Splunk Search

Splunk Search
Community Activity
splunk_zen
How to correct this SPL to avoid this error index=win EventCode=528 OR EventCode=4624 LogonType=2 | fields Account_...
by splunk_zen Builder in Splunk Search 04-19-2019
0 4
0
4
jiaqya
i have 2 columns as below. Please see if you have a way to do this .. thanks.. Requirement is if col1 = col2 , co...
by jiaqya Builder in Splunk Search 04-19-2019
0 6
0
6
net1993
Hi Lets say I have value of 99.99875547590601 and I want to get only 99,99 so I use the function round(99.998755475...
by net1993 Path Finder in Splunk Search 04-19-2019
0 1
0
1
rakeshkumar19
Please help me to add percentage column SourceName, Count, % ABC , 20, 5% XYZ, 10, 2% index=prod_sum | dedup Sour...
by rakeshkumar19 New Member in Splunk Search 04-18-2019
0 7
0
7
venkasplunk
hi all, have some query on search use case. 1) My requirement is to extract a hpotter from a log - ex: log looks...
by venkasplunk New Member in Splunk Search 04-18-2019
0 6
0
6
anasshsa
Hello, I cannot figure out the syntax of the rex function. I have a field called data multiple email addresses: eampl...
by anasshsa Engager in Splunk Search 04-18-2019
0 2
0
2
hketer
Hey! For example, if I have events contain different countries. Is it possible to restrict users by specific values...
by hketer Path Finder in Splunk Search 04-18-2019
0 2
0
2
anasshsa
Hello, I have this query: index=main | table sourcetype, data, context, local_endpoint, remote_endpoint | eval Ergebn...
by anasshsa Engager in Splunk Search 04-18-2019
0 2
0
2
vineeth_jain
Hi All, I am unable to convert date string to date format using below SPL query. eval "-Last Logon Date" = strptime...
by vineeth_jain Explorer in Splunk Search 04-18-2019
0 3
0
3
rjfv8205
Hello splunkers! We have lost indexed data of some days in clustered indexer. However, data exists in standalone spl...
by rjfv8205 Path Finder in Splunk Search 04-18-2019
0 6
0
6
HustenHelmut334
This is not working: Is there a special syntax to use the content of a variable an not its name? sourcetype="test" |...
by HustenHelmut334 New Member in Splunk Search 04-18-2019
0 2
0
2
anasshsa
Hello, I Need to know how can I trim a string from the begining until a specific character. For example, I have the t...
by anasshsa Engager in Splunk Search 04-17-2019
0 2
0
2
chandlercr
Is there any sort of syntax for me to be able to manipulate or get data on data that exists in the Values() field. S...
by chandlercr New Member in Splunk Search 04-17-2019
0 1
0
1
mjones414
I've got a test set of hosts using collectd to gather process information, and I'm struggling how to get mstats to gi...
by mjones414 Contributor in Splunk Search 04-17-2019
0 0
0
0
clozach
My goals is to grab the computer name from the multi-value field: identities. I then want to take that new attribute ...
by clozach Path Finder in Splunk Search 04-17-2019
0 1
0
1
evelenke
Hi Splunkers, we have JSON logs with multiple values for a single field - list of identities - up to 1000. I need ...
by evelenke Contributor in Splunk Search 04-17-2019
0 0
0
0
VanyBerg
Dear Community, I got a use case I seem to be too inexperienced with to complete on my own. Since I just started del...
by VanyBerg Engager in Splunk Search 04-17-2019
0 1
0
1
jip31
hello I use the search below in order to display cpu using is > to 80% by host and by process-name So a same host ca...
by jip31 Motivator in Splunk Search 04-17-2019
0 4
0
4
LHisham
I am fairly new to Splunk so bear with me. I have extracted two fields and they are ConnectTime and DisconnectTime a...
by LHisham Engager in Splunk Search 04-17-2019
1 3
1
3
jip31
hi I have diffuclties to understand how inputlookup works I use the search below index="x" sourcetype=y source="...
by jip31 Motivator in Splunk Search 04-17-2019
0 10
0
10
ddrillic
One of our customers wonders whether it's possible to change an index name. Is it possible?
by ddrillic Ultra Champion in Splunk Search 04-17-2019
0 2
0
2
wingstopdgon
I am trying to search event logs for an event when a user password is set to not expire. But the alert I have setu...
by wingstopdgon New Member in Splunk Search 04-17-2019
0 1
0
1
anasshsa
I Need to know to subtract a string from the begining of a value until a specific character in Spl. For example, if I...
by anasshsa Engager in Splunk Search 04-17-2019
0 1
0
1
adamcoquim
Hi, Essentially, I am trying to join 2 or 3 log entries together linking them by a yet to be determined value (sessi...
by adamcoquim Explorer in Splunk Search 04-17-2019
0 2
0
2
damucka
Hello, I have the following inputs.conf on my indexer: [default] host = mo-7ee963859.zone1.mo.sap.corp [monitor://...
by damucka Builder in Splunk Search 04-17-2019
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...
Top Solution Authors