Splunk Search

Splunk Search
Community Activity
antb
This search is slow (our dns logs are large). index=winlogs sourcetype=dns | eval dottedquestion=replace(replace(que...
by antb Path Finder in Splunk Search 08-08-2019
0 4
0
4
yomixxxmx
Hi, I would like to ask for help in grouping a list per Index/object. I have tried using tables but the values are ...
by yomixxxmx New Member in Splunk Search 08-08-2019
0 6
0
6
bhupalbobbadi
I need to get the roles assigned to current logged in user and set the value to filed in search. Anybody has any ide...
by bhupalbobbadi Path Finder in Splunk Search 08-08-2019
0 4
0
4
mcg_connor
So I am currently trying to compare the average value of a field is using 7 days of events to what the value is curre...
by mcg_connor Path Finder in Splunk Search 08-08-2019
0 2
0
2
mayank101
I have 1000 of text entities under the description field, and I want to write a regex for it and put to a different e...
by mayank101 New Member in Splunk Search 08-08-2019
0 7
0
7
owie6466
i have this rex code to extract the string from an event field: | rex "(?\d{1,2})\s+hours?\s+ago" | eval process=c...
by owie6466 Explorer in Splunk Search 08-08-2019
0 4
0
4
daniel333
All, Quick one I am stuck on. I want an EVAL statement that takes _indexedtime and adds 7 days to it and creates a ...
by daniel333 Builder in Splunk Search 08-08-2019
0 1
0
1
amaurya1
I've 2 indexes "abc" and "def". There is a field "account_number" in index "abc" and a field "Emp_nummber" in index "...
by amaurya1 Explorer in Splunk Search 08-08-2019
0 1
0
1
yonahol
Hi, I am trying to add a new lookup table using the GUI and get the above error. I looked at the file with a hex edit...
by yonahol Explorer in Splunk Search 08-08-2019
1 17
1
17
brinley
I'm trying to write a simple query to replace all of the values in a field (let's call this field my_field) with a si...
by brinley Path Finder in Splunk Search 08-08-2019
0 8
0
8
ashish9433
Hi Team, I With reference to the screenshot, the part of the table which is highlighted in yellow is what I have an...
by ashish9433 Communicator in Splunk Search 08-08-2019
0 6
0
6
w044f
how can i optimize this statement : <condition field="title"> <link> <![CDATA[/app/webs...
by w044f New Member in Splunk Search 08-08-2019
0 1
0
1
Rajik31
Having the following search result, I need to calculate total for few rows and average for few rows and both results ...
by Rajik31 New Member in Splunk Search 08-08-2019
0 2
0
2
pipipipi
Hi, I'm struggling to get a regular expression for characters in a string. https://status.aws.amazon.com/rss/#elb-u...
by pipipipi Path Finder in Splunk Search 08-08-2019
0 8
0
8
danielbb
A user tells us - -- I need to convert time value from EST to UTC in Splunk search. Is there any function available...
by danielbb Motivator in Splunk Search 08-08-2019
0 6
0
6
sbimizry
Hi, how to a must write search then set fields from general search to subsearch? Example: index=name host=thishost |...
by sbimizry Engager in Splunk Search 08-08-2019
0 1
0
1
nzsci
I have been using inputs to allow users to select the number of rows in a table. This has been working well, with n...
by nzsci New Member in Splunk Search 08-08-2019
0 1
0
1
davidjohnbecket
The event I have is from a windows event log and AppLocker See below: LogName=Microsoft-Windows-AppLocker/EXE and D...
by davidjohnbecket Path Finder in Splunk Search 08-08-2019
0 4
0
4
surekhasplunk
<notification-list xmlns="http://www......./restful/schema/response"> <added-instance preexisting="false"> <alarm id=...
by surekhasplunk Communicator in Splunk Search 08-08-2019
0 2
0
2
Maniteja81
Hi this is my data structure, i'm trying to rename clk1 , clk2, clk3 as something like this | rename clk* as * But ...
by Maniteja81 New Member in Splunk Search 08-08-2019
0 5
0
5
njohnson7
I am trying to setup an alert which will run every hour and considers the data from the start of current day(earliest...
by njohnson7 Path Finder in Splunk Search 08-08-2019
0 2
0
2
naved77
I want to get the result and divide it into three sections as three-column such as last 15 min result, avg of 7 day a...
by naved77 Loves-to-Learn Lots in Splunk Search 08-07-2019
0 2
0
2
salt87
Hi, my search is the following | inputlookup genesis.csv | eval _time=now() | eval field1=[ | inputlookup lookup.c...
by salt87 Engager in Splunk Search 08-07-2019
0 2
0
2
wrussell12
I currently have a search, which takes 5 minutes to complete, I did not write the search query, and would like to see...
by wrussell12 Explorer in Splunk Search 08-07-2019
0 4
0
4
kulick
I like and need mvexpand to work with some of my data. Sometimes, our input events contain information about multi...
by kulick Path Finder in Splunk Search 08-07-2019
0 4
0
4
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors