Thread Info | |||||
---|---|---|---|---|---|
I have 1000 of text entities under the description field, and I want to write a regex for it and put to a different e...
by
mayank101
New Member
in
Splunk Search
08-07-2019
|
0
|
7
| |||
i have this rex code to extract the string from an event field:
| rex "(?\d{1,2})\s+hours?\s+ago" | eval process=...
by
owie6466
Explorer
in
Splunk Search
08-08-2019
|
0
|
4
| |||
All,
Quick one I am stuck on. I want an EVAL statement that takes _indexedtime and adds 7 days to it and creates ...
by
daniel333
Builder
in
Splunk Search
08-08-2019
|
0
|
1
| |||
I've 2 indexes "abc" and "def". There is a field "account_number" in index "abc" and a field "Emp_nummber" in index "...
by
amaurya1
Explorer
in
Splunk Search
08-08-2019
|
0
|
1
| |||
Hi, I am trying to add a new lookup table using the GUI and get the above error. I looked at the file with a hex edit...
by
yonahol
Explorer
in
Splunk Search
04-25-2012
|
1
|
17
| |||
I'm trying to write a simple query to replace all of the values in a field (let's call this field my_field) with a si...
by
brinley
Path Finder
in
Splunk Search
08-08-2019
|
0
|
8
| |||
Hi Team,
I
With reference to the screenshot, the part of the table which is highlighted in yellow is what I...
by
ashish9433
Communicator
in
Splunk Search
10-06-2016
|
0
|
6
| |||
how can i optimize this statement :
<condition field="title">
<link>
<![CDATA[/app/we...
by
w044f
New Member
in
Splunk Search
08-08-2019
|
0
|
1
| |||
Having the following search result, I need to calculate total for few rows and average for few rows and both results ...
by
Rajik31
New Member
in
Splunk Search
08-08-2019
|
0
|
2
| |||
Hi,
I'm struggling to get a regular expression for characters in a string.
https://status.aws.amazon.com/rss/#e...
by
pipipipi
Path Finder
in
Splunk Search
08-08-2019
|
0
|
8
| |||
A user tells us -
-- I need to convert time value from EST to UTC in Splunk search. Is there any function availab...
by
danielbb
Motivator
in
Splunk Search
08-06-2019
|
0
|
6
| |||
Hi, how to a must write search then set fields from general search to subsearch? Example: index=name host=thishost | ...
by
sbimizry
Engager
in
Splunk Search
08-08-2019
|
0
|
1
| |||
I have been using inputs to allow users to select the number of rows in a table.
This has been working well, with...
by
nzsci
New Member
in
Splunk Search
10-15-2018
|
0
|
1
| |||
The event I have is from a windows event log and AppLocker
See below:
LogName=Microsoft-Windows-AppLocker/EXE a...
by
davidjohnbecket
Path Finder
in
Splunk Search
08-07-2019
|
0
|
4
| |||
<notification-list xmlns="http://www......./restful/schema/response">
<added-instance preexisting="false">
<alarm id=...
by
surekhasplunk
Communicator
in
Splunk Search
07-31-2019
|
0
|
2
| |||
Hi this is my data structure, i'm trying to rename clk1 , clk2, clk3 as something like this | rename clk* as *
Bu...
by
Maniteja81
New Member
in
Splunk Search
08-07-2019
|
0
|
5
| |||
I am trying to setup an alert which will run every hour and considers the data from the start of current day(earliest...
by
njohnson7
Path Finder
in
Splunk Search
08-07-2019
|
0
|
2
| |||
I want to get the result and divide it into three sections as three-column such as last 15 min result, avg of 7 day a...
by
naved77
Loves-to-Learn Lots
in
Splunk Search
08-07-2019
|
0
|
2
| |||
Hi,
my search is the following
| inputlookup genesis.csv
| eval _time=now()
| eval field1=[ | inputlookup look...
by
salt87
Engager
in
Splunk Search
08-07-2019
|
0
|
2
| |||
I currently have a search, which takes 5 minutes to complete, I did not write the search query, and would like to see...
by
wrussell12
Explorer
in
Splunk Search
08-06-2019
|
0
|
4
| |||
I like and need mvexpand to work with some of my data.
Sometimes, our input events contain information about mult...
by
kulick
Path Finder
in
Splunk Search
11-12-2018
|
0
|
4
| |||
Ex:
index=newIndex host="1.12.123.4*" "Field"="abcd"| stats count as totalcount | where totalcount >= 10 ...
by
celerickalyan11
New Member
in
Splunk Search
08-07-2019
|
0
|
9
| |||
So I'm trying to get a distinct count of source mac addresses by device.
The srcmac gives me the mac address The ...
by
summitsplunk
Communicator
in
Splunk Search
08-07-2019
|
0
|
1
| |||
Hi there! I am updating my question: Below is the scenario where I wanted to see what are the servers got patched sin...
by
vinaykataaig
Explorer
in
Splunk Search
08-07-2019
|
0
|
7
| |||
Hello, I am very new to Splunk and I would like some help in doing this. I need to extract from this field: Event 1 h...
by
owie6466
Explorer
in
Splunk Search
08-07-2019
|
0
|
3
|