Splunk Search

Splunk Search
Community Activity
whitecat001
Can i get a query that will find searches that users are running in splunk
by whitecat001 Explorer in Splunk Search 05-16-2024
0 6
0
6
whitecat001
I want a query that shows  the total volume of indexes used for splunk searches. Query on information that has to do ...
by whitecat001 Explorer in Splunk Search 05-16-2024
0 2
0
2
whitecat001
Pls what is the rest endpoint for searches that users are running 
by whitecat001 Explorer in Splunk Search 05-16-2024
0 3
0
3
ettaly
Hello,Can I know how to get the last Sunday of each month? For example, 31st is last Sunday of Jan 2021, 28th is last...
by ettaly Engager in Splunk Search 05-16-2024
0 4
0
4
ephraimjoseph
Currently, this is my SPL query and it just displays different resultsthis is my hostname_list.csvhosthostname_a*host...
by ephraimjoseph New Member in Splunk Search 05-16-2024
0 1
0
1
SteveIves1
I have 2 eventa from a mainframe running z/OS (not sure that affects things):1.{"MFSOURCETYPE":"SYSLOG","DATETIME":"2...
by SteveIves1 Engager in Splunk Search 05-15-2024
0 10
0
10
BrentHetherwick
I have some non-time-based data that I'd like to summarize using chart with a small number of bins.  For example, <so...
by BrentHetherwick Explorer in Splunk Search 05-15-2024
0 4
0
4
loganramirez
Hi.I have a lookup file with phone numbers broken down into their parts, so:cc,npa,nxx,list1,210,5551234,good1,512,77...
by loganramirez Path Finder in Splunk Search 05-15-2024
0 2
0
2
valleyman
Hello Community!I am trying to set up a search to monitor Powershell commands from Windows hosts; specifically, I am ...
by valleyman Loves-to-Learn Lots in Splunk Search 05-15-2024
0 6
0
6
tlmayes
SAML authenticated users are unable to access either REPORTS or ALERTS from the search app @ ./app/search/reports or ...
by tlmayes Contributor in Splunk Search 05-15-2024
0 0
0
0
tnegun
Hi all,I've a csv file with 3 columns ip, earliest, latest and over 400 rows.  I'm trying to return all evens associa...
by tnegun Engager in Splunk Search 05-15-2024
0 3
0
3
aatik5u
Hello,So I have to count the number of resulted fields, it doesn't go far than this. for my search I have index=examp...
by aatik5u Path Finder in Splunk Search 05-15-2024
0 2
0
2
kuul13
This was my original query to get the list of apis that failed for a client. I have more details of the client in the...
by kuul13 Explorer in Splunk Search 05-14-2024
0 14
0
14
ClubMed
This is just a fun optimization question. The benefit may be very little in fact!My Splunk searches are already optim...
by ClubMed Path Finder in Splunk Search 05-14-2024
0 5
0
5
cybersunny
All - I am new to Splunk and trying to figure out a way to return a matched command from a CSV table with inputlookup...
by cybersunny Loves-to-Learn Lots in Splunk Search 05-14-2024
0 10
0
10
andgarciaa
If I have an index with a retention of 90 days. Can I make a rough estimate about the cost of increasing the retentio...
by andgarciaa Explorer in Splunk Search 05-14-2024
0 6
0
6
dude49
Hey guys, I am working a report that needs to show any new employees coming into the company for the last 30 days. Ri...
by dude49 Explorer in Splunk Search 05-14-2024
0 2
0
2
IAskALotOfQs
Hi all, I'm trying to get all the saved searches in Splunk that are in all apps. Could someone explain to me what the...
by IAskALotOfQs Path Finder in Splunk Search 05-14-2024
0 3
0
3
OpeKush
Hi I was wondering if there was a way I could blacklist the following event based on the event code and the account n...
by OpeKush New Member in Splunk Search 05-14-2024
0 2
0
2
SplunkNinja
I am seeing the following alert on the Searching and Reporting App and also within the InfoSec App for Splunk.[idx-1,...
by SplunkNinja Path Finder in Splunk Search 05-14-2024
0 4
0
4
avi123
Hi All,I have a query which returns results for a particular month like how many tickets breached SLA. The month and ...
by avi123 Explorer in Splunk Search 05-13-2024
0 1
0
1
karthi2809
Hi All,Below query to get stats sum of field values of latest correlationId. need to show in pie chart. But i am gett...
by karthi2809 Builder in Splunk Search 05-13-2024
0 3
0
3
marioosh2
How to convert table like this (2 rows per topic): topic   mbean_property_name bytesA   BytesOutPerSec  60376267182A ...
by marioosh2 Engager in Splunk Search 05-13-2024
0 3
0
3
gschauhan81
Hello everyone Can anyone suggest me a search where I can get the notable Event time review between various phases of...
by gschauhan81 New Member in Splunk Search 05-13-2024
0 5
0
5
sanjai
Hello Splunk Community,I'm encountering challenges while converting multivalue fields to single value fields for effe...
by sanjai Communicator in Splunk Search 05-12-2024
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...