Splunk Search

Splunk Search
Community Activity
pwild_splunk
I have two data sources Source A time action src_ip session user - "action" varies between (logon, logoff and relog...
by pwild_splunk Splunk Employee Splunk Employee in Splunk Search 08-15-2019
1 4
1
4
jerrysplunk88
the events data set looks like this: 2:05:34.067 PM 3DS: auth_validate_success Proceeding with payment authorization...
by jerrysplunk88 Explorer in Splunk Search 08-15-2019
0 1
0
1
owie6466
Hello, need help from the experts. My search results (_raw) is this: Event 1 minute ago, vmrit-c4ca0001.lm.lmig...
by owie6466 Explorer in Splunk Search 08-15-2019
0 12
0
12
oxthon
Hi, I have a fleet of scotter who are geolocated. My sourcetype is like this: 20190101150909 49.86587 2.32952 NGQ 201...
by oxthon New Member in Splunk Search 08-15-2019
0 1
0
1
balash1979
Here is my splunk log line {"line":"2019-08-15T17:48:28.935Z LCS {\"configName\":\"Apple-SQS\",\"customerName\":\"Ap...
by balash1979 Path Finder in Splunk Search 08-15-2019
0 2
0
2
reverse
Lets say .. My result would produce a.log a.log.1 a.log.2 a.log.3 b.log b.log.1 b.log.2 b.log.3 c.log c.log.1 c.log...
by reverse Contributor in Splunk Search 08-15-2019
0 6
0
6
jgmit
Hi I started the Fundamentals 1 training a couple a weeks ago. I had to stop until today. So I started up by reviewi...
by jgmit New Member in Splunk Search 08-15-2019
0 7
0
7
reverse
index="iedss_was_prd" OR index=iedss_mule_prd | rex field=source "(?P<logType>[^\\\]+)$" | eval raw_len=len(_raw) ...
by reverse Contributor in Splunk Search 08-15-2019
0 13
0
13
kapiljagdishwal
I have a dashboard prepared in Splunk Enterprise for Production where input data is coming from one of my application...
by kapiljagdishwal New Member in Splunk Search 08-15-2019
0 5
0
5
lzaexpert
I have a csv file like : User_id,emails 375352,foo@foo.com foo@foo.ca foobar@foobar.co.uk 872352,toto@foo.com note: ...
by lzaexpert Explorer in Splunk Search 08-15-2019
1 8
1
8
jerrysplunk88
the events data set looks like this: 2:05:34.067 PM 3DS: auth_validate_success Proceeding with payment authorizatio...
by jerrysplunk88 Explorer in Splunk Search 08-15-2019
0 2
0
2
Joycetran
I have the table: _time Ip_1 Ip_2 Ip_3 a 36 ...
by Joycetran New Member in Splunk Search 08-15-2019
0 2
0
2
adamblock2
I have created a lookup table which contains iocs, a subset of which are IPv4 addresses. I am trying to use events f...
by adamblock2 Path Finder in Splunk Search 08-15-2019
0 1
0
1
andy_macn
I have a search that takes logs from an SSL vpn and shows me failures what I would like to do is put a time frame in ...
by andy_macn New Member in Splunk Search 08-15-2019
0 1
0
1
vivek991985
Query is: index=xyz source ="File1.log" [ search index=xyz source="File2.log" search_input | rex ".]*Rpc id :(?[0-9][...
by vivek991985 New Member in Splunk Search 08-15-2019
0 3
0
3
johnsasikumar
Hello, Am trying to extract UNIX CPU data core wise for multiple hosts, Am using the below query for extract, sourc...
by johnsasikumar Path Finder in Splunk Search 08-15-2019
0 6
0
6
jason_perkins
Hi, I need to apply field extractions across multiply files. They are the same type files but slighly labled differ...
by jason_perkins New Member in Splunk Search 08-15-2019
0 1
0
1
rajaguru2790
Need your help matching the next line of agent occurence timestamp. Example captured in link below link text Below ...
by rajaguru2790 Explorer in Splunk Search 08-15-2019
0 7
0
7
amunag439
For the following log, I would like to filter by a string. I would have to extract the string using regex. traceId=x...
by amunag439 Explorer in Splunk Search 08-14-2019
0 2
0
2
reverse
My search result is Date a.log a.log.1 a.log.2 b.log b.log.1 b.log.2 8/1 4 3 4 5 6 ...
by reverse Contributor in Splunk Search 08-14-2019
0 9
0
9
manapuna
I have 10 servers for my X applications. Sometime 1 or 2 servers will start to take 10% (or < 25%) where other 8 ser...
by manapuna New Member in Splunk Search 08-14-2019
0 4
0
4
jagdeepgupta813
HI , I want to extract serialNumber value from the logs. Below is the sample logger \"serialNumber\" : \"A1BZD2C5HD...
by jagdeepgupta813 Explorer in Splunk Search 08-14-2019
0 16
0
16
dhirajsir
I need to get a timechart for the data define by the search query sourcetype=bsgmc tranStatus="'ENTER'" | stats co...
by dhirajsir New Member in Splunk Search 08-14-2019
0 2
0
2
yemyslf
I have a lookup table which includes a list of IP addresses (field name = ip). I am trying to compose a search which ...
by yemyslf Path Finder in Splunk Search 08-14-2019
0 6
0
6
mbavlsik
If I look at Settings > Fields > Field extractions, it looks like there's a Status for "enabled/disabled." Is it poss...
by mbavlsik Engager in Splunk Search 08-14-2019
1 1
1
1
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors