Splunk Search

Splunk Search
Community Activity
jamesofthedead8
Trying to calculate out a "TransactionTime" time by pairing two events by one matching field (ECID) and then working ...
by jamesofthedead8 Explorer in Splunk Search 10-28-2019
0 4
0
4
jwalzerpitt
I have the following search looking for > three login attempts with > 0 successes and two or > failures by user, src,...
by jwalzerpitt Influencer in Splunk Search 10-28-2019
0 6
0
6
gopenshaw
Hi, I'm having an issue with a splunk lookup and I can't work out what the issue is. I have a lookup file, that amon...
by gopenshaw Explorer in Splunk Search 10-28-2019
0 1
0
1
evelenke
Hi Splunkers, when I set 2 conditions for the same field to where stanza - I get 0 results. Example: | tstats summa...
by evelenke Contributor in Splunk Search 10-28-2019
1 6
1
6
loza176
I'm having trouble writing a query in splunk to notify me when a user has been added to one or more groups in a speci...
by loza176 New Member in Splunk Search 10-27-2019
0 4
0
4
thomaszheng
Please help, I'm stuck on this problem for a while. Basically, lets say I have different events with fields like this...
by thomaszheng New Member in Splunk Search 10-26-2019
0 1
0
1
jgillman
I have been trying to sort this and I can not seem to be able to get it. index=uberagent* sourcetype=uberAgent:Syst...
by jgillman Explorer in Splunk Search 10-26-2019
0 5
0
5
pavanae
The following are my transforms.conf and props.conf in my cluster master transforms.conf [send_to_heavyforwarder]...
by pavanae Builder in Splunk Search 10-26-2019
0 3
0
3
shashwatsandeep
We have newly setup the Splunk Environment in AWS platform where we have used LDAP authentication method and created ...
by shashwatsandeep New Member in Splunk Search 10-25-2019
0 1
0
1
Deepz2612
I want to extract the Autosys_Job from the below log snippet and so used the below rex. Log Snippet : Query : rex ...
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 2
0
2
HeinzWaescher
Hi, I would like to know whether it is possible to perform something like this per default for each and every search...
by HeinzWaescher Motivator in Splunk Search 10-25-2019
0 4
0
4
lsy9891
I displayed the percentage values by enabling this: <option name="charting.chart.showPercent">1</option> And I t...
by lsy9891 Engager in Splunk Search 10-25-2019
0 1
0
1
aohls
I want to get a 7 day and 30 day average in a single search. sourcetype="businessService" OR sourcetype="bpmservice-...
by aohls Contributor in Splunk Search 10-25-2019
0 3
0
3
jsmithn
I am trying to create a search that evaluates today's date and uses that output string/field as part of the search: ...
by jsmithn Path Finder in Splunk Search 10-25-2019
0 7
0
7
mtrochym
I am banging my head trying to understand the map command and how it works. I have one search that returns values:...
by mtrochym Observer in Splunk Search 10-25-2019
0 4
0
4
romainbouajila
Hello, I'm having a little trouble solving this one. I managed to extract all hosts in Splunk in a table with events...
by romainbouajila Path Finder in Splunk Search 10-25-2019
0 9
0
9
eddy_liao
Hi I have a very wierd requirement to transform the result of my search **EMPLOYEE, BOSS** ERIC, CHRIS CHRIS, MACK ...
by eddy_liao Engager in Splunk Search 10-25-2019
1 3
1
3
digable1
(this may be a duplicate, as I wrote a version of this question before registering and can't find it) I have a situa...
by digable1 New Member in Splunk Search 10-25-2019
0 2
0
2
mohammedk01
Hi, I have a field called Location and It have data like Call Type, Site, Wing and Room all in just one field called...
by mohammedk01 Explorer in Splunk Search 10-25-2019
0 4
0
4
kartm2020
We have two different scheduled search and it is providing the two different result. I would like send the both of th...
by kartm2020 Communicator in Splunk Search 10-25-2019
0 1
0
1
Deepz2612
I have the below set of events where I wanted to write regex to capture only the last word Kindly help
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 3
0
3
reneedeleon
I have been working on a search that gives a duration breakdown. I am trying to achieve: thehost theip c...
by reneedeleon Engager in Splunk Search 10-25-2019
0 22
0
22
vkrishnachand
I have a table as shown below team open>3 days open>4 days Avg_days_task_open A 2 4...
by vkrishnachand New Member in Splunk Search 10-25-2019
0 1
0
1
sandeepmakkena
I have data something like this Name. Accepted Rejected Posted Total Change ...
by sandeepmakkena Contributor in Splunk Search 10-25-2019
1 4
1
4
bineetadas
events are like this : number = INCXXXXXX dv_sys = yyyy-mm-dd hh:mm:ss group = lx ........ for a particular value of ...
by bineetadas New Member in Splunk Search 10-25-2019
0 2
0
2
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors