Splunk Search

Splunk Search
Community Activity
mursidehsani
Hello,I have this search for tabular format. index="webbff" "SUCCESS: REQUEST" | table _time verificationId code BROW...
by mursidehsani Explorer in Splunk Search 04-22-2024
0 2
0
2
NAGA4
I have a lookup like this NameStatusExamIDJohnPass123BobPass345JohnFail234BobPass235SmithFail231 My Events are having...
by NAGA4 Engager in Splunk Search 04-22-2024
0 5
0
5
NAGA4
Could someone help me in deriving solution for this case below?Background : We have an app and in which we set all ou...
by NAGA4 Engager in Splunk Search 04-22-2024
0 0
0
0
bigll
I need to identify hosts with errors, but only in block modeMY SPL--------- index=firewall event_type="error [search ...
by bigll Path Finder in Splunk Search 04-22-2024
0 15
0
15
Poojitha
Hi All,I have deployed new deployment server  (aws ec2 instance) and updated the existing route53 dns entry to point ...
by Poojitha Communicator in Splunk Search 04-22-2024
0 3
0
3
gauravkumar85
My row data will look like below _row={"id":"0","severity":"Information","message":"CPW Total= 844961,SEQ Total =2448...
by gauravkumar85 Path Finder in Splunk Search 04-22-2024
0 8
0
8
moinoddinyadgir
Hi Community,I have a question about regex and extractionI have _raw data in 2 rows/lines  (key and value) and I have...
by moinoddinyadgir Loves-to-Learn in Splunk Search 04-19-2024
0 5
0
5
shashankk
I need to create a dashboard panel merging two different search queries. I have below two queries:Kindly help on this...
by shashankk Communicator in Splunk Search 04-19-2024
0 8
0
8
ravir_jbp
My splunk query able to get the required results using below query.  After running the query, I get NULL values in on...
by ravir_jbp Explorer in Splunk Search 04-19-2024
0 1
0
1
Poojitha
Hi All,I want to extract service name from sourcetype="aws:metadata" and source field.Example : 434531263412:eu-centr...
by Poojitha Communicator in Splunk Search 04-19-2024
0 7
0
7
codewarrior
I have a log stream in this format:level=info request.elapsed=100 request.method=GET request.path=/orders/123456 requ...
by codewarrior Loves-to-Learn Everything in Splunk Search 04-18-2024
0 5
0
5
selvam_sekar
Hi,I have requirement as below, please could you review and suggest ?Need to pick up all client ids from application ...
by selvam_sekar Path Finder in Splunk Search 04-18-2024
0 3
0
3
KwonTaeHoon
HelloMy lookup table has fields of src_ip, dst_ip, and description.src_ip=192.168.1.1dst_ip=192.168.1.100description=...
by KwonTaeHoon Path Finder in Splunk Search 04-18-2024
0 4
0
4
Renunaren
Hi Team,Good day!We have extracted the set of job names from the event using the below rex query.index=app_events_dwh...
by Renunaren Loves-to-Learn Everything in Splunk Search 04-18-2024
0 4
0
4
anooshac
Hi All,I have a json event which has test cases and test case status and jenkins build number. There are many test ca...
by anooshac Communicator in Splunk Search 04-18-2024
0 1
0
1
PoojaChand02
As per the above screenshot I am unable to view the Data summary tab in our Splunk search environment  
by PoojaChand02 New Member in Splunk Search 04-17-2024
0 3
0
3
sholl
I have some JSON output that is in key value structure (protobuf3 formatted--this is OTLP data going into Splunk Ente...
by sholl Engager in Splunk Search 04-17-2024
1 2
1
2
ssh
In our log, I'd like to extract statusText and categorize it in table to see how many error response statusCode and s...
by ssh Engager in Splunk Search 04-17-2024
0 3
0
3
avi123
Hi All,I have an output from a lookup table in splunk where the team work timings field is coming as::TeamWorkTimings...
by avi123 Explorer in Splunk Search 04-17-2024
0 2
0
2
redrabbit
Hi everyone, I have a line chart which works perfectly but only for one single value: index=events ComputerName=* Acc...
by redrabbit Observer in Splunk Search 04-17-2024
0 1
0
1
Real_captain
Hi Can you please let me know how i can display the below 3 rows in a single row : Query : index=events_prod_cdp_pena...
by Real_captain Path Finder in Splunk Search 04-17-2024
0 3
0
3
suhanishah
Requirement - alert only needs to trigger outside window even if server is down in maintenance window | tstats count ...
by suhanishah Loves-to-Learn Everything in Splunk Search 04-17-2024
0 12
0
12
aotuga001
I have two logs below, log a is throughout the environment and would be shown for all users.  log b is limited to spe...
by aotuga001 Explorer in Splunk Search 04-16-2024
0 6
0
6
sowbhagya
message: Updated Components { "servicechannel": [ { "LastmodifiedBy": "XYZ", "ModifiedDate": "2024-04-15T17:20:09.000...
by sowbhagya Loves-to-Learn in Splunk Search 04-16-2024
0 2
0
2
gauravkumar85
{"id":"0","severity":"Information","message":[{"TARGET_SYSTEM":"SEQ","FUNCTION_NAME":"CPW_02170","TOTAL":"121257","PR...
by gauravkumar85 Path Finder in Splunk Search 04-16-2024
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...