Splunk Search

Splunk Search
Community Activity
aking76
I have two searches, one getting the current connections and the other getting an average. I'm trying to grab the fie...
by aking76 Path Finder in Splunk Search 09-09-2019
0 6
0
6
mbreton
HI! I am using a CSV file to catch some alerts, and that part works fine, I catch all my alerts. index="main" [inp...
by mbreton Engager in Splunk Search 09-09-2019
0 0
0
0
khanyag1
Hi, I am trying to compare my latest app vs all the other app Version to evaluate adoption rate. I would like to disp...
by khanyag1 New Member in Splunk Search 09-09-2019
0 9
0
9
jnsd03
I am needing to pass a custom date to the sendemail subject line and I know it is possible using a standard Splunk se...
by jnsd03 Explorer in Splunk Search 09-09-2019
0 0
0
0
farooq3679
i ran a normal query, but it is auto cancelled after sometime ,so i am interested in why the query has failed.is ther...
by farooq3679 Engager in Splunk Search 09-09-2019
0 4
0
4
spisiakmi
Hi. Can you help me, please, to optimize the regular expression. The problem is, when I search in longer time, I rece...
by spisiakmi Contributor in Splunk Search 09-09-2019
0 8
0
8
angersleek
I am running following queries to get event counts average per second and per day over a weeks period but the results...
by angersleek Path Finder in Splunk Search 09-09-2019
0 3
0
3
jiaqya
I have a table like below A B C 1 2,3,4 Hello Need a query for wh...
by jiaqya Builder in Splunk Search 09-09-2019
0 1
0
1
pudanelilita
Hi, I struggling to create chart, which will be with multiple field values (max,avg and min pauses) + need to see mo...
by pudanelilita Explorer in Splunk Search 09-09-2019
0 2
0
2
sgrierson
Hello community. I'm struggling to find emails that have a word in the subject which also have the word in an attach...
by sgrierson New Member in Splunk Search 09-08-2019
0 4
0
4
angersleek
I have the following query which gives me per second average results for the events. Is there a way I can modify it ...
by angersleek Path Finder in Splunk Search 09-08-2019
0 2
0
2
scott_sackrider
Rather than use 3rd party websites, we'd like to use Splunk to geolocate an address that may not yet be indexed. Sim...
by scott_sackrider Explorer in Splunk Search 09-08-2019
1 2
1
2
aalhabbash1
Hi Splunker; I have the below search: index=winevents host=prdaddc02 OR host=PRDADDC01 OR host=DZITHQ-DC3 sourcetyp...
by aalhabbash1 Path Finder in Splunk Search 09-07-2019
0 2
0
2
collinrice
I am getting an inconsistent number of events in a transaction, relative to the value specified for maxevents=x: | ...
by collinrice Explorer in Splunk Search 09-06-2019
0 0
0
0
AbubakarShahid
Hello All, I am trying to find the difference between first time and last time in epoch time. and i want the differ...
by AbubakarShahid New Member in Splunk Search 09-06-2019
0 2
0
2
vrmandadi
Hello I have the below sample events Thu Sep 5 10:00:02 EDT 2019 XDB EXPIRED & LOCKED ...
by vrmandadi Builder in Splunk Search 09-06-2019
0 5
0
5
bapun18
Can Please anyone help me in building the query for my alert so that It takes the index name and its corresponding th...
by bapun18 Communicator in Splunk Search 09-06-2019
0 3
0
3
a123537
So I have a search query which returns registrations for a website called CXI. See below: sourcetype=applog Successf...
by a123537 New Member in Splunk Search 09-06-2019
0 5
0
5
tcalvillo
Hello everyone, I'm a newbie and I did build my own dashboard in Splunk. I was able to create different charts and I...
by tcalvillo Engager in Splunk Search 09-06-2019
0 5
0
5
pratyushd
... |rename General.SetupViews as Modes|eval mode=split(Modes," ")|eval name1=mvindex(mode,0) | eval name2=mvindex(mo...
by pratyushd New Member in Splunk Search 09-06-2019
0 4
0
4
kteng2024
Hi, Whenever log into the splunk , i am getting " app not found" error . can i please know how to keep "searching an...
by kteng2024 Path Finder in Splunk Search 09-06-2019
0 4
0
4
Arpmjdr
Hi Splunkers, I have the events getting ingested as below: timestamp patch_version hostname Now,I want to crea...
by Arpmjdr Explorer in Splunk Search 09-06-2019
0 5
0
5
lsy9891
Hi I have this query that counts the number of errors for two applications but I get the application names from diff...
by lsy9891 Engager in Splunk Search 09-06-2019
0 1
0
1
salmanbpc
for example: dport=86 pattern: 0 tcp && dst port 86 && dst 345 here dport is field and pattern is non field value. i...
by salmanbpc New Member in Splunk Search 09-06-2019
0 1
0
1
jip31
hi In a first lookup (host.csv), I have a field "host" In a second lookup (toto.csv), I have also a field "host" Is ...
by jip31 Motivator in Splunk Search 09-06-2019
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...