Splunk Search

Splunk Search
Community Activity
thambisetty
Hi Splunkers, I have distributed environment. when I tried searching for eventtype which contains macro is not worki...
by SplunkTrust SplunkTrust in Splunk Search 09-23-2019
1 8
1
8
cooperjaram
Hello, I have 6 fields that I would like to count and then add all the count values together. For example I have S...
by cooperjaram Engager in Splunk Search 09-23-2019
0 7
0
7
santosh11
Dear Team, We want to make a search id persistent in splunk can we do that? by using the search id we want to run th...
by santosh11 New Member in Splunk Search 09-23-2019
0 0
0
0
sandeepmakkena
index=core a=BuilderService AND "decision.received" "Overrides" NOT "ItemOverrides=()" NOT commitCode=null | rename ...
by sandeepmakkena Contributor in Splunk Search 09-23-2019
0 3
0
3
peeeeeeeeeeter
I have the following events **2019-09-20 01:39:25 INFO Listener processing event with message metal:AUD:ADJ 2019-09...
by peeeeeeeeeeter Engager in Splunk Search 09-23-2019
0 5
0
5
sandeepmakkena
SSP Request: {<!-- --> "disableAMLFlag" &#61; "false"; "orderAttributes" &#61; {<!-- --> "OrderAttributes" &#61; {<!-- --> "requestPostalIn...
by sandeepmakkena Contributor in Splunk Search 09-23-2019
0 0
0
0
mpasha
Good day, I have sysmon information collected in an index called sysmon. I also have created a summary index "HASh256...
by mpasha Path Finder in Splunk Search 09-23-2019
0 1
0
1
prsepulv
I'm using a dashboard to display the state of some services. For this purpose, I must takes single values from many s...
by prsepulv Explorer in Splunk Search 09-23-2019
0 5
0
5
danielbb
We have a parent search that looks like - index&#61;os_linux * | eval length &#61; len(process) | where length &#61; 7 | sea...
by danielbb Motivator in Splunk Search 09-23-2019
0 6
0
6
cpm003
Hi all, I´ve a custom command but it requieres python3 for launch properly. Errors on job inspector: 09-17-2019 13:...
by cpm003 Path Finder in Splunk Search 09-23-2019
0 4
0
4
mkamal18
Hello, I have a lookup filled with hostnames. I want to compare the hostnames with the host field in the index. If...
by mkamal18 New Member in Splunk Search 09-23-2019
0 3
0
3
melonman
Hi, Could anyone know how to start plotting from midnight when time range is something like earliest&#61;-1d&#64;d latest&#61;&#64;d...
by melonman Motivator in Splunk Search 09-23-2019
2 5
2
5
tyhopping1
There are three different events. Each event has the same fields. The fields I am focusing are "NumberOfRecords" and ...
by tyhopping1 Engager in Splunk Search 09-23-2019
0 2
0
2
jaffar20
I'm trying to either hide or show two panels depending on a search result from a different panel which will have 3 op...
by jaffar20 Explorer in Splunk Search 09-23-2019
0 1
0
1
punyanit
Hello All, I am working the below search - When I am running these two main which joined using join command are givi...
by punyanit Path Finder in Splunk Search 09-23-2019
0 8
0
8
bayman
I am trying to show the count of events where any external IP is attempting to connect to port 136-139, 445 from diff...
by bayman Path Finder in Splunk Search 09-23-2019
0 9
0
9
jaffar20
I have a timechart dependent on a dropdown at the top of the dashboard that selects the customer to show the results ...
by jaffar20 Explorer in Splunk Search 09-23-2019
0 2
0
2
swdowiarz
Hi, I would be grateful for any help. In my fields we are having two fields which are: data.user_id and data.confi...
by swdowiarz Path Finder in Splunk Search 09-23-2019
0 6
0
6
peeeeeeeeeeter
Suppose I have the following events. 2019-09-20 01:40:09 INFO Listener processing event with message key A1:B1:C1...
by peeeeeeeeeeter Engager in Splunk Search 09-23-2019
0 1
0
1
sandeepmakkena
(product&#61;X Phone , 512 ГБ, золотой,shipMethodCode&#61;E3,qty&#61;1,deliveryType&#61;STH,partNumber&#61;MRU/A,deliveryDate&#61;4 Окт - 11 ...
by sandeepmakkena Contributor in Splunk Search 09-22-2019
0 4
0
4
ccunov
Search A returns many events for each ID. Search B returns a single event for each ID. My end result is a table wit...
by ccunov New Member in Splunk Search 09-22-2019
0 6
0
6
jgan
I have a table below, how can I find the date I have the most income? Thanks. date Income 9/18/2019 20...
by jgan New Member in Splunk Search 09-22-2019
0 2
0
2
pmeyerson
I am attempting to use custom generating command protocol version 2, but my command seems to be detected as version 1...
by pmeyerson Path Finder in Splunk Search 09-21-2019
0 0
0
0
noob4now
So far, I've had success with the following command: eval Port&#61;if(len(Port)&gt;&#61;22,substr(Port,1,len(Port)-2),Port) ...
by noob4now New Member in Splunk Search 09-21-2019
0 1
0
1
brookshelpdesk
Hello, I'm running the following search that gives me accounts that get locked out and targets the specific domain c...
by brookshelpdesk Engager in Splunk Search 09-20-2019
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...