Splunk Search

Splunk Search
Community Activity
hastrike
Is there a best way to search for blank fields in a search? isnull() or ="" doesn't seem to work. Is there way to do...
by hastrike New Member in Splunk Search 05-14-2019
0 13
0
13
gesa_behrens
Hello, on searching for discrepancies in my dashboard I was able to cut down the problem to the following to searche...
by gesa_behrens Path Finder in Splunk Search 05-14-2019
0 3
0
3
mnarmada
Hello, I have 3 questions here. 1) Code WeeK RFS1 RFS2 RFS3 decision 1234 W1 5 5 5 1234 W2 5 5 6 1234 W3 1 2 2 etc....
by mnarmada Path Finder in Splunk Search 05-14-2019
0 0
0
0
splunkhan
I'm looking to search for multiple errors and exceptions across application logs for across multiple servers. using...
by splunkhan New Member in Splunk Search 05-13-2019
0 1
0
1
marty1234
There are many failures in my logs and many of them are failing for the same reason. I am using this query to see the...
by marty1234 Engager in Splunk Search 05-13-2019
0 1
0
1
hketer
Hey, I have this event. as you can see there is field named cs1. I need to create new field lets say cs_1 and extract...
by hketer Path Finder in Splunk Search 05-13-2019
0 13
0
13
perryd
Hi, i would match two field, exactly: field1 - field2 1 - Empty 1 - Empty 1 - Empty ...
by perryd Engager in Splunk Search 05-13-2019
0 8
0
8
rrakesh874
HI All, I have scenario where my field value is pipe delimited e.g. Session=PP|OO|GG if in search I do table of Ses...
by rrakesh874 New Member in Splunk Search 05-13-2019
0 4
0
4
mnarmada
Hello, My Situation is different. I have few columns like: code, Week, rfs, decision, new_deecision. In my search,...
by mnarmada Path Finder in Splunk Search 05-13-2019
0 0
0
0
jdhavo
It seems like something that has been answered before but i have been unable to find the answer. Is it possible to ru...
by jdhavo New Member in Splunk Search 05-13-2019
0 3
0
3
jatwell2
Here is the source data: { "contextValues": [ "10.1.1.1", "10", "testhost" ], "contextTypes": [ ...
by jatwell2 New Member in Splunk Search 05-13-2019
0 9
0
9
wlwilliams01
1
2
maryamchar
Hello, I asked this question yesterday but didn't get the right solution. I have two indexes with different fields a...
by maryamchar Explorer in Splunk Search 05-13-2019
0 4
0
4
arunsundarm
index=* [search index=_internal [| rest /services/authentication/current-context splunk_server=local | fields usernam...
by arunsundarm Engager in Splunk Search 05-13-2019
0 3
0
3
brpsingara
May I know what is User Activity as per PCI requirement 10 ? On going SSAE 18 audit, there is one question - please ...
by brpsingara Explorer in Splunk Search 05-13-2019
0 0
0
0
smanganiello_sp
Other than making reports more readable, are there other reasons to use the upper/lower function of eval?
by smanganiello_sp Splunk Employee Splunk Employee in Splunk Search 05-13-2019
0 4
0
4
mschlapfer
I'm trying to write a dbinspect query to calculate the # of days of data that is stored in our hot/warm storage parti...
by mschlapfer Explorer in Splunk Search 05-13-2019
0 2
0
2
D2SI
Hello there, I am stuck with a dynamic field name extraction. The data is partly JSON and sometimes contains nested...
by D2SI Communicator in Splunk Search 05-13-2019
0 2
0
2
afulamba
Hi there, I want to build a query with strings from the lookup table. I have the list of domains in the look up table...
by afulamba Explorer in Splunk Search 05-13-2019
0 19
0
19
BP9906
How can one delete stale lookup files? Sometimes users output their data to a lookup table file to reference in anoth...
by BP9906 Builder in Splunk Search 05-12-2019
1 4
1
4
knalla
Hi, I have the below urls. How can I use the regex to remove the tokens from urls? Looking to remove data between /...
by knalla Path Finder in Splunk Search 05-12-2019
0 3
0
3
chrishow
Hi all, I want to create the correlation search in order to further enhance our current security alert from splunk b...
by chrishow Engager in Splunk Search 05-12-2019
0 3
0
3
SplunkDank
I have a semicolon separated file that is to be used as a lookup file. How do you parse the file within the transform...
by SplunkDank New Member in Splunk Search 05-12-2019
0 5
0
5
christianubeda
Hi team! I want to compare last week with avg last three months. This is my code right now. I need some help pls. ...
by christianubeda Path Finder in Splunk Search 05-12-2019
0 0
0
0
astatrial
Hi all, I am trying to run a map command that will run searches from a lookup one by one as follows : | inputlooku...
by astatrial Contributor in Splunk Search 05-12-2019
0 13
0
13
Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...