Splunk Search

Splunk Search
Community Activity
amaurya1
Requirement - account_no can have many session_no and session_no can have many sub_session_no. For each session, I wa...
by amaurya1 Explorer in Splunk Search 07-10-2019
0 2
0
2
splunked38
Hi, In short, just wondering if anyone has used Splunk for 'mail merging' I have a dynamically generated field cont...
by splunked38 Communicator in Splunk Search 07-10-2019
0 0
0
0
SplunkHorse
I have a dashboard with a single value sparkline based off a timechart: index=[theindex] event_name=[theevent] | ti...
by SplunkHorse New Member in Splunk Search 07-10-2019
0 2
0
2
habisht
Hi All, I'm trying to create a pie chart where i'v 2 search result sets from different condition and different source...
by habisht Explorer in Splunk Search 07-10-2019
0 3
0
3
codedtech
I'm building a time chart of avg daily backup volume, and I need to exclude entries where volume = 0. The reason be...
by codedtech Path Finder in Splunk Search 07-10-2019
0 1
0
1
jeroenborger
hello splunk communitie, i am new to splunk but found allot of information allready but i have a problem with the giv...
by jeroenborger Explorer in Splunk Search 07-10-2019
0 2
0
2
rjfv8205
Hello Splunkers. Yesterday I don't have events but today I have it. For example: Event aaa today exists 100 times ...
by rjfv8205 Path Finder in Splunk Search 07-10-2019
0 0
0
0
twjack
index=myIndex FieldA="A" AND LogonType IN (4,5,8,9,10,11,12) The documentation says it is used with "eval" or "wher...
by twjack Explorer in Splunk Search 07-10-2019
0 2
0
2
adalbor
Hey All, I am trying to calculate the number of events per EventCode along with the total size in kb/mb of all event...
by adalbor Builder in Splunk Search 07-10-2019
1 6
1
6
cxfuent29
Not sure where I should be going but, I am all for raw data going into fields, enhanced etc... I am looking at our ra...
by cxfuent29 New Member in Splunk Search 07-10-2019
0 5
0
5
bahndg
I want to dynamically add fields to my result set depending on a search I did. How do I can add fields/new columns b...
by bahndg Explorer in Splunk Search 07-10-2019
0 2
0
2
kaizersx
What kind of request you need to create to select all the logs in which all fields are filled?
by kaizersx New Member in Splunk Search 07-10-2019
0 2
0
2
chrisray_view
I have a challenge in front of me that I can't figure out. I spent a few hours searching 'answers' and made some hea...
by chrisray_view New Member in Splunk Search 07-09-2019
0 3
0
3
mcbradford
I have a search that returns one result, one of the fields is called whatchanged, and this field really has two value...
by mcbradford Contributor in Splunk Search 07-09-2019
0 1
0
1
itrimble1
How can I make a table for multiple Windows Events ? This search gives me good results for one Event Code, but I hav...
by itrimble1 Path Finder in Splunk Search 07-09-2019
0 2
0
2
bwindham
I am terrible with regexes. What regex would I need to extract "pdf" from the following? This was not pulling all ev...
by bwindham Path Finder in Splunk Search 07-09-2019
0 2
0
2
jbezanson
I have a report that reports the count of events per another field. I can get a total of all of these events but it ...
by jbezanson Engager in Splunk Search 07-09-2019
1 5
1
5
runiyal
I need to create a report based on three different search criteria from three different sources. But since its a reco...
by runiyal Path Finder in Splunk Search 07-09-2019
0 2
0
2
runiyal
I need to create a report based on three different search criteria from three different sources. But since its a reco...
by runiyal Path Finder in Splunk Search 07-09-2019
0 1
0
1
cmille19
I'm trying to exclude known issues from a search by using a lookup of exclusions. Our Splunk admins lock down alert c...
by cmille19 Engager in Splunk Search 07-09-2019
0 3
0
3
amunag439
I'm calculating the time difference between two events by using Transaction and Duration. Below is the query that I u...
by amunag439 Explorer in Splunk Search 07-09-2019
0 5
0
5
johnansett
Hello, I am trying to extract the entire URL up to the point where it includes a question mark. Generally the data w...
by johnansett Communicator in Splunk Search 07-09-2019
0 2
0
2
jeburkes76
Trying to understand how this SEDCMD works so I can modify it for something else. It works in props.conf but I can't ...
by jeburkes76 Explorer in Splunk Search 07-09-2019
0 6
0
6
keldridg2
I downloaded the Splunk visualization app to create a custom visualization but when I click on starting on the base t...
by keldridg2 New Member in Splunk Search 07-09-2019
0 0
0
0
zawan
I am trying to optimize my splunk deployment by removing duplicate alerts. I have this search which shows me all of ...
by zawan Engager in Splunk Search 07-09-2019
0 1
0
1
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...