Splunk Search

Splunk Search
Community Activity
gopenshaw
Hi, I'm having an issue with a splunk lookup and I can't work out what the issue is. I have a lookup file, that amon...
by gopenshaw Explorer in Splunk Search 10-28-2019
0 1
0
1
evelenke
Hi Splunkers, when I set 2 conditions for the same field to where stanza - I get 0 results. Example: | tstats summa...
by evelenke Contributor in Splunk Search 10-28-2019
1 6
1
6
loza176
I'm having trouble writing a query in splunk to notify me when a user has been added to one or more groups in a speci...
by loza176 New Member in Splunk Search 10-27-2019
0 4
0
4
thomaszheng
Please help, I'm stuck on this problem for a while. Basically, lets say I have different events with fields like this...
by thomaszheng New Member in Splunk Search 10-26-2019
0 1
0
1
jgillman
I have been trying to sort this and I can not seem to be able to get it. index=uberagent* sourcetype=uberAgent:Syst...
by jgillman Explorer in Splunk Search 10-26-2019
0 5
0
5
pavanae
The following are my transforms.conf and props.conf in my cluster master transforms.conf [send_to_heavyforwarder]...
by pavanae Builder in Splunk Search 10-26-2019
0 3
0
3
shashwatsandeep
We have newly setup the Splunk Environment in AWS platform where we have used LDAP authentication method and created ...
by shashwatsandeep New Member in Splunk Search 10-25-2019
0 1
0
1
Deepz2612
I want to extract the Autosys_Job from the below log snippet and so used the below rex. Log Snippet : Query : rex ...
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 2
0
2
HeinzWaescher
Hi, I would like to know whether it is possible to perform something like this per default for each and every search...
by HeinzWaescher Motivator in Splunk Search 10-25-2019
0 4
0
4
lsy9891
I displayed the percentage values by enabling this: <option name="charting.chart.showPercent">1</option> And I t...
by lsy9891 Engager in Splunk Search 10-25-2019
0 1
0
1
aohls
I want to get a 7 day and 30 day average in a single search. sourcetype="businessService" OR sourcetype="bpmservice-...
by aohls Contributor in Splunk Search 10-25-2019
0 3
0
3
jsmithn
I am trying to create a search that evaluates today's date and uses that output string/field as part of the search: ...
by jsmithn Path Finder in Splunk Search 10-25-2019
0 7
0
7
mtrochym
I am banging my head trying to understand the map command and how it works. I have one search that returns values:...
by mtrochym Observer in Splunk Search 10-25-2019
0 4
0
4
romainbouajila
Hello, I'm having a little trouble solving this one. I managed to extract all hosts in Splunk in a table with events...
by romainbouajila Path Finder in Splunk Search 10-25-2019
0 9
0
9
eddy_liao
Hi I have a very wierd requirement to transform the result of my search **EMPLOYEE, BOSS** ERIC, CHRIS CHRIS, MACK ...
by eddy_liao Engager in Splunk Search 10-25-2019
1 3
1
3
digable1
(this may be a duplicate, as I wrote a version of this question before registering and can't find it) I have a situa...
by digable1 New Member in Splunk Search 10-25-2019
0 2
0
2
mohammedk01
Hi, I have a field called Location and It have data like Call Type, Site, Wing and Room all in just one field called...
by mohammedk01 Explorer in Splunk Search 10-25-2019
0 4
0
4
kartm2020
We have two different scheduled search and it is providing the two different result. I would like send the both of th...
by kartm2020 Communicator in Splunk Search 10-25-2019
0 1
0
1
Deepz2612
I have the below set of events where I wanted to write regex to capture only the last word Kindly help
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 3
0
3
reneedeleon
I have been working on a search that gives a duration breakdown. I am trying to achieve: thehost theip c...
by reneedeleon Engager in Splunk Search 10-25-2019
0 22
0
22
vkrishnachand
I have a table as shown below team open>3 days open>4 days Avg_days_task_open A 2 4...
by vkrishnachand New Member in Splunk Search 10-25-2019
0 1
0
1
sandeepmakkena
I have data something like this Name. Accepted Rejected Posted Total Change ...
by sandeepmakkena Contributor in Splunk Search 10-25-2019
1 4
1
4
bineetadas
events are like this : number = INCXXXXXX dv_sys = yyyy-mm-dd hh:mm:ss group = lx ........ for a particular value of ...
by bineetadas New Member in Splunk Search 10-25-2019
0 2
0
2
williamcharlton
This cli search command works from a machine with a universal forwarder: splunk search "index="foo" earliest=-7d | ...
by williamcharlton Path Finder in Splunk Search 10-25-2019
0 6
0
6
milky88
I have a field called data. Example of what is in the data field. 1234567890 9999999999 7638278823 1234567891 8475627...
by milky88 New Member in Splunk Search 10-25-2019
0 1
0
1
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors