Splunk Search

Splunk Search
Community Activity
loganramirez
Hi.I have a lookup file with phone numbers broken down into their parts, so:cc,npa,nxx,list1,210,5551234,good1,512,77...
by loganramirez Path Finder in Splunk Search 05-15-2024
0 2
0
2
valleyman
Hello Community!I am trying to set up a search to monitor Powershell commands from Windows hosts; specifically, I am ...
by valleyman Loves-to-Learn Lots in Splunk Search 05-15-2024
0 6
0
6
tlmayes
SAML authenticated users are unable to access either REPORTS or ALERTS from the search app @ ./app/search/reports or ...
by tlmayes Contributor in Splunk Search 05-15-2024
0 0
0
0
tnegun
Hi all,I've a csv file with 3 columns ip, earliest, latest and over 400 rows.  I'm trying to return all evens associa...
by tnegun Engager in Splunk Search 05-15-2024
0 3
0
3
aatik5u
Hello,So I have to count the number of resulted fields, it doesn't go far than this. for my search I have index=examp...
by aatik5u Path Finder in Splunk Search 05-15-2024
0 2
0
2
kuul13
This was my original query to get the list of apis that failed for a client. I have more details of the client in the...
by kuul13 Explorer in Splunk Search 05-14-2024
0 14
0
14
ClubMed
This is just a fun optimization question. The benefit may be very little in fact!My Splunk searches are already optim...
by ClubMed Path Finder in Splunk Search 05-14-2024
0 5
0
5
cybersunny
All - I am new to Splunk and trying to figure out a way to return a matched command from a CSV table with inputlookup...
by cybersunny Loves-to-Learn Lots in Splunk Search 05-14-2024
0 10
0
10
andgarciaa
If I have an index with a retention of 90 days. Can I make a rough estimate about the cost of increasing the retentio...
by andgarciaa Explorer in Splunk Search 05-14-2024
0 6
0
6
dude49
Hey guys, I am working a report that needs to show any new employees coming into the company for the last 30 days. Ri...
by dude49 Explorer in Splunk Search 05-14-2024
0 2
0
2
IAskALotOfQs
Hi all, I'm trying to get all the saved searches in Splunk that are in all apps. Could someone explain to me what the...
by IAskALotOfQs Path Finder in Splunk Search 05-14-2024
0 3
0
3
OpeKush
Hi I was wondering if there was a way I could blacklist the following event based on the event code and the account n...
by OpeKush New Member in Splunk Search 05-14-2024
0 2
0
2
SplunkNinja
I am seeing the following alert on the Searching and Reporting App and also within the InfoSec App for Splunk.[idx-1,...
by SplunkNinja Path Finder in Splunk Search 05-14-2024
0 4
0
4
avi123
Hi All,I have a query which returns results for a particular month like how many tickets breached SLA. The month and ...
by avi123 Explorer in Splunk Search 05-13-2024
0 1
0
1
karthi2809
Hi All,Below query to get stats sum of field values of latest correlationId. need to show in pie chart. But i am gett...
by karthi2809 Builder in Splunk Search 05-13-2024
0 3
0
3
marioosh2
How to convert table like this (2 rows per topic): topic   mbean_property_name bytesA   BytesOutPerSec  60376267182A ...
by marioosh2 Engager in Splunk Search 05-13-2024
0 3
0
3
gschauhan81
Hello everyone Can anyone suggest me a search where I can get the notable Event time review between various phases of...
by gschauhan81 New Member in Splunk Search 05-13-2024
0 5
0
5
sanjai
Hello Splunk Community,I'm encountering challenges while converting multivalue fields to single value fields for effe...
by sanjai Communicator in Splunk Search 05-12-2024
0 3
0
3
R_Ramanan
I am using query as below  index="test" sourcetype="reports" | bin _time span=1m | stats values(a) as a values(b) as ...
by R_Ramanan Loves-to-Learn in Splunk Search 05-12-2024
0 5
0
5
Jasmine
If attr.error exist then Error will be attr.error. If attr.error not exist and attr.error.errmsg exist then Error wou...
by Jasmine Path Finder in Splunk Search 05-12-2024
0 2
0
2
Jasmine
In the below query if c= I,  the reg expression is | rex field=attr.namespace "(?<DB>[^\.]*)"if c= other than "I" the...
by Jasmine Path Finder in Splunk Search 05-11-2024
0 1
0
1
phularah
So, I have data like this after I ran a query. For each aggregator, if the aggregator_status is Error and before15 mi...
by phularah Communicator in Splunk Search 05-11-2024
0 3
0
3
splunk6
Hi All,I have a soap request and response being ingested in the splunk under an index. There are multiple API calls a...
by splunk6 Path Finder in Splunk Search 05-11-2024
0 1
0
1
jayita1989
Hello,Can someone please help me in extracting nested json fields without regex?I have tried below:1. Updating KV_mod...
by jayita1989 Loves-to-Learn Lots in Splunk Search 05-10-2024
0 7
0
7
karthi2809
Hi All,I have a field in my data called 'message' ,which contain information about status of the field.I'd like categ...
by karthi2809 Builder in Splunk Search 05-10-2024
0 3
0
3
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors