOfQs
Hi all, I'm trying to get all the saved searches in Splunk that are in all apps. Could someone explain to me what the...
by IAskALotOfQs Path Finder in Splunk Search 05-14-2024
0 3
0
3
OpeKush
Hi I was wondering if there was a way I could blacklist the following event based on the event code and the account n...
by OpeKush New Member in Splunk Search 05-14-2024
0 2
0
2
SplunkNinja
I am seeing the following alert on the Searching and Reporting App and also within the InfoSec App for Splunk.[idx-1,...
by SplunkNinja Path Finder in Splunk Search 05-14-2024
0 4
0
4
avi123
Hi All,I have a query which returns results for a particular month like how many tickets breached SLA. The month and ...
by avi123 Explorer in Splunk Search 05-13-2024
0 1
0
1
karthi2809
Hi All,Below query to get stats sum of field values of latest correlationId. need to show in pie chart. But i am gett...
by karthi2809 Builder in Splunk Search 05-13-2024
0 3
0
3
marioosh2
How to convert table like this (2 rows per topic): topic   mbean_property_name bytesA   BytesOutPerSec  60376267182A ...
by marioosh2 Engager in Splunk Search 05-13-2024
0 3
0
3
gschauhan81
Hello everyone Can anyone suggest me a search where I can get the notable Event time review between various phases of...
by gschauhan81 New Member in Splunk Search 05-13-2024
0 5
0
5
sanjai
Hello Splunk Community,I'm encountering challenges while converting multivalue fields to single value fields for effe...
by sanjai Path Finder in Splunk Search 05-12-2024
0 3
0
3
R_Ramanan
I am using query as below  index="test" sourcetype="reports" | bin _time span=1m | stats values(a) as a values(b) as ...
by R_Ramanan Loves-to-Learn in Splunk Search 05-12-2024
0 5
0
5
Jasmine
If attr.error exist then Error will be attr.error. If attr.error not exist and attr.error.errmsg exist then Error wou...
by Jasmine Path Finder in Splunk Search 05-12-2024
0 2
0
2
Jasmine
In the below query if c= I,  the reg expression is | rex field=attr.namespace "(?<DB>[^\.]*)"if c= other than "I" the...
by Jasmine Path Finder in Splunk Search 05-11-2024
0 1
0
1
phularah
So, I have data like this after I ran a query. For each aggregator, if the aggregator_status is Error and before15 mi...
by phularah Communicator in Splunk Search 05-11-2024
0 3
0
3
splunk6
Hi All,I have a soap request and response being ingested in the splunk under an index. There are multiple API calls a...
by splunk6 Path Finder in Splunk Search 05-11-2024
0 1
0
1
jayita1989
Hello,Can someone please help me in extracting nested json fields without regex?I have tried below:1. Updating KV_mod...
by jayita1989 Loves-to-Learn Lots in Splunk Search 05-10-2024
0 7
0
7
karthi2809
Hi All,I have a field in my data called 'message' ,which contain information about status of the field.I'd like categ...
by karthi2809 Builder in Splunk Search 05-10-2024
0 3
0
3
bhavesh0124
I'm running stats to find out which events I want to delete. Basically I'm finding the minimum "change_set" a particu...
by bhavesh0124 Explorer in Splunk Search 05-10-2024
0 7
0
7
howard_mclean
what is the best approach to run splunk queries
by howard_mclean New Member in Splunk Search 05-10-2024
0 1
0
1
bofasplunkguy
I am trying to show a "primary" and "secondary" IP in rows to recreate a spreadsheet. I currently have a search like:...
by bofasplunkguy Explorer in Splunk Search 05-10-2024
0 4
0
4
jaibalaraman
Splunk search " EventCode="4688" AND earliest="5/8/2024:10:07:20" latest="5/8/2024:10:17:20 " Could you please the ti...
by jaibalaraman Path Finder in Splunk Search 05-10-2024
0 6
0
6
Orange_girl
Hello, I have a really basic question  I have a .csv file saved in SPLUNK, which I believe is indexed - this is not ...
by Orange_girl Loves-to-Learn Everything in Splunk Search 05-10-2024
0 11
0
11
nsiva
my output in splunk is as below <error code #> IP Address is x.y.z.a  I want to extract only the x.y.z.a and its coun...
by nsiva New Member in Splunk Search 05-10-2024
0 6
0
6
karthi2809
Hi All, This the query which i try to get status.But in the table its shows both error and success.PFA screenshot | e...
by karthi2809 Builder in Splunk Search 05-10-2024
0 7
0
7
Jamietriplet
I am trying to compute the R-squared value of a set of measured values, to verify the performance or accuracy of a pr...
by Jamietriplet Explorer in Splunk Search 05-10-2024
0 1
0
1
vineela
i have a log and i am able to fetch all the codes which is of same format, but not able to fetch logs of one error co...
by vineela Path Finder in Splunk Search 05-09-2024
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...