Splunk Search

Splunk Search
Community Activity
cpm003
Hi all, I am trying to make a correlation between an inventory of assets and vulnerability indexed data. I am curren...
by cpm003 Path Finder in Splunk Search 07-31-2019
0 2
0
2
RDurica
I'd like to assess how many events I'm getting per hour for each value of the signature field. However, stats calcula...
by RDurica Engager in Splunk Search 07-31-2019
0 2
0
2
patrycja
Hello, I created a simple dashboard with some panels taking data from the index. It was taking a long time to load,...
by patrycja Explorer in Splunk Search 07-31-2019
0 5
0
5
VI371887
open in search fails due to long search size, is there a way to allow open in search option to carry-forward longer q...
by VI371887 Path Finder in Splunk Search 07-31-2019
0 2
0
2
patrycja
Hello, I don't know if it possible, but I want to make a conditional append in my search query. I'm using saved sea...
by patrycja Explorer in Splunk Search 07-31-2019
1 5
1
5
splunker1981
Hello all - Trying to figure out how to return the table below when using two index/sourcetypes. I'd like to do so...
by splunker1981 Path Finder in Splunk Search 07-31-2019
0 3
0
3
jwalzerpitt
At some point in the past month, the existing extract in transforms.conf quit working and the DNS logs (ingesting fro...
by jwalzerpitt Influencer in Splunk Search 07-31-2019
0 6
0
6
vrmandadi
I am trying to join two indexes through a common field but has a different name in the indexes and want to run in dif...
by vrmandadi Builder in Splunk Search 07-31-2019
0 6
0
6
payton_tayvion
Im having an issue where my contact field and l2 field is showing duplicates of the same name and when i use the dedu...
by payton_tayvion Path Finder in Splunk Search 07-31-2019
0 1
0
1
anilkashyap
I want to extract the PID number from the log and store in variable failedPID. i have many of this kind of message w...
by anilkashyap New Member in Splunk Search 07-31-2019
0 3
0
3
Mike6960
I am trying to use eval to calculate the time between events. Those events have a unique ID. This is the sarch that I...
by Mike6960 Path Finder in Splunk Search 07-31-2019
0 6
0
6
yuraminsk
I have a complicated request that starts like host=*hb* Exception OR Exception: NOT whitehat NOT org.springframework...
by yuraminsk Engager in Splunk Search 07-31-2019
0 2
0
2
wfskmoney
Which one would be faster or better in general: | dedup fieldA fieldB --> I would assume that Splunk does a concaten...
by wfskmoney Path Finder in Splunk Search 07-31-2019
0 1
0
1
Sujithkumarkb
I want to extract the below fields from my raw data and place it into a field . How can i do it with transforms and p...
by Sujithkumarkb Observer in Splunk Search 07-31-2019
0 5
0
5
dpelletier
We have an existing Drill down that currently works. We are adding 2 new lines to the drilldown that filter out compu...
by dpelletier Observer in Splunk Search 07-30-2019
0 1
0
1
jordanking1992
We have data indexed in Splunk that has a field called pod. In the screenshots, you can see that pod has a list of va...
by jordanking1992 Path Finder in Splunk Search 07-30-2019
0 3
0
3
splunker1981
Hello fellow Splunkers Not sure the best way to approach the following problem. I use replace to update values wit...
by splunker1981 Path Finder in Splunk Search 07-30-2019
0 2
0
2
splkcurtis
I have a search for a dashboard and I'd like to filter it based on an IN search with results from parent search. Is ...
by splkcurtis New Member in Splunk Search 07-30-2019
0 1
0
1
esalmon_splunk
I'm using the transaction command to correlate some searches, no I don't want to use stats, and its all split how I w...
by esalmon_splunk Splunk Employee Splunk Employee in Splunk Search 07-30-2019
0 3
0
3
Vfinney
I am trying to extract the file types, file names, and URLs from proxy logs for monitoring purposes. Here is what I'...
by Vfinney Observer in Splunk Search 07-30-2019
0 1
0
1
russell120
I have a multivalue field with at least 3 different combinations of values. See Example.CSV below (the 2 "apple orang...
by russell120 Communicator in Splunk Search 07-30-2019
0 6
0
6
kelseycasco
I would like to make a Pareto chart that shows the sum of how many scrapped pieces were produced by their given reaso...
by kelseycasco New Member in Splunk Search 07-30-2019
0 1
0
1
Gowtham0809
Hi, I been using fill null commands on my other searched without any issue, but in a specific case i am unable to g...
by Gowtham0809 New Member in Splunk Search 07-30-2019
0 4
0
4
kimberlytrayson
I need to eval time in hours between now and earliest time from timepicker to use it in search. e.g. if timepicker se...
by kimberlytrayson Path Finder in Splunk Search 07-30-2019
0 7
0
7
nawazns5038
Hi, Does anybody know how to pull the smallest or the largest value in a multi value field ? | makeresults | eval ...
by nawazns5038 Builder in Splunk Search 07-30-2019
0 11
0
11
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...