Splunk Search

Splunk Search
Community Activity
su_kumar
Hi, I am using the stats command with the list() function. , i am getting below error. Error : 'stats' command: lim...
by su_kumar New Member in Splunk Search 05-08-2019
0 12
0
12
jwalzerpitt
I have some ADFS logs that I'm trying to pull the IPs from. My regex is as follows: (?:(^Token\sType):\s*(?:\n(?!Cli...
by jwalzerpitt Influencer in Splunk Search 05-08-2019
0 5
0
5
ryanisibor
I receive a weekly report on terminated users and I’m trying to create a search that will identify events/domain acti...
by ryanisibor Engager in Splunk Search 05-08-2019
0 2
0
2
Shashank_87
Hi, I have one OS index in Splunk where i get the raw data in a tabular format like below. Now I need to extract thes...
by Shashank_87 Explorer in Splunk Search 05-08-2019
0 7
0
7
sjansma
I have made two indexes and set the values into a table. How can i find a value from table1 in table2 and present de ...
by sjansma Explorer in Splunk Search 05-08-2019
0 7
0
7
marxsabandana
I'm about to unite product codes from 2 different sourcetypes with different names, but with the same value. Here's ...
by marxsabandana Path Finder in Splunk Search 05-08-2019
1 1
1
1
virex
I have a main search and a lookup table I want to assign field called isCorrect to values from the main search that m...
by virex Engager in Splunk Search 05-07-2019
0 2
0
2
nick405060
Hey guys, I am ingesting VPN logs and would like to parse them out. Does anyone have regexes to use?
by nick405060 Motivator in Splunk Search 05-07-2019
0 1
0
1
bramkostermans
Dear fellow Splunkers, I'm running a saved search containing multiple sub searches and writing the results to a sum...
by bramkostermans Engager in Splunk Search 05-07-2019
1 0
1
0
jofish
Let's say I've got a timechart of URLs I'm serving. Over an hour, let's say I served this: server.com/MYcats.html -...
by jofish Engager in Splunk Search 05-07-2019
1 2
1
2
zacksoft
host = Mayhem sourcetype="phutans:servo" host=R00878 | eval headers=split(_raw," ") | eval plant_length=mvindex(heade...
by zacksoft Contributor in Splunk Search 05-07-2019
0 9
0
9
samn123
I have a lookup table with fields Application name and host, and i have a realtime Incident data with index, sourcety...
by samn123 New Member in Splunk Search 05-07-2019
0 3
0
3
johnraftery
Hello, I have a token called range (assume it has a value of "123-456"), and I am trying to use it inside a token eva...
by johnraftery Communicator in Splunk Search 05-07-2019
1 6
1
6
ghostdog920
I have looked at a ton of posts about breaking a multivalued field but having zero luck effecting a solution. I have...
by ghostdog920 Path Finder in Splunk Search 05-07-2019
0 23
0
23
singh3and12
Hi, I am trying to create a dashboard that shows % CPU Processor time avg (Value)..but the query i used to only givin...
by singh3and12 Path Finder in Splunk Search 05-07-2019
0 4
0
4
sarit_s
Hello i have source path that looks like : s3://splunk/OTHER/1/OTHER/Star J750/pjserialnumber/2019-05-06T13:40:37....
by sarit_s Communicator in Splunk Search 05-07-2019
0 5
0
5
jiaqya
i have a field with dates in single line ( could be many dates ) ex: 2019-04-11 23:15:58.547 2019-05-02 10:11:22.833...
by jiaqya Builder in Splunk Search 05-07-2019
0 4
0
4
sarit_s
hello i have this query : index = amer_pj | SerialNumber | Region | stats dc(SerialNumber) as Serial...
by sarit_s Communicator in Splunk Search 05-06-2019
0 11
0
11
taroito1q75
contingencyコマンドを使えばクロス集計表(左図)が得られますが、これをパーセント表記させる(右図)方法はありますでしょうか?
by taroito1q75 New Member in Splunk Search 05-06-2019
0 1
0
1
grook
New to Splunk. Trying to use the "as" command modifier to change the name of a column. However, the modifier is not b...
by grook New Member in Splunk Search 05-06-2019
0 4
0
4
isplunk2999
Hi I have the following search query which shows the output as shown below,as you can see the issue is the linegraph...
by isplunk2999 Path Finder in Splunk Search 05-06-2019
0 6
0
6
sansay
We just found out that the search command TERM does NOT work when used on extracted fields in one of our Splunk Enter...
by sansay Contributor in Splunk Search 05-06-2019
0 5
0
5
Rhuen
Hy, i have create a Dashboard with Error Logs. 1 for all pc's: Computername="*", it works, i see all PC's but which ...
by Rhuen New Member in Splunk Search 05-06-2019
0 3
0
3
almin
Hi everyone, I am using Splunk Enterprise 7.0.8.5 with the Universal Forwarder 6.5.2/6.5.3 on multiple hosts runnin...
by almin Engager in Splunk Search 05-06-2019
0 3
0
3
atl215
index=rap sourcetype="joyner lucas" | dedup albums| table albums |append [search index=country sourcetype="lil Nas" |...
by atl215 New Member in Splunk Search 05-06-2019
0 3
0
3
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...