Splunk Search

Splunk Search
Community Activity
viking1978
I am doing weekly statistics and in splunk 7, i can easily specify the first day of a week by @w1 so 1 means Monday. ...
by viking1978 New Member in Splunk Search 06-11-2019
0 1
0
1
dirtyspawn
I am kind of new so I apologize to my ignorance. What I am trying to do is use the Windows Event Logs EventCode 5156 ...
by dirtyspawn Engager in Splunk Search 06-11-2019
0 6
0
6
jenkinsta
I have a search that gets the count of events by users which works well. However, I want to have the chart list all u...
by jenkinsta Path Finder in Splunk Search 06-11-2019
0 5
0
5
eholz1
Hello all, I have a working universal forwarder that happily sends data to my Enterprise indexer. The data shows up u...
by eholz1 Builder in Splunk Search 06-11-2019
0 5
0
5
user93
Hello, I need a search to match when a field that has free form text contains exactly 8 characters that are letters ...
by user93 Communicator in Splunk Search 06-11-2019
0 3
0
3
barriersbill
hi, what are your thoughts on data virtualization and how does it apply to Splunk? I ave been researching data virtua...
by barriersbill Explorer in Splunk Search 06-11-2019
1 2
1
2
jsalsbur
Good afternoon I have a stats count query leading to a single number dashboard. I was wondering if it is possible to ...
by jsalsbur Explorer in Splunk Search 06-11-2019
0 3
0
3
veerappan
I am beginner to Splunk and could you please help me with the following scenario. I have a search that will display a...
by veerappan New Member in Splunk Search 06-11-2019
0 2
0
2
sarit_s
Hello i have several reports that contains the search index=something__something in my case, '' is the name of the re...
by sarit_s Communicator in Splunk Search 06-11-2019
0 9
0
9
aleksandar_mati
Hi, I need help with transaction command results. I have the following input to transaction command: eventID,"_time...
by aleksandar_mati New Member in Splunk Search 06-11-2019
0 4
0
4
jip31
Hello I use 2 tokens in the XML below, I need to use comparison sign like > and < in this token. I would like also t...
by jip31 Motivator in Splunk Search 06-11-2019
0 10
0
10
splunkuzleuven
I'm wondering if/how I can do the following: I have a JSON structured file that is being parsed perfectly as JSON, s...
by splunkuzleuven Loves-to-Learn Lots in Splunk Search 06-11-2019
0 3
0
3
corecomputetool
is this command is correct ? ** | chart count by sourcetype | sort count desc*
by corecomputetool New Member in Splunk Search 06-10-2019
0 10
0
10
riotto
I have events that will be indexed that will look like the below: 2019-06-06 21:12:40.397 { "response": "NodeJST5109...
by riotto Path Finder in Splunk Search 06-10-2019
0 3
0
3
gcharles
I would like to understand which of the following is the fastest and why or if there are any more faster ways to achi...
by gcharles Explorer in Splunk Search 06-10-2019
0 2
0
2
ashiknew007
Hi, I am trying to match events between two index: Index A & Index B. Index A have 3 column: date-time, User's Cell ...
by ashiknew007 New Member in Splunk Search 06-10-2019
0 2
0
2
rashi83
I have a CSV file with region , status , hostname as Columns - field extraction works and gives them as region , stat...
by rashi83 Path Finder in Splunk Search 06-10-2019
0 3
0
3
summitsplunk
For example: stats sum(bytes_in) AS bytes_in, sum(bytes_out) AS bytes_out is the sum going to be in bytes like the d...
by summitsplunk Communicator in Splunk Search 06-10-2019
0 2
0
2
kristian_kolb
Trying to write a search that list events happening outside office hours, across a bunch of sourcetypes - however, th...
by kristian_kolb Ultra Champion in Splunk Search 06-10-2019
6 9
6
9
mbasharat
Hi, Scnenario is: I have an Organization A. Organization A has 10 Hosts. Vulnerability scan finds 50 unique vulne...
by mbasharat Builder in Splunk Search 06-10-2019
0 3
0
3
the_wolverine
Is there a search that can be run to display the contents of a lookup file?
by the_wolverine Champion in Splunk Search 06-10-2019
11 7
11
7
himanshu_b_shek
hello content of /opt/splunk/etc/splunk-launch.conf : in my environment , i can see it is commented then how it i...
by himanshu_b_shek New Member in Splunk Search 06-10-2019
0 2
0
2
nick405060
Hey guys So I would like to have a search select events from myindex based on what the user selects in a multiselect...
by nick405060 Motivator in Splunk Search 06-10-2019
0 7
0
7
dowdag
I am trying to look for data (from a few different log files) between a pair of Start Event and End Events in one rel...
by dowdag Engager in Splunk Search 06-10-2019
0 3
0
3
elaoumam
Hi there, I have these two searchs to count TPS : First one : index=tutti sourcetype=toto status!=4 | bucket span=...
by elaoumam Engager in Splunk Search 06-10-2019
0 3
0
3
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...