Splunk Search

Splunk Search
Community Activity
potluri_88
I have setup splunk enterprise 7.2.1. Custom roles are created under $SPLUNK_HOME/etc/system/local/ authorize.conf ...
by potluri_88 Explorer in Splunk Search 08-29-2019
0 3
0
3
pudanelilita
Hi, I need hep to create table, which shows multiple custom values / field count / % example, how it need to look:
by pudanelilita Explorer in Splunk Search 08-29-2019
0 2
0
2
mrtolu6
I'm getting the following error. How do I troubleshoot? Search process did not exit cleanly, exit_code=-1, descript...
by mrtolu6 Path Finder in Splunk Search 08-29-2019
0 6
0
6
johnsasikumar
Can we save results of a saved search/ search back into splunk. Something similar to a view in SQL database. Splunk q...
by johnsasikumar Path Finder in Splunk Search 08-28-2019
0 1
0
1
grashupfer
Hi Splunkers, I was wading through some of the Enterprise Security correlation searches and I noticed that the Remot...
by grashupfer Engager in Splunk Search 08-28-2019
0 0
0
0
alivesince92
Hello, After my query my result is: <ns2:OriginCountry>RUS</ns2:OriginCountry><ns2:MessageValues><ns2:MessageValu...
by alivesince92 Engager in Splunk Search 08-28-2019
0 11
0
11
vishal9023
Hello, I am new to Splunk and wanted to create a dashboard. I have 8 ORs coming through log but the problem is if an...
by vishal9023 New Member in Splunk Search 08-28-2019
0 7
0
7
seomaniv
I have reviewed https://answers.splunk.com/answers/63730/using-fieldformat-and-rename.html?utm_source=typeahead&utm_m...
by seomaniv Explorer in Splunk Search 08-28-2019
0 3
0
3
chandlercr
I am curious, does including an index help the search any when writing a search? This comes about as me and a frien...
by chandlercr New Member in Splunk Search 08-28-2019
0 2
0
2
hmbisht
I'm trying to extract a string (alphabets and underscore) from a given string which can contain any number of numeric...
by hmbisht Explorer in Splunk Search 08-28-2019
0 3
0
3
rajaguru2790
In the above log User(Saj) to Agent(Rohi) Response for all the conversations in the log should be captured: In the ab...
by rajaguru2790 Explorer in Splunk Search 08-28-2019
0 0
0
0
rajaguru2790
Rohi is the agent and Saj is the user. Using system message we can find the . Then we need to matc h the next line of...
by rajaguru2790 Explorer in Splunk Search 08-28-2019
0 14
0
14
srinivasmanikan
i have a field called application_name it is indexing to Splunk for every 5 min. so if i run top command for getting ...
by srinivasmanikan Engager in Splunk Search 08-28-2019
0 11
0
11
ajdyer2000
If the vulnerability column has a certain value then a new column called ‘Software_Affected’ has a corresponding valu...
by ajdyer2000 Path Finder in Splunk Search 08-28-2019
0 3
0
3
cip1
Hi, I need help in converting the time provided by a lookup. | inputlookup AD_User_LDAP_list | search cn=jon1 | fiel...
by cip1 Engager in Splunk Search 08-28-2019
0 3
0
3
sheloaha
I run a search to find all events relating to a particular transaction number i.e. index=myindex searchstring | tran...
by sheloaha Path Finder in Splunk Search 08-28-2019
0 6
0
6
elvistitus
For example, I have events that contain a Version field and also a timeTaken field. I want to display two tables of ...
by elvistitus New Member in Splunk Search 08-28-2019
0 2
0
2
rwills2
I am trying to create a pareto chart. I have already done that portion of the work. I have been asked to identify a n...
by rwills2 New Member in Splunk Search 08-28-2019
0 2
0
2
vikram1583
<37>Aug 27 10:52:59 DC1TPSMS02 CEF:0|TippingPoint|UnityOne|1.0.0.17|7611|Suspicious Country Blacklist|1|app=IP cnt=1 ...
by vikram1583 Explorer in Splunk Search 08-28-2019
0 21
0
21
surekhasplunk
Hi, I using a query : index=abc source="unknown.log" "192.0.44.13" | rex "Value 0: (?<device>.*)" | rex "Value 1: (...
by surekhasplunk Communicator in Splunk Search 08-28-2019
0 5
0
5
DEAD_BEEF
I have a custom set of logs where I wrote out the regex to parse it. I then created a field extraction via the searc...
by DEAD_BEEF Builder in Splunk Search 08-28-2019
0 3
0
3
theodorel
I have a problem regarding sorting in Splunk. I want to make automated reports and I want to sort in a calendar the a...
by theodorel Engager in Splunk Search 08-28-2019
0 2
0
2
lavster
i've created a table from a project run that displays the time a run started, ended and what time files have been cre...
by lavster Path Finder in Splunk Search 08-28-2019
0 2
0
2
reney44
i expect var1="d:\test\data.csv" but i got it shows mismatch or missing closing parenthesis var="d:\test\data.csv...
by reney44 Engager in Splunk Search 08-28-2019
0 2
0
2
subachu
I'm having trouble writing a search statement that sets the count to 0 when the service is normally. This is my data...
by subachu New Member in Splunk Search 08-27-2019
0 4
0
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...