Splunk Search

Splunk Search
Community Activity
anandhalagarasa
My search is that I have to log in the client machine, which needs to be ingested into Splunk Cloud- so I have deploy...
by anandhalagarasa Path Finder in Splunk Search 09-13-2019
0 7
0
7
koshyk
We need to override a tags & eventtypes from one of the official TA (eg eventtype=ssh_authentication). eventtypes....
by koshyk Super Champion in Splunk Search 09-13-2019
0 2
0
2
alex387
Hello, Is there a way to split out the unique values of a field into separate fields that are returned after a searc...
by alex387 New Member in Splunk Search 09-13-2019
0 4
0
4
toryan
I have a somewhat complicated search whose results I present in a dashboard, and looks a bit like this: [ search...
by toryan Engager in Splunk Search 09-13-2019
0 0
0
0
pkbhavani
I have created a field called PROCESS via Fields » Field transformations I could not see in the field appear in th...
by pkbhavani New Member in Splunk Search 09-13-2019
0 1
0
1
sai33
Hi All, I'm looking to include a If Else Check along with Len() Function along with Eval in my Search. My Raw synta...
by sai33 Explorer in Splunk Search 09-13-2019
0 2
0
2
twinspop
Since 7.3 the missing indexes message below goes to all my users causing many panicked questions about Splunk being d...
by twinspop Influencer in Splunk Search 09-13-2019
0 4
0
4
Glasses
Hi I need a little clarification as the related posts I have found are confusing. I inherited a lot of reports from...
by Glasses Builder in Splunk Search 09-13-2019
0 4
0
4
kfelts68
Just installed Splunk Enterprise free edition on a Windows 10 computer. Downloaded a Wordpress error log from a dec...
by kfelts68 Explorer in Splunk Search 09-13-2019
0 2
0
2
Glasses
Hi Just not having luck with my syntax. I have proofpoint logs and I am looking for the latest final_action value tha...
by Glasses Builder in Splunk Search 09-13-2019
1 14
1
14
avni26
I want to calculate last 3months count and take its average and need to compare with last month total count. For exam...
by avni26 Explorer in Splunk Search 09-13-2019
0 3
0
3
inventsekar
Hi, For a testing purposes, can i have few long running search SPL queries please. Using the search tutorials sample ...
by SplunkTrust SplunkTrust in Splunk Search 09-13-2019
0 1
0
1
kartm2020
Hi, We are monitoring the transaction count. I need to verify the results of last one hour, if there is any decrease ...
by kartm2020 Communicator in Splunk Search 09-13-2019
0 7
0
7
PBerry7538
Hi I am having an issue with the result of my dur2sec function not displaying. Here is the SPL. I am still new to s...
by PBerry7538 New Member in Splunk Search 09-13-2019
0 2
0
2
lsy9891
Hi, I have this query that I use as a base search query. host=NETWEBA* sourcetype=iis NOT("ErrorGuid") cs_uri_stem=...
by lsy9891 Engager in Splunk Search 09-13-2019
0 1
0
1
jip31
hi As you can see below, I am doing a stats with the field "process_name" In order to be more comprenhensive, I am d...
by jip31 Motivator in Splunk Search 09-13-2019
0 4
0
4
harshal_chakran
Hi, I have a multiple search queries for which I have created separate panels in Dashboard, each showing the output ...
by harshal_chakran Builder in Splunk Search 09-12-2019
0 9
0
9
jmulcaster_splu
We have an established Splunk Enterprise production environment that several departments use. Some people want to dev...
by jmulcaster_splu Splunk Employee Splunk Employee in Splunk Search 09-12-2019
0 1
0
1
efranke
Hello everyone, I am trying to assign a value to "myVar", which depends on a dropdown token on my dashboard. The val...
by efranke New Member in Splunk Search 09-12-2019
0 2
0
2
sai_shreyashi_p
Suppose I have logged data with certain fields like id, level, message etc. Ex: id:123 level:warn Message:xyz task i...
by sai_shreyashi_p New Member in Splunk Search 09-12-2019
0 4
0
4
aferone
I would like to add which index each of these hosts comes from in this search. index=_internal source=*/metrics.log ...
by aferone Builder in Splunk Search 09-12-2019
0 5
0
5
harinivgr
| inputlookup fnms_copy1.csv | eval MACaddress = replace(MACaddress,":", "") | where MACaddress!=" " | rename MACaddr...
by harinivgr Explorer in Splunk Search 09-12-2019
0 0
0
0
lquinn
I have a simple column chart with fields '-','High', 'Medium', 'Low', 'None'. I am using JS stack with the following ...
by lquinn Contributor in Splunk Search 09-12-2019
4 4
4
4
balcv
I have the following search index="pan" (dest_ip="192.168.*" AND NOT src_ip="192.168.*" AND NOT src_location="AU" AN...
by balcv Contributor in Splunk Search 09-12-2019
0 2
0
2
humantorch
I have events in same index and source-type as follows: 9/12/19 11:28:46.398 AM [WARNING/ForkPoolWorker-13] project=...
by humantorch New Member in Splunk Search 09-12-2019
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...