Splunk Search

Splunk Search
Community Activity
DEAD_BEEF
I have a custom set of logs where I wrote out the regex to parse it. I then created a field extraction via the searc...
by DEAD_BEEF Builder in Splunk Search 08-28-2019
0 3
0
3
theodorel
I have a problem regarding sorting in Splunk. I want to make automated reports and I want to sort in a calendar the a...
by theodorel Engager in Splunk Search 08-28-2019
0 2
0
2
lavster
i've created a table from a project run that displays the time a run started, ended and what time files have been cre...
by lavster Path Finder in Splunk Search 08-28-2019
0 2
0
2
reney44
i expect var1="d:\test\data.csv" but i got it shows mismatch or missing closing parenthesis var="d:\test\data.csv...
by reney44 Engager in Splunk Search 08-28-2019
0 2
0
2
subachu
I'm having trouble writing a search statement that sets the count to 0 when the service is normally. This is my data...
by subachu New Member in Splunk Search 08-27-2019
0 4
0
4
Amirahussein
Hello all, I need to know all differences between append, appendcols, and join when being used with pipe while searc...
by Amirahussein Path Finder in Splunk Search 08-27-2019
5 2
5
2
jackywsy
HI Experts, I am a fresh guy in SPLUNK Searching. Recently, my team leader needed us to create a DNS regex and make ...
by jackywsy Explorer in Splunk Search 08-27-2019
0 4
0
4
splunkranger
props.conf [win_dns] SEDCMD-win_dns = s/(\d+)/./g SEDCMD-domainname = s/(\(\d\))/./g EXTRACT-dns_name = (?i)] \w+\s+(...
by splunkranger Path Finder in Splunk Search 08-27-2019
0 7
0
7
DEAD_BEEF
I am using a CDN and have obtained my DNS logs. Some of the DNS logs have multiple values for the field response ID ...
by DEAD_BEEF Builder in Splunk Search 08-27-2019
0 1
0
1
lynmar
I have an index in Splunk enterprise named "my_index". When I search for data using index="my_index" for the last 24 ...
by lynmar Explorer in Splunk Search 08-27-2019
0 5
0
5
bobstoll
Hi all. I'm trying to write a search that will list users with more than 5 failed logins in the past 8 hours and the...
by bobstoll New Member in Splunk Search 08-27-2019
0 1
0
1
aferone
I would like to chart license usage throughout the day cumulatively, meaning, the results are added and charts every ...
by aferone Builder in Splunk Search 08-27-2019
0 8
0
8
JoshuaJohn
I am ingesting data at 6AM, 2PM, 7PM, 10PM (CST) Is there anyway I could have my query check the time and set earlies...
by JoshuaJohn Contributor in Splunk Search 08-27-2019
0 3
0
3
pepper_seattle
Hi, I've got a timechart which lays out the average response count for multiple groups over the last hour with a col...
by pepper_seattle Path Finder in Splunk Search 08-27-2019
3 7
3
7
BC88
Hey there, I have been banging my head over this issue. Basically, I am searching a sourcetype for, let's call it, "...
by BC88 New Member in Splunk Search 08-27-2019
0 2
0
2
JyotiP
I have the following response : Message=Login failed for user 'testuser_FSQ5'. Reason: Failed to open the explicitly ...
by JyotiP Path Finder in Splunk Search 08-27-2019
0 6
0
6
aohls
I am working to extract a field that at times is surrounded by quotes. This means I have either; operation or "operat...
by aohls Contributor in Splunk Search 08-27-2019
0 6
0
6
tlay
We have a very simple space delimited input, but the results occasionally instantiate per event: INFO_TYPE 2019-08-...
by tlay Explorer in Splunk Search 08-27-2019
0 0
0
0
cjohnk
I want to merge multiple fields from multiple lookup tables into a single field/column. I only know the name of the f...
by cjohnk Explorer in Splunk Search 08-27-2019
0 3
0
3
brewster88
Afternoon All, I have been tasked to get a list of information from Splunk UF's that are installed on 31 Domain Cont...
by brewster88 New Member in Splunk Search 08-27-2019
0 0
0
0
rajeshku348
hi everyone, I need count of "id" field against the sequence field parentRecord sequence ...
by rajeshku348 New Member in Splunk Search 08-27-2019
0 2
0
2
Graham_Hanningt
I have a dashboard in Splunk 7.3.0 with the following HTML viz definition: <html depends="$eventCount$,$duration$,$s...
by Graham_Hanningt Builder in Splunk Search 08-27-2019
0 0
0
0
ips_mandar
I want to group events with last occurance of notnull field value ex. I am grouping events which startswith:logon and...
by ips_mandar Builder in Splunk Search 08-26-2019
0 6
0
6
johnsasikumar
Hello, We are trying to import a third party library party library "go.js" to bring in custom visualization into sp...
by johnsasikumar Path Finder in Splunk Search 08-26-2019
0 0
0
0
toehser1
Something like, DEBUG traceid=123 user=john DEBUG traceid=123 result=200 DEBUG traceid=456 user=john DEBUG traceid=4...
by toehser1 New Member in Splunk Search 08-26-2019
0 1
0
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...