Splunk Search

Splunk Search
Community Activity
mbasharat
I have an index=os It has a field name os_description. This field has multiple versions/flavors of os mentioned in va...
by mbasharat Builder in Splunk Search 11-06-2019
0 5
0
5
weidertc
I must be out of my mind. The comments built-in macro since version 6.5.0 gives me an error that it can't find the ma...
by weidertc Contributor in Splunk Search 11-06-2019
1 8
1
8
nanachu
Hi all I have event like that. 2019-10-26 15:00:09.158, servicename="ROOT2", area="SCP", place="tokyo", path="AAA12...
by nanachu Path Finder in Splunk Search 11-06-2019
0 4
0
4
benkeen
Hi all, brand new to splunk search syntax. I have a command like so: ... | stats count by userAgent, browserVersion,...
by benkeen Engager in Splunk Search 11-05-2019
0 2
0
2
JyotiP
I have the followinf query sourcetype="server" host=*localqa* | stats count by Path | rex field=Path "\/a...
by JyotiP Path Finder in Splunk Search 11-05-2019
0 3
0
3
gopiven
Hi experts! Since I am new to Splunk, I understand that we cannot use a time chart with inputlookup(?). But I am usi...
by gopiven Explorer in Splunk Search 11-05-2019
0 2
0
2
mitsost
Greetings all, Noob here. I have the following timechart: index=fileshare user_login=john_doe@mycompany.com (event_...
by mitsost Path Finder in Splunk Search 11-05-2019
1 19
1
19
justinsplunk_12
Hi all, I'm working with a sample log snippet below. The overall goal is to get stats about long-running operations. ...
by justinsplunk_12 Explorer in Splunk Search 11-05-2019
1 7
1
7
mchang_splunk
We have a critical dashboard where users need to click on the magnifying glass to open up that search in a search win...
by mchang_splunk Splunk Employee Splunk Employee in Splunk Search 11-05-2019
0 1
0
1
rschuetzler
I have a set of log data that is basically in this format: Event timestamp user 6 10/14/2019 1:29 Use...
by rschuetzler Explorer in Splunk Search 11-05-2019
0 4
0
4
danielbb
We need to decide soon how much storage to allocate to the hot/warm volume versus the cold one. Therefore, I would li...
by danielbb Motivator in Splunk Search 11-05-2019
0 7
0
7
edoardo_vicendo
Hi all, In the middle of a search, I have two string fields, one is called A and the other B (both have the ";" as d...
by edoardo_vicendo Builder in Splunk Search 11-05-2019
1 4
1
4
surekhasplunk
The search I am using is below and in the output for few I am getting 3 records in the filed manage. Please help me t...
by surekhasplunk Communicator in Splunk Search 11-05-2019
0 5
0
5
bineetadas
If a certain incident is in resolved/closed state I want all logs pertaining to that incident to be excluded from the...
by bineetadas New Member in Splunk Search 11-05-2019
0 3
0
3
chrishartsock
Hello, I am currently trying to do a search across two different sourcetypes using the map command: sourcetype=sour...
by chrishartsock Path Finder in Splunk Search 11-05-2019
0 7
0
7
prettysunshinez
Hi, I would want to have the count of a string (say "abcdef"). sometimes the string occurs multiple times in the sam...
by prettysunshinez Explorer in Splunk Search 11-05-2019
0 1
0
1
matimat
Hi, I want to show how many lines contains some value even if no line return. My data : Row 1 : F1: a Row 2 ...
by matimat Explorer in Splunk Search 11-05-2019
1 4
1
4
steffen1
I have the data field "user" with data like: user1, user1, user2, user2, user3, user3, user3, ... How do I get/coun...
by steffen1 Engager in Splunk Search 11-04-2019
0 4
0
4
ayush1906
Hi , My current index when done table shows: Name| Attendance | Class abc | Present | 2A efg ...
by ayush1906 Communicator in Splunk Search 11-04-2019
0 3
0
3
basplunk
How differences named capturing group expression between "(?<name>)" and "(?P<name>)"?
by basplunk New Member in Splunk Search 11-04-2019
0 2
0
2
gndivya
There are 3 different values for one particular field say field1 - "INTPAY\ITS\TD_EFT\can contain other data", "INTPA...
by gndivya Explorer in Splunk Search 11-04-2019
1 2
1
2
lsy9891
Hi how to disable the hover functionality for line charts? I've tried disabling tooltips but it just hides the label-...
by lsy9891 Engager in Splunk Search 11-04-2019
0 0
0
0
amesbury
Is there a way to set sampling for subsearches separately from the main search? For example, given a search of a hug...
by amesbury Engager in Splunk Search 11-04-2019
1 2
1
2
esalesapns2
I created a Splunk Health Dashboard for myself on the server that runs my Monitoring Console. The MC server is not ...
by esalesapns2 Communicator in Splunk Search 11-04-2019
1 1
1
1
danielransell
I'm working on creating either a report with a table or a dashboard to visualize the status of my Windows Audit Polic...
by danielransell Path Finder in Splunk Search 11-04-2019
0 8
0
8
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors