Splunk Search

Splunk Search
Community Activity
Graham_Hanningt
With apologies, I'll admit to being lazy asking this question. @niketnilay has already provided an answer to my simil...
by Graham_Hanningt Builder in Splunk Search 08-22-2019
1 0
1
0
torowa
Hi Splunkers. We have an application which roles over logs and renames them to have a .bak extension. I've been hav...
by torowa Path Finder in Splunk Search 08-22-2019
0 0
0
0
viandyg
I have 4 columns of data: Country City Date Price I want to make a table where the Price column is is sum...
by viandyg Engager in Splunk Search 08-22-2019
0 1
0
1
Gowtham0809
I have some CSV files indexed via splunk. I have noticed that files are getting indexed daily even though there is no...
by Gowtham0809 New Member in Splunk Search 08-22-2019
0 6
0
6
mariog2000
Sorry in advance this is such a long post so I'll try describing this in a sentence or two in case this is so easy yo...
by mariog2000 Explorer in Splunk Search 08-22-2019
1 13
1
13
zayra
Hi Is it possible to work with the versions of the csv files every time it is modified in the Lookup Editor app with...
by zayra Loves-to-Learn in Splunk Search 08-22-2019
0 0
0
0
ESPrioleau
For instance: the results have 01.2.3 and ABC5. How do I only pull out 01.2.3?
by ESPrioleau New Member in Splunk Search 08-22-2019
0 3
0
3
jenniferhao
I need to make a chat similar to the following picture base on the data below. The column chart should show 2 column...
by jenniferhao Explorer in Splunk Search 08-22-2019
0 4
0
4
cindywee
Hi. How do I get from the first table to look like the second table? I have tried chart, transpose, different combin...
by cindywee New Member in Splunk Search 08-22-2019
0 2
0
2
danielbb
We have the following working query - (index=wineventlog sourcetype=WinEventLog NOT ("xxxx" OR "yyyy") src_ip IN (...
by danielbb Motivator in Splunk Search 08-22-2019
1 3
1
3
rajatsinghbagga
Hello Everyone, I have got the list of 80+ applications this I want to include in my SPL. Is there a way I can use C...
by rajatsinghbagga Explorer in Splunk Search 08-22-2019
0 1
0
1
spoolunk
I have a query index=errors earliest=@d latest=now |stats count(ErrorCode) as ErrorCountForToday by host I would ...
by spoolunk Engager in Splunk Search 08-22-2019
0 9
0
9
sayanidasgupta
Single Table containing - stats count by DID TN - for today avg count for last 7 day by DID and TN deviation of toda...
by sayanidasgupta Explorer in Splunk Search 08-22-2019
0 0
0
0
Nidd
I have Splunk logs like: class,method,user,transactionType,,428856645467856301,1073258159,50213,5,2019-08-21 23:17:5...
by Nidd Path Finder in Splunk Search 08-22-2019
0 3
0
3
jwindley_splunk
I'm very new to Splunk and need to get some details about a transaction which spans multiple events. Am trying to get...
by jwindley_splunk Splunk Employee Splunk Employee in Splunk Search 08-21-2019
0 7
0
7
vb1612
Hi , I am having data like Col1 Col2(created from values()) row 1 X ...
by vb1612 New Member in Splunk Search 08-21-2019
0 4
0
4
rashi83
Hi, I have diff log formats in a single sourcetype. Thus can't define field extraction - is there way to use REX in ...
by rashi83 Path Finder in Splunk Search 08-21-2019
0 1
0
1
guimilare
Hi Splunkers. I've been trying for a while to customize a bar chart I have. Here are the data I have: range ...
by guimilare Communicator in Splunk Search 08-21-2019
2 5
2
5
donemery
I am looking to enhance a search with a lookup (if it returns an IP) to replace the value returned in the TID field i...
by donemery Explorer in Splunk Search 08-21-2019
0 2
0
2
venkat0896
Hi, I am working on a dashboard. i am creating a table to monitor the count, average response time and maximum respo...
by venkat0896 Path Finder in Splunk Search 08-21-2019
0 8
0
8
danielbb
A developer here wrote the following - |eval admin_activity=if((like(cmd_data, "%audit%") AND like(cmd_data, "%star...
by danielbb Motivator in Splunk Search 08-21-2019
0 2
0
2
AKG1_old1
Hi, How can we Ignore timechart column if all rows having 0 values. basically I am using trellis to display and w...
by AKG1_old1 Builder in Splunk Search 08-21-2019
0 4
0
4
dsmith1988
I am trying to run a search from amazon. index=amazon-aws sourcetype="aws:description" source="*:ec2_instances" W...
by dsmith1988 Engager in Splunk Search 08-21-2019
0 2
0
2
deeptha1992
How I can Change this sql query to splunk query, I tried in different way but It is not giving proper result please h...
by deeptha1992 New Member in Splunk Search 08-21-2019
0 4
0
4
Ricapar
I have some logs where there are events that are like this: Apr 5 21:16:33 myhost001.company.com key=value key2=va...
by Ricapar Communicator in Splunk Search 08-21-2019
0 6
0
6
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors