Splunk Search

Splunk Search
Community Activity
danielbb
We would like to set -- to be a comment in SPL. Can we do that and if so what's needed. We are on 7.3.
by danielbb Motivator in Splunk Search 08-16-2019
0 5
0
5
lbrhyne
Hello, We are trying to calculate employee retention by the department for the previous month. The challenge is tryi...
by lbrhyne Path Finder in Splunk Search 08-16-2019
0 2
0
2
ram1042
I need to develop a custom donut chart using Highcharts API. I came to know that Splunk internally uses Highcharts fo...
by ram1042 New Member in Splunk Search 08-16-2019
0 2
0
2
ketandessai1992
I am trying to integrate two splunk instance with a single Service Now module. One SPL instance is an ITSM module and...
by ketandessai1992 New Member in Splunk Search 08-16-2019
0 0
0
0
alanzchan
We have two IPs for a single indexer host. We are using this command to add a peer to the indexer cluster: /opt/spl...
by alanzchan Path Finder in Splunk Search 08-16-2019
0 1
0
1
KarnN
Hello fellow Splunkers. I made a query that shows the right results. I would like to show these results in percentage...
by KarnN Engager in Splunk Search 08-16-2019
0 5
0
5
damucka
Hello, I desperately search the way to overcome the issue with the map command overwriting the variable values. I ca...
by damucka Builder in Splunk Search 08-16-2019
0 5
0
5
daniel333
All, Just curious if "cool-fields" are billed against our license in the example below? curl -k https://hec.doma...
by daniel333 Builder in Splunk Search 08-15-2019
0 2
0
2
shierlawa
Hi all, I haven't been able to work this out and I was hoping someone can help answer. I am looking to create a tabl...
by shierlawa Engager in Splunk Search 08-15-2019
0 7
0
7
ygdrassilp
Hello we are having a problem on cisco syslog. We set the syslog level to debugging but we are not receiving anythi...
by ygdrassilp Explorer in Splunk Search 08-15-2019
0 0
0
0
pwild_splunk
I have two data sources Source A time action src_ip session user - "action" varies between (logon, logoff and relog...
by pwild_splunk Splunk Employee Splunk Employee in Splunk Search 08-15-2019
1 4
1
4
jerrysplunk88
the events data set looks like this: 2:05:34.067 PM 3DS: auth_validate_success Proceeding with payment authorization...
by jerrysplunk88 Explorer in Splunk Search 08-15-2019
0 1
0
1
owie6466
Hello, need help from the experts. My search results (_raw) is this: Event 1 minute ago, vmrit-c4ca0001.lm.lmig...
by owie6466 Explorer in Splunk Search 08-15-2019
0 12
0
12
oxthon
Hi, I have a fleet of scotter who are geolocated. My sourcetype is like this: 20190101150909 49.86587 2.32952 NGQ 201...
by oxthon New Member in Splunk Search 08-15-2019
0 1
0
1
balash1979
Here is my splunk log line {"line":"2019-08-15T17:48:28.935Z LCS {\"configName\":\"Apple-SQS\",\"customerName\":\"Ap...
by balash1979 Path Finder in Splunk Search 08-15-2019
0 2
0
2
reverse
Lets say .. My result would produce a.log a.log.1 a.log.2 a.log.3 b.log b.log.1 b.log.2 b.log.3 c.log c.log.1 c.log...
by reverse Contributor in Splunk Search 08-15-2019
0 6
0
6
jgmit
Hi I started the Fundamentals 1 training a couple a weeks ago. I had to stop until today. So I started up by reviewi...
by jgmit New Member in Splunk Search 08-15-2019
0 7
0
7
reverse
index="iedss_was_prd" OR index=iedss_mule_prd | rex field=source "(?P<logType>[^\\\]+)$" | eval raw_len=len(_raw) ...
by reverse Contributor in Splunk Search 08-15-2019
0 13
0
13
kapiljagdishwal
I have a dashboard prepared in Splunk Enterprise for Production where input data is coming from one of my application...
by kapiljagdishwal New Member in Splunk Search 08-15-2019
0 5
0
5
lzaexpert
I have a csv file like : User_id,emails 375352,foo@foo.com foo@foo.ca foobar@foobar.co.uk 872352,toto@foo.com note: ...
by lzaexpert Explorer in Splunk Search 08-15-2019
1 8
1
8
jerrysplunk88
the events data set looks like this: 2:05:34.067 PM 3DS: auth_validate_success Proceeding with payment authorizatio...
by jerrysplunk88 Explorer in Splunk Search 08-15-2019
0 2
0
2
Joycetran
I have the table: _time Ip_1 Ip_2 Ip_3 a 36 ...
by Joycetran New Member in Splunk Search 08-15-2019
0 2
0
2
adamblock2
I have created a lookup table which contains iocs, a subset of which are IPv4 addresses. I am trying to use events f...
by adamblock2 Path Finder in Splunk Search 08-15-2019
0 1
0
1
andy_macn
I have a search that takes logs from an SSL vpn and shows me failures what I would like to do is put a time frame in ...
by andy_macn New Member in Splunk Search 08-15-2019
0 1
0
1
vivek991985
Query is: index=xyz source ="File1.log" [ search index=xyz source="File2.log" search_input | rex ".]*Rpc id :(?[0-9][...
by vivek991985 New Member in Splunk Search 08-15-2019
0 3
0
3
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...