Splunk Search

Splunk Search
Community Activity
mschlapfer
I'm trying to write a dbinspect query to calculate the # of days of data that is stored in our hot/warm storage parti...
by mschlapfer Explorer in Splunk Search 05-13-2019
0 2
0
2
D2SI
Hello there, I am stuck with a dynamic field name extraction. The data is partly JSON and sometimes contains nested...
by D2SI Communicator in Splunk Search 05-13-2019
0 2
0
2
afulamba
Hi there, I want to build a query with strings from the lookup table. I have the list of domains in the look up table...
by afulamba Explorer in Splunk Search 05-13-2019
0 19
0
19
BP9906
How can one delete stale lookup files? Sometimes users output their data to a lookup table file to reference in anoth...
by BP9906 Builder in Splunk Search 05-12-2019
1 4
1
4
knalla
Hi, I have the below urls. How can I use the regex to remove the tokens from urls? Looking to remove data between /...
by knalla Path Finder in Splunk Search 05-12-2019
0 3
0
3
chrishow
Hi all, I want to create the correlation search in order to further enhance our current security alert from splunk b...
by chrishow Engager in Splunk Search 05-12-2019
0 3
0
3
SplunkDank
I have a semicolon separated file that is to be used as a lookup file. How do you parse the file within the transform...
by SplunkDank New Member in Splunk Search 05-12-2019
0 5
0
5
christianubeda
Hi team! I want to compare last week with avg last three months. This is my code right now. I need some help pls. ...
by christianubeda Path Finder in Splunk Search 05-12-2019
0 0
0
0
astatrial
Hi all, I am trying to run a map command that will run searches from a lookup one by one as follows : | inputlooku...
by astatrial Contributor in Splunk Search 05-12-2019
0 13
0
13
swaguzari
I'm having a problem creating an alert for following scenario: Data source: index=mail sourcetype=pps_messagelog (in...
by swaguzari Engager in Splunk Search 05-12-2019
0 3
0
3
jip31
hello I am doing the distinct count below in my search | stats dc(host) AS OnlineCount by Code | where Code = "Onl...
by jip31 Motivator in Splunk Search 05-12-2019
0 5
0
5
williamsmew
index=av sourcetype=BobsCutRateAV category="BadStuffHappening" | eval date_hour=strftime(_time, "%H") | eval date_w...
by williamsmew New Member in Splunk Search 05-11-2019
0 7
0
7
russell120
Hello, I have a scheduled search that populates a CSV with data each day, including the current date. Here is an ex...
by russell120 Communicator in Splunk Search 05-11-2019
0 4
0
4
keanhong
Hi All, I have a problem to form the logic for sorting Latest and Previous Data to compare. Looking Field1=Status , ...
by keanhong New Member in Splunk Search 05-11-2019
0 7
0
7
lsanthoshbe
If look the below screen shot due to multiple calls in same time some time response takes a while and we need to matc...
by lsanthoshbe New Member in Splunk Search 05-11-2019
0 4
0
4
marxsabandana
I need to filter searches that has a value of "F*" included per transaction number. The transaction number with my se...
by marxsabandana Path Finder in Splunk Search 05-11-2019
0 1
0
1
Sukisen1981
I have a simple search on a text pad, like this index=text|rex field=_raw "ApplicationRegistry-(?<text>.*)" max_match...
by Sukisen1981 Champion in Splunk Search 05-11-2019
0 22
0
22
summitsplunk
Here's my query: index="smt_fortigate" host="10.8.12.1" srcintf=mysummitwifi | stats count by devtype What I want t...
by summitsplunk Communicator in Splunk Search 05-10-2019
0 5
0
5
nplamondon
I'm using predict, and seeing good results, but I would like to clean up my visualization. What I would like is to s...
by nplamondon Communicator in Splunk Search 05-10-2019
0 20
0
20
alc2019
My data is from the same source but I would like to count the number of times a host appears on the event based on tw...
by alc2019 New Member in Splunk Search 05-10-2019
0 6
0
6
alc2019
Hi, How do I convert two fields (date and time) from a lookup table to _time? I would like to use it to create time...
by alc2019 New Member in Splunk Search 05-10-2019
0 5
0
5
timothytruax
Here is what I have: ...a log table with a unique FName-LName & Job-Title. I pulled 100 rows on both yesterday and ...
by timothytruax Explorer in Splunk Search 05-10-2019
0 6
0
6
Prakash493
Splunk HTTP event collector not sending data to an index. I have HTTP event collector configured in HF . And it sends...
by Prakash493 Communicator in Splunk Search 05-10-2019
0 2
0
2
jip31
hello I use the search below in order to display the result (count) in a single value panel In the same single value,...
by jip31 Motivator in Splunk Search 05-10-2019
0 1
0
1
jip31
hi I use the search below in order to count the number of machines which are online it works BUT When I count the ma...
by jip31 Motivator in Splunk Search 05-10-2019
0 1
0
1
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors