Splunk Search

Splunk Search
Community Activity
splunkuseradmin
hello I have a command which gives the value ex., "172" it is basically change when no. of ldap users added and remo...
by splunkuseradmin Path Finder in Splunk Search 05-22-2019
0 3
0
3
dayananda7449
Hi Everyone, I am a newbie to splunk. We are using splunk to monitor our custom perfmon counters. see the below sear...
by dayananda7449 New Member in Splunk Search 05-22-2019
0 3
0
3
vickie123
I am seeing this error: java.lang.RuntimeException: Operation timed out (Connection timed out) when I try to creat...
by vickie123 New Member in Splunk Search 05-22-2019
0 0
0
0
andweng
I have a search that produces the following sample data: ValueA ValueB A 1 A 2 A 3 B ...
by andweng New Member in Splunk Search 05-22-2019
0 2
0
2
pavanae
I have the following stanza on the transforms.conf which actually splits commands separated by characters like |, &, ...
by pavanae Builder in Splunk Search 05-22-2019
0 4
0
4
nashia
I only want to look at built in shares like A$-Z$, but not ADMIN$ or IPC$. Is there a rex expression that will allow ...
by nashia New Member in Splunk Search 05-22-2019
0 6
0
6
_smp_
I have an event with a mix of JSON and non-JSON data. I have successfully extracted a Payload field with props whose ...
by _smp_ Builder in Splunk Search 05-22-2019
2 5
2
5
roopeshetty
Hi guys, Is there any way we can display more than 100 rows in a table format dashboard? We tried to modify the ...
by roopeshetty Path Finder in Splunk Search 05-22-2019
0 6
0
6
marxsabandana
I need to display a table that will show all the rows without pagination. I have already tried using "showPager" opti...
by marxsabandana Path Finder in Splunk Search 05-22-2019
0 2
0
2
pavanae
I have the regex query as below sourcetype=syslog | rex field=_raw "(?rshd[^:]: .+) as (?[^\s:]+)" | rex field=_ra...
by pavanae Builder in Splunk Search 05-22-2019
0 2
0
2
mlevsh
I need to extract "hostname" from the path in data input on directory monitoring. Path: /export/var/path/host1.log ...
by mlevsh Builder in Splunk Search 05-22-2019
0 13
0
13
saravanafd
Has been busy for "639" seconds using rex command i need to extract value 639 and store it in one field. Please he...
by saravanafd Explorer in Splunk Search 05-22-2019
0 3
0
3
vishaltv
Hi team, Please help me to figure out the issue. I would like to create a dashboard using my Audit logs to capture m...
by vishaltv Path Finder in Splunk Search 05-22-2019
0 3
0
3
zacksoft
host = Mayhem sourcetype="phutans:servo" host=R00878 | eval headers=split(_raw," ") | eval plant_length=mvindex(he...
by zacksoft Contributor in Splunk Search 05-22-2019
0 9
0
9
bosch_softtec
Hi, I am trying to create a new field "foo" whose content is generated from field "bar", depending on the content of...
by bosch_softtec Path Finder in Splunk Search 05-22-2019
0 2
0
2
stwong
Hi, we've a simple web application in PHP that queries user's status from different sources (e.g. LDAP, Oracle DB, et...
by stwong Communicator in Splunk Search 05-21-2019
0 3
0
3
jadengoho
How can i get latest value of all ID (1-1,1-2,2-1,2-2). considering there are no latest data on ID(2-1,2-2) Data: 1...
by jadengoho Builder in Splunk Search 05-21-2019
0 1
0
1
balcv
I have an sql database containing a list of ip addresses and a bunch of other fields that I can query from Splunk usi...
by balcv Contributor in Splunk Search 05-21-2019
0 5
0
5
singh3and12
Hi , I have used following query for predicting disk transfer of particular host, here we are using LLP algorithm i...
by singh3and12 Path Finder in Splunk Search 05-21-2019
0 12
0
12
zacksoft
I have a lookup table from a csv that looks like this name exam1 exam2 exam3 john good bad bad peter ...
by zacksoft Contributor in Splunk Search 05-21-2019
0 1
0
1
jip31
Hello I use the search below in order to monitore process with a CPU charge > 80% BUT What I exactly need is to moni...
by jip31 Motivator in Splunk Search 05-21-2019
0 8
0
8
moorhead_30s
Hello, I'm writing a custom Splunk search command that runs a query on another Splunk host, then returns those result...
by moorhead_30s New Member in Splunk Search 05-21-2019
0 3
0
3
reverse
I want to add 2 text boxes where I can key in 2 dates. Later I want to use these 2 dates at 4 locations of my query. ...
by reverse Contributor in Splunk Search 05-21-2019
0 3
0
3
surekhasplunk
| mstats max(_value) as Bits_in_sec where index=ehealth (host="SC2CLK-CLOUD-CFD-VDC2" OR host="SC2BJV-CLOUD-CFD-VDC2"...
by surekhasplunk Communicator in Splunk Search 05-21-2019
0 2
0
2
NAVEEN_CTS
Hi I need a help with a Splunk search to find the number of users having access for each indexes. Thanks
by NAVEEN_CTS Path Finder in Splunk Search 05-21-2019
0 1
0
1
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...