Splunk Search

Splunk Search
Community Activity
RyanDonnelly22
I have alert logs coming in from an AV tool and when a tech is working on an alert assigned it to themselves, it gene...
by RyanDonnelly22 Explorer in Splunk Search 08-09-2019
0 4
0
4
mcram52
How can I use the same search to divide the results of a specific time frame with the total daily sum to get a percen...
by mcram52 New Member in Splunk Search 08-09-2019
0 1
0
1
samble
I have the below command to extract the top 100 IP addresses. How can I modify the search to extract only the first ...
by samble Path Finder in Splunk Search 08-09-2019
0 5
0
5
mpham07
Hello all, I just came onto a new job and we're trying to figure out the daily indexing rate broken down by sourcety...
by mpham07 Path Finder in Splunk Search 08-09-2019
0 2
0
2
chadman
I have a search below that works fine, but I would like to add a wildcard to it. This search works | ldapsearch doma...
by chadman Path Finder in Splunk Search 08-09-2019
0 8
0
8
sbimizry
Hi, I must write and read data from lookup files. Example: cn,srcip,destip,owner "Canada","207.188.75.136","192.1.1...
by sbimizry Engager in Splunk Search 08-09-2019
0 3
0
3
dineshCool
Hi Guys, I have to extract one field from the below log and i tried this regex in https://rubular.com/ "(?<...
by dineshCool New Member in Splunk Search 08-09-2019
0 1
0
1
ALXWBR
I am running the below search to get a sum of starvation per 15 minute period. The problem I am having, is that durat...
by ALXWBR Path Finder in Splunk Search 08-09-2019
0 17
0
17
damucka
Hello, I have a dbxquery, that returns a table, where I am interested in one column, let us say c1. Then in my searc...
by damucka Builder in Splunk Search 08-09-2019
0 4
0
4
funlearning321
Hello, I am new to splunk and learning it . My question is when we install splunk what are things to be done if need...
by funlearning321 New Member in Splunk Search 08-08-2019
0 3
0
3
antb
This search is slow (our dns logs are large). index=winlogs sourcetype=dns | eval dottedquestion=replace(replace(que...
by antb Path Finder in Splunk Search 08-08-2019
0 4
0
4
yomixxxmx
Hi, I would like to ask for help in grouping a list per Index/object. I have tried using tables but the values are ...
by yomixxxmx New Member in Splunk Search 08-08-2019
0 6
0
6
bhupalbobbadi
I need to get the roles assigned to current logged in user and set the value to filed in search. Anybody has any ide...
by bhupalbobbadi Path Finder in Splunk Search 08-08-2019
0 4
0
4
mcg_connor
So I am currently trying to compare the average value of a field is using 7 days of events to what the value is curre...
by mcg_connor Path Finder in Splunk Search 08-08-2019
0 2
0
2
mayank101
I have 1000 of text entities under the description field, and I want to write a regex for it and put to a different e...
by mayank101 New Member in Splunk Search 08-08-2019
0 7
0
7
owie6466
i have this rex code to extract the string from an event field: | rex "(?\d{1,2})\s+hours?\s+ago" | eval process=c...
by owie6466 Explorer in Splunk Search 08-08-2019
0 4
0
4
daniel333
All, Quick one I am stuck on. I want an EVAL statement that takes _indexedtime and adds 7 days to it and creates a ...
by daniel333 Builder in Splunk Search 08-08-2019
0 1
0
1
amaurya1
I've 2 indexes "abc" and "def". There is a field "account_number" in index "abc" and a field "Emp_nummber" in index "...
by amaurya1 Explorer in Splunk Search 08-08-2019
0 1
0
1
yonahol
Hi, I am trying to add a new lookup table using the GUI and get the above error. I looked at the file with a hex edit...
by yonahol Explorer in Splunk Search 08-08-2019
1 17
1
17
brinley
I'm trying to write a simple query to replace all of the values in a field (let's call this field my_field) with a si...
by brinley Path Finder in Splunk Search 08-08-2019
0 8
0
8
ashish9433
Hi Team, I With reference to the screenshot, the part of the table which is highlighted in yellow is what I have an...
by ashish9433 Communicator in Splunk Search 08-08-2019
0 6
0
6
w044f
how can i optimize this statement : <condition field="title"> <link> <![CDATA[/app/webs...
by w044f New Member in Splunk Search 08-08-2019
0 1
0
1
Rajik31
Having the following search result, I need to calculate total for few rows and average for few rows and both results ...
by Rajik31 New Member in Splunk Search 08-08-2019
0 2
0
2
pipipipi
Hi, I'm struggling to get a regular expression for characters in a string. https://status.aws.amazon.com/rss/#elb-u...
by pipipipi Path Finder in Splunk Search 08-08-2019
0 8
0
8
danielbb
A user tells us - -- I need to convert time value from EST to UTC in Splunk search. Is there any function available...
by danielbb Motivator in Splunk Search 08-08-2019
0 6
0
6
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...