Splunk Search

Splunk Search
Community Activity
sbhatnagar88
How can we apply below logic in splunk. We have the data in Splunk which is coming out as below. Host Patching L...
by sbhatnagar88 Path Finder in Splunk Search 08-05-2019
0 2
0
2
marisstella
Hii Everyone, I want to move all the knowledge objects and everything from one splunk instance to another instance......
by marisstella Explorer in Splunk Search 08-05-2019
0 5
0
5
miguelebf
Hi i have raw data like this: 192.0.100.3 - - [30/Jul/2019:00:06:05 -0500] "GET /test/ HTTP/1.1" 403 207 "-" "Mozill...
by miguelebf New Member in Splunk Search 08-04-2019
0 2
0
2
surekhasplunk
Hi, index="spectrum" * | eval foo=_cd | rename "ns1.alarm.ns1.attribute{}.$" as value "ns1.alarm.ns1.attribute{}.@i...
by surekhasplunk Communicator in Splunk Search 08-04-2019
0 4
0
4
chinkeeparco
Hello guys, I have the following syntax and data: However, there is a discrepancy with the total count per catego...
by chinkeeparco Explorer in Splunk Search 08-04-2019
0 10
0
10
jhuysing
We have a log of some metrics that look like this: 20:45:00 10.10.71.01 values : [12035313, 233658, 0, 0, 24249, 13...
by jhuysing Explorer in Splunk Search 08-04-2019
0 6
0
6
saikumarsplunkt
Can someone please help with extracting the bold highlighted field from below /07981368-d226-4cf6-8d88-9853c843bcb9...
by saikumarsplunkt New Member in Splunk Search 08-04-2019
0 1
0
1
harshal_chakran
I have a search in below format: index=xyz sourcetype=abc...|table code... |join code[search index=def ....] |where...
by harshal_chakran Builder in Splunk Search 08-04-2019
0 7
0
7
praphulla1
one of our dashboards were using below query | timechart count span=1d cont=false in 6.6.4 Splunk enterprise, we cou...
by praphulla1 Path Finder in Splunk Search 08-04-2019
0 8
0
8
balash1979
I have 3 panels. Each panel runs a query and displays the result in timechart. This works fine. Now , I would like t...
by balash1979 Path Finder in Splunk Search 08-04-2019
0 8
0
8
monipinni
Hi, Can any one help me adding two fields in one search I am seeing both fields in splunk selected fields but not s...
by monipinni Explorer in Splunk Search 08-04-2019
0 2
0
2
belamg
How can I refine this search string to grab those for the whole year and add other Splunk commands to break them into...
by belamg New Member in Splunk Search 08-04-2019
0 2
0
2
damucka
I have the following example: |makeresults | eval trigger=0|eval decision=case(trigger=1;[|savedsearch test|eval t=1...
by damucka Builder in Splunk Search 08-03-2019
0 3
0
3
brdr
We are starting see issues with users running adhoc searches. While doing adhoc searches we are seeing the error: Un...
by brdr Contributor in Splunk Search 08-03-2019
1 2
1
2
hok2010
Hello All, i need a help in creating report i have a mv field called "report", i want to search for values so they ...
by hok2010 New Member in Splunk Search 08-03-2019
0 3
0
3
gryfon
Hello, everyone. I have a series of logs that have, among other data, the source address from which they come (src_ip...
by gryfon New Member in Splunk Search 08-03-2019
0 5
0
5
gdorman619
Hello, I'm new to Splunk and I'm having trouble with the following line of code. I think what I'm trying to do is pr...
by gdorman619 Engager in Splunk Search 08-03-2019
0 3
0
3
newbie09
Currently, i have the below result of the search. It is returning the servername,errorcode and the timestamp. What my...
by newbie09 Explorer in Splunk Search 08-03-2019
0 3
0
3
elloyd4
I am trying to display a line chart that counts in a 15min spans throughout the course of a day, the number of ticke...
by elloyd4 Explorer in Splunk Search 08-02-2019
0 4
0
4
cquinney
I'm having an issue with matching results between two searches utilizing the append command. I realize I could use t...
by cquinney Communicator in Splunk Search 08-02-2019
1 3
1
3
zebu14
Hello, In Splunk previous versions (5.x) there was an editable file to be able to add more choices for the number of ...
by zebu14 Explorer in Splunk Search 08-02-2019
1 4
1
4
amaurya1
I've a below query where I'm filtering out the results of one index "def" from the result of other index "abc". I'm u...
by amaurya1 Explorer in Splunk Search 08-02-2019
0 3
0
3
jwalzerpitt
I have an index that contains a field called user. I have a lookup file that also contains the header user, in additi...
by jwalzerpitt Influencer in Splunk Search 08-02-2019
0 5
0
5
jwalzerpitt
I am doing some field extractions for Juniper JunOS logs and I created the following field extractions via props/tran...
by jwalzerpitt Influencer in Splunk Search 08-02-2019
0 9
0
9
dsitek
I am creating a search that finds ID's in two different logs, one when the ID is created and another when the ID is s...
by dsitek Explorer in Splunk Search 08-02-2019
0 0
0
0
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...