Splunk Search

Splunk Search
Community Activity
shugup2923
index=storage source="/******.csv" | stats sum(00_) //It represents sum of various fields | eval sum1=0 | forea...
by shugup2923 Path Finder in Splunk Search 09-25-2019
0 2
0
2
PC00128849
Lets say i have a column called as birthdate in my events and i do not want to see the events or birth records which ...
by PC00128849 New Member in Splunk Search 09-25-2019
0 3
0
3
criedman
Hello, i have only two values logout_time and online_time and i would like to get the login_time. How could i subtra...
by criedman Explorer in Splunk Search 09-25-2019
0 2
0
2
arisat
Hi, I have a rather large multiline event which I am trying to extract data from. The problem is that the format is ...
by arisat Engager in Splunk Search 09-25-2019
0 3
0
3
santosh11
Dear Team, We have configured the email notification in splunk but we are getting the below warning message. How can...
by santosh11 New Member in Splunk Search 09-24-2019
0 2
0
2
amerineni
Hi, I want to run a search for a selected time range, and also want to do a sub search for the same duration in the p...
by amerineni Loves-to-Learn in Splunk Search 09-24-2019
0 3
0
3
andydong
Somehow i have not got logs from universal forwarder servers since Sep 11, How to find out the reason ?
by andydong New Member in Splunk Search 09-24-2019
0 2
0
2
tonakano
ご教授ください。 今日の日付とデータの日付を比較し、差分(何日間)をdurationという名前で抽出ししました。 このdurationを一定の範囲の数をカウントしてビジュアライズしたいと考えたのですが、この範囲カウントが出来ませんで...
by tonakano Engager in Splunk Search 09-24-2019
0 2
0
2
999chris
Hi All, I am indexing a file with JSON and epoch values on the JSON are written in scientific notation An example o...
by 999chris New Member in Splunk Search 09-24-2019
0 3
0
3
balcv
I have a search with a bunch of OR's and I wanted to replace it with "IN" however I do not get the same results. My ...
by balcv Contributor in Splunk Search 09-24-2019
0 2
0
2
lamelendrez
Is it possible to convert a dashboard into an APP? I am trying to make it easier for managment to access it. If it ...
by lamelendrez Loves-to-Learn Lots in Splunk Search 09-24-2019
0 1
0
1
lewisgrantevans
Hi everyone, I've tried to answer this myself but no luck. I fear it might be so simple i'm overlooking it. I'm comf...
by lewisgrantevans Explorer in Splunk Search 09-24-2019
0 3
0
3
jordanking1992
Hello, We have a field called "Certificate Expiration Date" and trying to only show items that expire 90 days or le...
by jordanking1992 Path Finder in Splunk Search 09-24-2019
0 1
0
1
andytangjpmc
I have trace, level, and message fields in my events. I want to group by trace, and I also want to display all other ...
by andytangjpmc New Member in Splunk Search 09-24-2019
0 1
0
1
mbrownoutside
Hello, I'm attempting to verify a blacklist parameter for a wineventlog stanza by using regex and rex in search and ...
by mbrownoutside Path Finder in Splunk Search 09-24-2019
0 1
0
1
tescowill
We have a large number of alerts which extract data from nginx logs and ping under certain conditions. In each of the...
by tescowill New Member in Splunk Search 09-24-2019
0 1
0
1
fabrizioalleva
Hi all, I'm in enviroment so configured: 1 uf, 1 hf, 4 indexers, 1 search head, 1 master cluster. I've to index a l...
by fabrizioalleva Path Finder in Splunk Search 09-24-2019
0 1
0
1
jonydupre
Hi all, I'm pretty new to Splunk and I'm trying out different things to challange myself. I completed the fundementa...
by jonydupre Path Finder in Splunk Search 09-24-2019
0 4
0
4
avni26
Hello , I want to show trending compared to last score calculated. I have multiple single panels calculating one fiel...
by avni26 Explorer in Splunk Search 09-24-2019
0 6
0
6
astatrial
It is unclear for me why there isn't any easy and comfortable way to search all the objects that have been changed on...
by astatrial Contributor in Splunk Search 09-23-2019
0 2
0
2
thambisetty
Hi Splunkers, I have distributed environment. when I tried searching for eventtype which contains macro is not worki...
by SplunkTrust SplunkTrust in Splunk Search 09-23-2019
1 8
1
8
cooperjaram
Hello, I have 6 fields that I would like to count and then add all the count values together. For example I have S...
by cooperjaram Engager in Splunk Search 09-23-2019
0 7
0
7
santosh11
Dear Team, We want to make a search id persistent in splunk can we do that? by using the search id we want to run th...
by santosh11 New Member in Splunk Search 09-23-2019
0 0
0
0
sandeepmakkena
index=core a=BuilderService AND "decision.received" "Overrides" NOT "ItemOverrides=()" NOT commitCode=null | rename ...
by sandeepmakkena Contributor in Splunk Search 09-23-2019
0 3
0
3
peeeeeeeeeeter
I have the following events **2019-09-20 01:39:25 INFO Listener processing event with message metal:AUD:ADJ 2019-09...
by peeeeeeeeeeter Engager in Splunk Search 09-23-2019
0 5
0
5
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors