Splunk Search

Splunk Search
Community Activity
koshyk
hi We have a centralised lookup file (which is CSV file), but not in our control to change it. The lookup file (enri...
by koshyk Super Champion in Splunk Search 05-14-2019
0 2
0
2
BryanScovill
I've been trying to research this for a couple of days and haven't been able to find anything just right. I am attem...
by BryanScovill Explorer in Splunk Search 05-14-2019
0 6
0
6
vijitgoud9
Looking how Meta woot application will help with KV store.
by vijitgoud9 New Member in Splunk Search 05-14-2019
0 0
0
0
Yaichael
Good day, I've the following query where I want to show the amount of times a category was notified "Blocked" out of...
by Yaichael Communicator in Splunk Search 05-14-2019
0 5
0
5
hastrike
Is there a best way to search for blank fields in a search? isnull() or ="" doesn't seem to work. Is there way to do...
by hastrike New Member in Splunk Search 05-14-2019
0 13
0
13
gesa_behrens
Hello, on searching for discrepancies in my dashboard I was able to cut down the problem to the following to searche...
by gesa_behrens Path Finder in Splunk Search 05-14-2019
0 3
0
3
mnarmada
Hello, I have 3 questions here. 1) Code WeeK RFS1 RFS2 RFS3 decision 1234 W1 5 5 5 1234 W2 5 5 6 1234 W3 1 2 2 etc....
by mnarmada Path Finder in Splunk Search 05-14-2019
0 0
0
0
splunkhan
I'm looking to search for multiple errors and exceptions across application logs for across multiple servers. using...
by splunkhan New Member in Splunk Search 05-13-2019
0 1
0
1
marty1234
There are many failures in my logs and many of them are failing for the same reason. I am using this query to see the...
by marty1234 Engager in Splunk Search 05-13-2019
0 1
0
1
hketer
Hey, I have this event. as you can see there is field named cs1. I need to create new field lets say cs_1 and extract...
by hketer Path Finder in Splunk Search 05-13-2019
0 13
0
13
perryd
Hi, i would match two field, exactly: field1 - field2 1 - Empty 1 - Empty 1 - Empty ...
by perryd Engager in Splunk Search 05-13-2019
0 8
0
8
rrakesh874
HI All, I have scenario where my field value is pipe delimited e.g. Session=PP|OO|GG if in search I do table of Ses...
by rrakesh874 New Member in Splunk Search 05-13-2019
0 4
0
4
mnarmada
Hello, My Situation is different. I have few columns like: code, Week, rfs, decision, new_deecision. In my search,...
by mnarmada Path Finder in Splunk Search 05-13-2019
0 0
0
0
jdhavo
It seems like something that has been answered before but i have been unable to find the answer. Is it possible to ru...
by jdhavo New Member in Splunk Search 05-13-2019
0 3
0
3
jatwell2
Here is the source data: { "contextValues": [ "10.1.1.1", "10", "testhost" ], "contextTypes": [ ...
by jatwell2 New Member in Splunk Search 05-13-2019
0 9
0
9
wlwilliams01
1
2
maryamchar
Hello, I asked this question yesterday but didn't get the right solution. I have two indexes with different fields a...
by maryamchar Explorer in Splunk Search 05-13-2019
0 4
0
4
arunsundarm
index=* [search index=_internal [| rest /services/authentication/current-context splunk_server=local | fields usernam...
by arunsundarm Engager in Splunk Search 05-13-2019
0 3
0
3
brpsingara
May I know what is User Activity as per PCI requirement 10 ? On going SSAE 18 audit, there is one question - please ...
by brpsingara Explorer in Splunk Search 05-13-2019
0 0
0
0
smanganiello_sp
Other than making reports more readable, are there other reasons to use the upper/lower function of eval?
by smanganiello_sp Splunk Employee Splunk Employee in Splunk Search 05-13-2019
0 4
0
4
mschlapfer
I'm trying to write a dbinspect query to calculate the # of days of data that is stored in our hot/warm storage parti...
by mschlapfer Explorer in Splunk Search 05-13-2019
0 2
0
2
D2SI
Hello there, I am stuck with a dynamic field name extraction. The data is partly JSON and sometimes contains nested...
by D2SI Communicator in Splunk Search 05-13-2019
0 2
0
2
afulamba
Hi there, I want to build a query with strings from the lookup table. I have the list of domains in the look up table...
by afulamba Explorer in Splunk Search 05-13-2019
0 19
0
19
BP9906
How can one delete stale lookup files? Sometimes users output their data to a lookup table file to reference in anoth...
by BP9906 Builder in Splunk Search 05-12-2019
1 4
1
4
knalla
Hi, I have the below urls. How can I use the regex to remove the tokens from urls? Looking to remove data between /...
by knalla Path Finder in Splunk Search 05-12-2019
0 3
0
3
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...