Splunk Search

Splunk Search
Community Activity
ddrillic
We created a lookup via the outputlookup command and we can see the file under $SPLUNK_HOME/etc/apps/<app name>/looku...
by ddrillic Ultra Champion in Splunk Search 04-15-2019
0 1
0
1
splunkuseradmin
Hi everyone, I have 40 source type with different names so I was wondering if i can extract sourcetype using rex. a...
by splunkuseradmin Path Finder in Splunk Search 04-15-2019
1 1
1
1
donemery
I am using regex slot and port information. Here is an example of the syslog output: Slot1 : OLTPort2 Is it possib...
by donemery Explorer in Splunk Search 04-15-2019
0 7
0
7
sudheeraha
Hi there, I have below result with this query. index="abc" Properties.CorrelationId != XYZ | stats count by Prope...
by sudheeraha Engager in Splunk Search 04-15-2019
0 3
0
3
Lowell
Anyone have any thoughts as to how to reorder a multi-valued field? Ideally I'd like to be able to do a "sort" or in...
by Lowell Super Champion in Splunk Search 04-15-2019
4 5
4
5
pench2k19
Hi Team, I m planning to collect the highlited text from the raw data as below info : Detailed logging to /apps/dat...
by pench2k19 Explorer in Splunk Search 04-15-2019
0 10
0
10
Shashank_87
Hi, I want to calculate the Java threads on my 4 application servers. I have one query but i believe that gives all t...
by Shashank_87 Explorer in Splunk Search 04-15-2019
0 2
0
2
rajkumarsowmy
{<!-- --> "timestamp": "2019-04-11T16:44:45.497462", "payload": {<!-- --> "KEY_CHK_DCN_NBR": "19054", "recommendations": ...
by rajkumarsowmy New Member in Splunk Search 04-15-2019
0 2
0
2
cpressl
I have an index that lists (among other things) a device, event date, and level (1-4). Devices change levels at rando...
by cpressl New Member in Splunk Search 04-15-2019
0 0
0
0
msarro
For some reason the following isn't working: index&#61;"sandbox" sourcetype&#61;"as-cdr" |stats count AS numCalls |append [s...
by msarro Builder in Splunk Search 04-15-2019
0 5
0
5
matt
What's the best way to create a search to identify which hosts have not sent a syslog message to Splunk in the last 2...
by matt Splunk Employee Splunk Employee in Splunk Search 04-15-2019
2 10
2
10
johnsasikumar
Hi I have 10 different Splunk queries that return results only when there is an issue or a flag of 1. All the queries...
by johnsasikumar Path Finder in Splunk Search 04-15-2019
0 1
0
1
AKG1_old1
Hi, I am looking to sort column with specific condition. Condition: if column Context_Command contains * it should...
by AKG1_old1 Builder in Splunk Search 04-15-2019
1 2
1
2
kannu
Hello Guys , I am having results from two different query 1&gt; index&#61;_internal ("version" AND source&#61;"/opt/splunk/va...
by kannu Communicator in Splunk Search 04-15-2019
0 10
0
10
lbkAconectodk
I want to output computers who only has started 1 specific application Field values: Application &#43; Computers There i...
by lbkAconectodk New Member in Splunk Search 04-15-2019
0 7
0
7
jip31
Hello I use the search below it works fine..... BUT for some host, I cant catch the fields there is in the subsearch...
by jip31 Motivator in Splunk Search 04-14-2019
0 7
0
7
wailoont
Hi, I have a search query as below. query | stats list(repo_name) by user_login This returns username with their ...
by wailoont Engager in Splunk Search 04-14-2019
0 2
0
2
nick405060
Hi there, I need to disable drilldown on certain columns. Unlike the answer given here... https://answers.splunk.co...
by nick405060 Motivator in Splunk Search 04-14-2019
1 8
1
8
thefuzz4
So I have HomeAssistant installed and I'm sending all of the events off to my splunk server. I recently had my attic...
by thefuzz4 Path Finder in Splunk Search 04-13-2019
0 2
0
2
fred1455
Given the search stats count by Name, Fruit results in: Name, Fruit, count Mike, Bananas, 10 Mike, Apples, 10 Sus...
by fred1455 New Member in Splunk Search 04-13-2019
0 4
0
4
vbantug
Hi, I would like to update a lookup file with, for an example 10 new information, through Splunk Search only. The ...
by vbantug New Member in Splunk Search 04-13-2019
0 2
0
2
brienhawker
I have two fields se_split and re_split which are lined up like so re_split se_split a ...
by brienhawker Explorer in Splunk Search 04-13-2019
1 10
1
10
proylea
Hi Splunkers I have a set of results from using set diff which is all good. I am now wanting to output another field...
by proylea Contributor in Splunk Search 04-13-2019
0 20
0
20
darrenaefc
Hi guys, I am very new to Splunk (about 1 month or so) and I am having some trouble incorporating "set diff" into my...
by darrenaefc Engager in Splunk Search 04-13-2019
0 8
0
8
smiththebest
Have a log file that has http response codes in a particular field. I am doing timechart on it but as the 200 respons...
by smiththebest New Member in Splunk Search 04-13-2019
0 2
0
2
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Solution Authors