Splunk Search

Splunk Search
Community Activity
khourihan_splun
I basically took the list if fqdn in outputs.conf and ran “host inputs1.example.splunkcloud.com” for each one.. the...
by khourihan_splun Splunk Employee Splunk Employee in Splunk Search 07-14-2019
0 2
0
2
astatrial
Hi all, I am counting distinct values of destinations with timechart (span=1h). I am trying to take those values a...
by astatrial Contributor in Splunk Search 07-14-2019
0 4
0
4
mbasharat
I have a text file in below format. We are monitoring this file in Splunk. This file has like entries in new lines wi...
by mbasharat Builder in Splunk Search 07-14-2019
0 4
0
4
marisstella
Hello everyone, I have created some fields A, B, C but now I want to combine the fields, Ex: I have created fields li...
by marisstella Explorer in Splunk Search 07-14-2019
0 1
0
1
milesmedboe
Hi folks, Recently onboarded a new sourcetype configured with search time extractions. Regex works when tested on sa...
by milesmedboe Explorer in Splunk Search 07-14-2019
0 15
0
15
srs20
Hello, i'm searching for a certain condition and wrote the query below .It works but not quite what I'm looking for...
by srs20 New Member in Splunk Search 07-14-2019
0 7
0
7
jhonsonkelly56
Eg : Event 1 : Field1, Field a, Field b Event 2 : Field2, Fields n, Field y How to compare Field1 of event 1 ...
by jhonsonkelly56 New Member in Splunk Search 07-14-2019
0 5
0
5
su_kumar
issue : Unable to see correct result after running query. I have lookup file .CSV which consists some field (AD group...
by su_kumar New Member in Splunk Search 07-14-2019
0 1
0
1
codedtech
I'm working on a query that predicts GB growth, I keep getting "command="predict", Unknown field after eval". Here i...
by codedtech Path Finder in Splunk Search 07-14-2019
0 1
0
1
TylerJVitale
In my dashboard, I have the user select a server and then a line chart displays of application crashes on the selecte...
by TylerJVitale Explorer in Splunk Search 07-14-2019
0 2
0
2
aohls
I am attempting to setup an exctraction for the following; 2 hrs 2 mins 36 secs 312 ms; extracting it as the time val...
by aohls Contributor in Splunk Search 07-14-2019
0 5
0
5
scottkoontz57
I'm trying to extract the key-value pairs from an Untangle firewall log ( syslog ), but the Regex example I found on ...
by scottkoontz57 New Member in Splunk Search 07-13-2019
0 8
0
8
clozach
All I want to do is display a single value of yesterdays entire 24 hour count compared to that of the previous day/ye...
by clozach Path Finder in Splunk Search 07-13-2019
0 3
0
3
cipi23
for 08.07.19 count number of hostnames that have last_seen > 30 days for 01.07.19 count number of hostnames that have...
by cipi23 New Member in Splunk Search 07-13-2019
0 1
0
1
taynord
Works just fine | timechart count by orderLineState | eval cancelRate=round((cancelled/(cancelled+released))*100,2...
by taynord Engager in Splunk Search 07-13-2019
0 2
0
2
malear_ion
I have different case: | eval this_week = case(last_seen < strftime(relative_time(now(), "-mon"), "%Y-%m-%dT%H:%M:%S...
by malear_ion New Member in Splunk Search 07-13-2019
0 1
0
1
tirams
I have a field lets call it usage that can up to 3 of these letters (b, n, e) i.e. all possible logged permutations w...
by tirams New Member in Splunk Search 07-13-2019
0 5
0
5
marisstella
Hiiii How to extract the single field with multiple values? Like status is active, failed, cancelled, deactivated, fo...
by marisstella Explorer in Splunk Search 07-13-2019
0 6
0
6
ritikaviavi
sample CEF: May 20 20:44:51 10.XX.XX.XX May 20 2019 20:44:51 avcm02.com CEF:0|AV|Control Manager|7.0|BM:1000|Behavi...
by ritikaviavi Observer in Splunk Search 07-13-2019
0 2
0
2
codedtech
I need to to convert this field in to a number and remove the $ capacity_gb = $8,191.75, I've tried eval to num and c...
by codedtech Path Finder in Splunk Search 07-13-2019
0 4
0
4
russell120
Hi, I'm using this search: | tstats count by host where index="wineventlog" to attempt to show a unique list of hosts...
by russell120 Communicator in Splunk Search 07-12-2019
0 3
0
3
jchrysler
I must have two accounts associated with my e-mail address. I am stuck on the page stating that I should merge them. ...
by jchrysler Engager in Splunk Search 07-12-2019
1 0
1
0
alucarddjin
Is there a way to get the top 10 count for a number of groupings eg: Col1 Col2 Count G1 SG1 10 G1 ...
by alucarddjin Path Finder in Splunk Search 07-12-2019
0 1
0
1
pitaszek
Hello Comminity, Here goes the more detailed descrition 2019-07-12 11:19:55.519 [VDI111][Process1][Info] msg=report...
by pitaszek New Member in Splunk Search 07-12-2019
0 1
0
1
mkamal18
Hello , I have a connexion problem between Splunk and the LDAP. Please find below the log that i have continuously ...
by mkamal18 New Member in Splunk Search 07-12-2019
0 0
0
0
Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...