Splunk Search

Splunk Search
Community Activity
anilkashyap
I want to extract the PID number from the log and store in variable failedPID. i have many of this kind of message w...
by anilkashyap New Member in Splunk Search 07-31-2019
0 3
0
3
Mike6960
I am trying to use eval to calculate the time between events. Those events have a unique ID. This is the sarch that I...
by Mike6960 Path Finder in Splunk Search 07-31-2019
0 6
0
6
yuraminsk
I have a complicated request that starts like host=*hb* Exception OR Exception: NOT whitehat NOT org.springframework...
by yuraminsk Engager in Splunk Search 07-31-2019
0 2
0
2
wfskmoney
Which one would be faster or better in general: | dedup fieldA fieldB --> I would assume that Splunk does a concaten...
by wfskmoney Path Finder in Splunk Search 07-31-2019
0 1
0
1
Sujithkumarkb
I want to extract the below fields from my raw data and place it into a field . How can i do it with transforms and p...
by Sujithkumarkb Observer in Splunk Search 07-31-2019
0 5
0
5
dpelletier
We have an existing Drill down that currently works. We are adding 2 new lines to the drilldown that filter out compu...
by dpelletier Observer in Splunk Search 07-30-2019
0 1
0
1
jordanking1992
We have data indexed in Splunk that has a field called pod. In the screenshots, you can see that pod has a list of va...
by jordanking1992 Path Finder in Splunk Search 07-30-2019
0 3
0
3
splunker1981
Hello fellow Splunkers Not sure the best way to approach the following problem. I use replace to update values wit...
by splunker1981 Path Finder in Splunk Search 07-30-2019
0 2
0
2
splkcurtis
I have a search for a dashboard and I'd like to filter it based on an IN search with results from parent search. Is ...
by splkcurtis New Member in Splunk Search 07-30-2019
0 1
0
1
esalmon_splunk
I'm using the transaction command to correlate some searches, no I don't want to use stats, and its all split how I w...
by esalmon_splunk Splunk Employee Splunk Employee in Splunk Search 07-30-2019
0 3
0
3
Vfinney
I am trying to extract the file types, file names, and URLs from proxy logs for monitoring purposes. Here is what I'...
by Vfinney Observer in Splunk Search 07-30-2019
0 1
0
1
russell120
I have a multivalue field with at least 3 different combinations of values. See Example.CSV below (the 2 "apple orang...
by russell120 Communicator in Splunk Search 07-30-2019
0 6
0
6
kelseycasco
I would like to make a Pareto chart that shows the sum of how many scrapped pieces were produced by their given reaso...
by kelseycasco New Member in Splunk Search 07-30-2019
0 1
0
1
Gowtham0809
Hi, I been using fill null commands on my other searched without any issue, but in a specific case i am unable to g...
by Gowtham0809 New Member in Splunk Search 07-30-2019
0 4
0
4
kimberlytrayson
I need to eval time in hours between now and earliest time from timepicker to use it in search. e.g. if timepicker se...
by kimberlytrayson Path Finder in Splunk Search 07-30-2019
0 7
0
7
nawazns5038
Hi, Does anybody know how to pull the smallest or the largest value in a multi value field ? | makeresults | eval ...
by nawazns5038 Builder in Splunk Search 07-30-2019
0 11
0
11
jwalzerpitt
I have the following search results and would like to add the count totals up. If I add the following line: |addtota...
by jwalzerpitt Influencer in Splunk Search 07-30-2019
0 9
0
9
hackerspoint
I would like to predict how long the transaction would take given the dataset grows. Let us assume the job runs daily...
by hackerspoint New Member in Splunk Search 07-30-2019
0 1
0
1
mariorodriguez
Good day. Could you help me in the following situation? I was informed that an OU had been removed from the active d...
by mariorodriguez Engager in Splunk Search 07-30-2019
0 2
0
2
bmicek
I can't find anything about them anywhere else, under statistics I see a list of items Avg. Event Count Avg. Result C...
by bmicek New Member in Splunk Search 07-30-2019
0 0
0
0
jmpaul012
I'm trying to do a JOIN with 2 search but I'm having issues. I tried to do a multi search join but I'm getting a str...
by jmpaul012 New Member in Splunk Search 07-30-2019
0 10
0
10
romulusc
Hi, For some reason when running one of the preset Active Directory searches like 'Group Changes' for instance I do ...
by romulusc New Member in Splunk Search 07-30-2019
0 2
0
2
rileyken
I have a GUID field in my logs, and the guid is unique for a specific location. I wanted to query for all events that...
by rileyken Explorer in Splunk Search 07-30-2019
0 3
0
3
damucka
Hello, I have quite long SPL search in my alert and one part of it looks as follows: | eval rcatrigger = "" | appen...
by damucka Builder in Splunk Search 07-30-2019
0 2
0
2
schose
Hi forum, we are facing large increasing delays between dispatch_time and scheduled_time in scheduler log. We see de...
by schose Builder in Splunk Search 07-30-2019
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors