Splunk Search

Splunk Search
Community Activity
mpham07
Hello all, I just came onto a new job and we're trying to figure out the daily indexing rate broken down by sourcety...
by mpham07 Path Finder in Splunk Search 08-09-2019
0 2
0
2
chadman
I have a search below that works fine, but I would like to add a wildcard to it. This search works | ldapsearch doma...
by chadman Path Finder in Splunk Search 08-09-2019
0 8
0
8
sbimizry
Hi, I must write and read data from lookup files. Example: cn,srcip,destip,owner "Canada","207.188.75.136","192.1.1...
by sbimizry Engager in Splunk Search 08-09-2019
0 3
0
3
dineshCool
Hi Guys, I have to extract one field from the below log and i tried this regex in https://rubular.com/ "(?<...
by dineshCool New Member in Splunk Search 08-09-2019
0 1
0
1
ALXWBR
I am running the below search to get a sum of starvation per 15 minute period. The problem I am having, is that durat...
by ALXWBR Path Finder in Splunk Search 08-09-2019
0 17
0
17
damucka
Hello, I have a dbxquery, that returns a table, where I am interested in one column, let us say c1. Then in my searc...
by damucka Builder in Splunk Search 08-09-2019
0 4
0
4
funlearning321
Hello, I am new to splunk and learning it . My question is when we install splunk what are things to be done if need...
by funlearning321 New Member in Splunk Search 08-08-2019
0 3
0
3
antb
This search is slow (our dns logs are large). index=winlogs sourcetype=dns | eval dottedquestion=replace(replace(que...
by antb Path Finder in Splunk Search 08-08-2019
0 4
0
4
yomixxxmx
Hi, I would like to ask for help in grouping a list per Index/object. I have tried using tables but the values are ...
by yomixxxmx New Member in Splunk Search 08-08-2019
0 6
0
6
bhupalbobbadi
I need to get the roles assigned to current logged in user and set the value to filed in search. Anybody has any ide...
by bhupalbobbadi Path Finder in Splunk Search 08-08-2019
0 4
0
4
mcg_connor
So I am currently trying to compare the average value of a field is using 7 days of events to what the value is curre...
by mcg_connor Path Finder in Splunk Search 08-08-2019
0 2
0
2
mayank101
I have 1000 of text entities under the description field, and I want to write a regex for it and put to a different e...
by mayank101 New Member in Splunk Search 08-08-2019
0 7
0
7
owie6466
i have this rex code to extract the string from an event field: | rex "(?\d{1,2})\s+hours?\s+ago" | eval process=c...
by owie6466 Explorer in Splunk Search 08-08-2019
0 4
0
4
daniel333
All, Quick one I am stuck on. I want an EVAL statement that takes _indexedtime and adds 7 days to it and creates a ...
by daniel333 Builder in Splunk Search 08-08-2019
0 1
0
1
amaurya1
I've 2 indexes "abc" and "def". There is a field "account_number" in index "abc" and a field "Emp_nummber" in index "...
by amaurya1 Explorer in Splunk Search 08-08-2019
0 1
0
1
yonahol
Hi, I am trying to add a new lookup table using the GUI and get the above error. I looked at the file with a hex edit...
by yonahol Explorer in Splunk Search 08-08-2019
1 17
1
17
brinley
I'm trying to write a simple query to replace all of the values in a field (let's call this field my_field) with a si...
by brinley Path Finder in Splunk Search 08-08-2019
0 8
0
8
ashish9433
Hi Team, I With reference to the screenshot, the part of the table which is highlighted in yellow is what I have an...
by ashish9433 Communicator in Splunk Search 08-08-2019
0 6
0
6
w044f
how can i optimize this statement : <condition field="title"> <link> <![CDATA[/app/webs...
by w044f New Member in Splunk Search 08-08-2019
0 1
0
1
Rajik31
Having the following search result, I need to calculate total for few rows and average for few rows and both results ...
by Rajik31 New Member in Splunk Search 08-08-2019
0 2
0
2
pipipipi
Hi, I'm struggling to get a regular expression for characters in a string. https://status.aws.amazon.com/rss/#elb-u...
by pipipipi Path Finder in Splunk Search 08-08-2019
0 8
0
8
danielbb
A user tells us - -- I need to convert time value from EST to UTC in Splunk search. Is there any function available...
by danielbb Motivator in Splunk Search 08-08-2019
0 6
0
6
sbimizry
Hi, how to a must write search then set fields from general search to subsearch? Example: index=name host=thishost |...
by sbimizry Engager in Splunk Search 08-08-2019
0 1
0
1
nzsci
I have been using inputs to allow users to select the number of rows in a table. This has been working well, with n...
by nzsci New Member in Splunk Search 08-08-2019
0 1
0
1
davidjohnbecket
The event I have is from a windows event log and AppLocker See below: LogName=Microsoft-Windows-AppLocker/EXE and D...
by davidjohnbecket Path Finder in Splunk Search 08-08-2019
0 4
0
4
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...