Splunk Search

Splunk Search
Community Activity
shugup2923
How can we use case insensitive value in Replace command- | replace "name" with "entity" in description will it rep...
by shugup2923 Path Finder in Splunk Search 06-19-2019
0 1
0
1
dhirendra761
I am trying to extract a filename Nsences_2016_10_10_12_50.csv from below field value. D:\Program Files\X620\ABC\TGF...
by dhirendra761 Contributor in Splunk Search 06-19-2019
0 5
0
5
jorcabro
I'm trying to convert the Health Check queries into a dashboard, I already change neccesary permissions in some macro...
by jorcabro Explorer in Splunk Search 06-19-2019
0 4
0
4
Deepz2612
In the logs I wanted to include events that has the string "uri=https://www.bikerace.com" and if it is not present I ...
by Deepz2612 Explorer in Splunk Search 06-19-2019
0 1
0
1
basvanderbijl
Hi all, I want to merge the following sets based on their timestamp. index=bus sourcetype=bus | table timestamp type...
by basvanderbijl New Member in Splunk Search 06-19-2019
0 0
0
0
denzelchung
I have a base query in my dashboard with multiple other queries that make use of the base query. In my base query, I...
by denzelchung Path Finder in Splunk Search 06-19-2019
0 3
0
3
Nadhiyaa
My script runs every 2 hrs per day .But i need the latest file per day for a timerange to do some calculation.
by Nadhiyaa Path Finder in Splunk Search 06-18-2019
0 3
0
3
nikita012
I have two fields in my data. Below is an example.The actual data contains 100 rows. Store Minutes 81145 33 81234 42...
by nikita012 New Member in Splunk Search 06-18-2019
0 3
0
3
snehalatha
Hi , The below give me the no of days between two dates but i want to calculate only no of business days between two ...
by snehalatha Engager in Splunk Search 06-18-2019
2 4
2
4
sowmya120
I am trying to match a field across two inputs if the field matches then I compare the dates and table them. When I c...
by sowmya120 New Member in Splunk Search 06-18-2019
0 3
0
3
TylerJVitale
I'm linking a click value token in a dashboard to a search. Is there a way to format the drilldown search string so ...
by TylerJVitale Explorer in Splunk Search 06-18-2019
0 2
0
2
bhuvanabala
Hi Team, I am having field called expirationdatetime in my event and its format is 2019-06-21T06:08:40.220082Z. My r...
by bhuvanabala New Member in Splunk Search 06-18-2019
0 2
0
2
matthewcanty
I have the following search: earliest=@d+11h latest=@d+22h index="daluat" Action="DAL*" | timechart span=30m count ...
by matthewcanty Communicator in Splunk Search 06-18-2019
0 9
0
9
sumit29
Hi Team I need your help to write the search on the licence usage. Suppose I have a 100 GB license. My daily licence...
by sumit29 Path Finder in Splunk Search 06-18-2019
1 3
1
3
Deepz2612
Hi,help me in writing regex to extract field between two hyhpens. Eg: S-STRA-32 F-FIDR-67 Thanks!
by Deepz2612 Explorer in Splunk Search 06-18-2019
0 5
0
5
svivekananda007
I need to find a string in a log and set/unset a field depending on this.Ex: field Status = 1 or 0.I should say if(a_...
by svivekananda007 Engager in Splunk Search 06-18-2019
4 9
4
9
vnguyen46
Hi - I am searching for events based on time field Last_Login_Time (sample value: 2019-06-13T20:26:12.000Z) which hap...
by vnguyen46 Contributor in Splunk Search 06-18-2019
0 3
0
3
ddrillic
Is it possible to retrieve data using DBConnect for rows which got modified? And not included via the rising column?
by ddrillic Ultra Champion in Splunk Search 06-18-2019
0 1
0
1
wicke_s
Disclaimer : I'm new to Regex and using the Rex function I have a field "Message" that has the following string form...
by wicke_s Explorer in Splunk Search 06-18-2019
0 12
0
12
rg33
I am looking for methods to compare two fields for a like match. Specifically, I'd like to match when field1 can be ...
by rg33 Explorer in Splunk Search 06-18-2019
1 7
1
7
waghuldese1
I have a stats calculated using : stats distinct_count(c1) by c2 Now I want to calculate the sum of these distinct_...
by waghuldese1 New Member in Splunk Search 06-18-2019
0 1
0
1
antb
index=_internal source="*license_usage.log*" type=Usage idx IN (index1,index2,index3, index4,etcindex) | eval yearmo...
by antb Path Finder in Splunk Search 06-18-2019
0 2
0
2
sarit_s
Hello i have this event for example: $changeSystemTimeCmd 1533808153 -newTime 1533808153 -oldTime 1533808147 i ne...
by sarit_s Communicator in Splunk Search 06-18-2019
0 5
0
5
rashid47010
How to extract the field values between two same characters. Event Axxtalled=xrxnx xx Client\;**12.0.5294**\;15.179...
by rashid47010 Communicator in Splunk Search 06-18-2019
0 2
0
2
damucka
Hello, I need to concatenate two variables including strings (e-mail lists) into one. the code I use for that is the...
by damucka Builder in Splunk Search 06-18-2019
0 1
0
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...