Splunk Search

Splunk Search
Community Activity
akarivaratharaj
host=* sourcetype=* |replace *.zip WITH * IN Object | replace *.csv WITH * IN Object | replace *.null WITH * IN Obj...
by akarivaratharaj Communicator in Splunk Search 09-26-2019
0 1
0
1
bowesmana
I am using eventgen to generate transaction type data, where I create an event in Splunk and then at some point in th...
by SplunkTrust SplunkTrust in Splunk Search 09-26-2019
0 2
0
2
purnavenkatesh
Hi, I need to route the index data to null-queue based on the strings from the events. For example, all the events t...
by purnavenkatesh Explorer in Splunk Search 09-25-2019
0 12
0
12
harishbabu
Hi All, I am new to Splunk. please help me here on this requirement. i would like to check if there is any possibil...
by harishbabu New Member in Splunk Search 09-25-2019
0 1
0
1
phil__tanner
Hi all - bit of a weird one! I've run out of ideas. Help please! I'm trying to index some CSV files. However, the fi...
by phil__tanner Path Finder in Splunk Search 09-25-2019
0 3
0
3
aatern
Hi, I have a couple searches where the main search can be limited a fair amount, lets say the last 2 weeks, but I hav...
by aatern Engager in Splunk Search 09-25-2019
0 3
0
3
franjo
I need to search for *exception in our logs (e.g. "NullPointerException") but want to exclude certain matches (e.g. "...
by franjo Explorer in Splunk Search 09-25-2019
0 11
0
11
kmedara
I have a time chart that displays the average duration of calls for each day in the time range, the time range is set...
by kmedara Engager in Splunk Search 09-25-2019
1 3
1
3
c_o_serban
I have a string field that I split into a variable-length multi-value, removed the last value and need to combine it ...
by c_o_serban Engager in Splunk Search 09-25-2019
0 1
0
1
vikram1583
[Response:"AccessToken":"XXXXX", "AuthenticationLevel":"2","AuthProviderInfo":" [Response:"AccessToken":"XXXXX", "Au...
by vikram1583 Explorer in Splunk Search 09-25-2019
0 2
0
2
skakani114
I have logs that have a keyword "*CLP" repeated multiple times in each event. I am trying the get the total counts of...
by skakani114 New Member in Splunk Search 09-25-2019
0 2
0
2
massumtaqi
I want to get notified every time when an account expiry date is removed from Active directory and set to Never "Acc...
by massumtaqi New Member in Splunk Search 09-25-2019
0 5
0
5
spammenot66
Does anyone know of a way to search all search histories containing |multisearch? Based on the previous answer, this ...
by spammenot66 Contributor in Splunk Search 09-25-2019
0 1
0
1
lavster
hello, we are trying to configure a lastchanceindex to capture events being sent to a non-existing index, however it ...
by lavster Path Finder in Splunk Search 09-25-2019
0 1
0
1
jgillman
For this my ultimate goal is to set up a automatic lookup for a source type. Set this to Global also I set up the th...
by jgillman Explorer in Splunk Search 09-25-2019
0 0
0
0
mukuru74
Here is my log sent from an UF to and Indexer: 2019-09-16 09:37:00 Fetching ISS data 'issfiles/sampleFile.tmp' -> 'i...
by mukuru74 New Member in Splunk Search 09-25-2019
0 7
0
7
jgillman
I have created a csv lookup file that looks like this computerip Sitename 10.89.64.0/24 Test Si...
by jgillman Explorer in Splunk Search 09-25-2019
0 1
0
1
Madhavi_alugant
Hi, I am working on onboarding CUR data of AWS to Splunk in order to design dashboards with specific to few items l...
by Madhavi_alugant New Member in Splunk Search 09-25-2019
0 0
0
0
shugup2923
index=storage source="/******.csv" | stats sum(00_) //It represents sum of various fields | eval sum1=0 | forea...
by shugup2923 Path Finder in Splunk Search 09-25-2019
0 2
0
2
PC00128849
Lets say i have a column called as birthdate in my events and i do not want to see the events or birth records which ...
by PC00128849 New Member in Splunk Search 09-25-2019
0 3
0
3
criedman
Hello, i have only two values logout_time and online_time and i would like to get the login_time. How could i subtra...
by criedman Explorer in Splunk Search 09-25-2019
0 2
0
2
arisat
Hi, I have a rather large multiline event which I am trying to extract data from. The problem is that the format is ...
by arisat Engager in Splunk Search 09-25-2019
0 3
0
3
santosh11
Dear Team, We have configured the email notification in splunk but we are getting the below warning message. How can...
by santosh11 New Member in Splunk Search 09-24-2019
0 2
0
2
amerineni
Hi, I want to run a search for a selected time range, and also want to do a sub search for the same duration in the p...
by amerineni Loves-to-Learn in Splunk Search 09-24-2019
0 3
0
3
andydong
Somehow i have not got logs from universal forwarder servers since Sep 11, How to find out the reason ?
by andydong New Member in Splunk Search 09-24-2019
0 2
0
2
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...