Splunk Search

Splunk Search
Community Activity
davidjohnbecket
The event I have is from a windows event log and AppLocker See below: LogName=Microsoft-Windows-AppLocker/EXE and D...
by davidjohnbecket Path Finder in Splunk Search 08-08-2019
0 4
0
4
surekhasplunk
<notification-list xmlns="http://www......./restful/schema/response"> <added-instance preexisting="false"> <alarm id=...
by surekhasplunk Communicator in Splunk Search 08-08-2019
0 2
0
2
Maniteja81
Hi this is my data structure, i'm trying to rename clk1 , clk2, clk3 as something like this | rename clk* as * But ...
by Maniteja81 New Member in Splunk Search 08-08-2019
0 5
0
5
njohnson7
I am trying to setup an alert which will run every hour and considers the data from the start of current day(earliest...
by njohnson7 Path Finder in Splunk Search 08-08-2019
0 2
0
2
naved77
I want to get the result and divide it into three sections as three-column such as last 15 min result, avg of 7 day a...
by naved77 Loves-to-Learn Lots in Splunk Search 08-07-2019
0 2
0
2
salt87
Hi, my search is the following | inputlookup genesis.csv | eval _time=now() | eval field1=[ | inputlookup lookup.c...
by salt87 Engager in Splunk Search 08-07-2019
0 2
0
2
wrussell12
I currently have a search, which takes 5 minutes to complete, I did not write the search query, and would like to see...
by wrussell12 Explorer in Splunk Search 08-07-2019
0 4
0
4
kulick
I like and need mvexpand to work with some of my data. Sometimes, our input events contain information about multi...
by kulick Path Finder in Splunk Search 08-07-2019
0 4
0
4
celerickalyan11
Ex: index=newIndex host="1.12.123.4*" "Field"="abcd"| stats count as totalcount | where totalcount >= 10 ...
by celerickalyan11 New Member in Splunk Search 08-07-2019
0 9
0
9
summitsplunk
So I'm trying to get a distinct count of source mac addresses by device. The srcmac gives me the mac address The de...
by summitsplunk Communicator in Splunk Search 08-07-2019
0 1
0
1
vinaykataaig
Hi there! I am updating my question: Below is the scenario where I wanted to see what are the servers got patched sin...
by vinaykataaig Explorer in Splunk Search 08-07-2019
0 7
0
7
owie6466
Hello, I am very new to Splunk and I would like some help in doing this. I need to extract from this field: Event...
by owie6466 Explorer in Splunk Search 08-07-2019
0 3
0
3
nimercu
I have a python script that attempts to get a token from Splunk search result and then build my REST post to TrueSigh...
by nimercu New Member in Splunk Search 08-07-2019
0 0
0
0
Joycetran
I want to create the dashboard for Splunk Health, one of the KPI is "search concurrent %" and " skipped search ratio ...
by Joycetran New Member in Splunk Search 08-07-2019
0 3
0
3
kholleran
Hello, I am monitoring Active Directory with Splunk and have two questions: 1.) How do I format time in a search? ...
by kholleran Communicator in Splunk Search 08-07-2019
0 3
0
3
sheamus69
We have several lookup files for users who have left, and we would like to transfer the ownership to a new production...
by sheamus69 Communicator in Splunk Search 08-07-2019
0 2
0
2
Nidd
I have logs in my application, that looks like: 8/7/19 1:30:35.977 AM [8/7/19 1:30:35:977 MST] 00000232 MyClass ...
by Nidd Path Finder in Splunk Search 08-07-2019
0 3
0
3
Sfry1981
I have the below query where i want all closed dates counted by the last 7 days but the below is not working | input...
by Sfry1981 Communicator in Splunk Search 08-07-2019
0 3
0
3
christianubeda
Hi team! I have a problem. I want to ignore some words from a field. This what I have: "Aplicación restringida det...
by christianubeda Path Finder in Splunk Search 08-07-2019
0 3
0
3
Nidd
I have an application log like: 8/7/19 1:30:35.977 AM [8/7/19 1:30:35:977 MST] 00000232 MyClass I Method Process...
by Nidd Path Finder in Splunk Search 08-07-2019
0 4
0
4
lavster
I have results of a field Severity High Medium Low How do i count the amount of Highs, Mediums and Lows in one field...
by lavster Path Finder in Splunk Search 08-07-2019
0 1
0
1
broccolino
Hi everyone, I would need a .sh script that allows me to read only the second line of a file and then send it to mac...
by broccolino New Member in Splunk Search 08-07-2019
0 0
0
0
chinkeeparco
Hello guys, I'm new in SPLUNK. Just wanted to ask for an advice :). Currently, I have 11,000 ticket data and I'm tr...
by chinkeeparco Explorer in Splunk Search 08-07-2019
0 5
0
5
vidhijain333
I have configured splunk daemonset for k8s cluster. Agent logs are flowing. However the application logs are not gett...
by vidhijain333 Loves-to-Learn in Splunk Search 08-06-2019
0 0
0
0
lbrhyne
Hello, Based on some suggested changes by @jawaharas I was able to successfully lookup the value of user from the Va...
by lbrhyne Path Finder in Splunk Search 08-06-2019
0 10
0
10
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...