Splunk Search

Splunk Search
Community Activity
nawazns5038
Hi, Does anybody know how to pull the smallest or the largest value in a multi value field ? | makeresults | eval ...
by nawazns5038 Builder in Splunk Search 07-30-2019
0 11
0
11
jwalzerpitt
I have the following search results and would like to add the count totals up. If I add the following line: |addtota...
by jwalzerpitt Influencer in Splunk Search 07-30-2019
0 9
0
9
hackerspoint
I would like to predict how long the transaction would take given the dataset grows. Let us assume the job runs daily...
by hackerspoint New Member in Splunk Search 07-30-2019
0 1
0
1
mariorodriguez
Good day. Could you help me in the following situation? I was informed that an OU had been removed from the active d...
by mariorodriguez Engager in Splunk Search 07-30-2019
0 2
0
2
bmicek
I can't find anything about them anywhere else, under statistics I see a list of items Avg. Event Count Avg. Result C...
by bmicek New Member in Splunk Search 07-30-2019
0 0
0
0
jmpaul012
I'm trying to do a JOIN with 2 search but I'm having issues. I tried to do a multi search join but I'm getting a str...
by jmpaul012 New Member in Splunk Search 07-30-2019
0 10
0
10
romulusc
Hi, For some reason when running one of the preset Active Directory searches like 'Group Changes' for instance I do ...
by romulusc New Member in Splunk Search 07-30-2019
0 2
0
2
rileyken
I have a GUID field in my logs, and the guid is unique for a specific location. I wanted to query for all events that...
by rileyken Explorer in Splunk Search 07-30-2019
0 3
0
3
damucka
Hello, I have quite long SPL search in my alert and one part of it looks as follows: | eval rcatrigger = "" | appen...
by damucka Builder in Splunk Search 07-30-2019
0 2
0
2
schose
Hi forum, we are facing large increasing delays between dispatch_time and scheduled_time in scheduler log. We see de...
by schose Builder in Splunk Search 07-30-2019
0 1
0
1
DreadEclipse
I am writing a series of programs to make regular calls to the Splunk server and quickly sort the results of a search...
by DreadEclipse Explorer in Splunk Search 07-30-2019
0 2
0
2
wgawhh5hbnht
I'm attempting to find out when Windows event log service has been stopped/logs cleared but only when a shutdown comm...
by wgawhh5hbnht Communicator in Splunk Search 07-29-2019
0 2
0
2
bowesmana
I am creating a SearchManager var detailSearch = new SearchManager({ id: 'detailSearch', earliest_time: '-...
by SplunkTrust SplunkTrust in Splunk Search 07-29-2019
0 1
0
1
JoshuaJohn
There are 3 fields important to this search Application InstalledVersion InstalledStatus I am trying to find device...
by JoshuaJohn Contributor in Splunk Search 07-29-2019
0 1
0
1
varunawasthi9
Hi All, is this doable that a search request give a list of results in that a filed will have order id those are lis...
by varunawasthi9 New Member in Splunk Search 07-29-2019
0 4
0
4
RaymondN80
I'm trying to trim the URL's for a particular search, where it removes everything after the last "/". In other words:...
by RaymondN80 New Member in Splunk Search 07-29-2019
0 10
0
10
mnarmada
Hello All, I have a log file where I am trying to extract one match, and If I find that match I have to put as "File...
by mnarmada Path Finder in Splunk Search 07-29-2019
0 8
0
8
vnguyen46
Hi, I have two different records: [2019-07-22 10:32:03.819930 -0500] rprt s=2tuw17mc0b cmd=env_rcpt value=ken@gmail.c...
by vnguyen46 Contributor in Splunk Search 07-29-2019
0 5
0
5
jwalzerpitt
I am trying to figure out what end of the anchor parameter to use for the Symantec event. Here is a snippet of the ...
by jwalzerpitt Influencer in Splunk Search 07-29-2019
0 3
0
3
mcg_connor
I am trying to create an alert for the below search that would go off if within the event there are 10 times where Ev...
by mcg_connor Path Finder in Splunk Search 07-29-2019
0 2
0
2
ketaka
I created a custom search command on windows, but the following error message is displayed and I can not execute it. ...
by ketaka Explorer in Splunk Search 07-29-2019
0 4
0
4
officialsubho
Have the following queries query 1 - cf_org_name="xxx" cf_space_name="yyy" cf_app_name=zzz index=123* msg= "Transact...
by officialsubho New Member in Splunk Search 07-29-2019
0 3
0
3
nick405060
Hi there, I have a real-time table in one of my dashboards that doesn't update when you first load the page. If you ...
by nick405060 Motivator in Splunk Search 07-29-2019
0 9
0
9
espengler
I'm running CRL expiration checks and using splunk to read the logs to track the last check run and when they are nex...
by espengler Engager in Splunk Search 07-29-2019
0 8
0
8
sbimizry
How to I must a write result from stats count to field? Example ideas... | inputlookup lookup | stats count(eval(fi...
by sbimizry Engager in Splunk Search 07-29-2019
0 6
0
6
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...