Splunk Search

Splunk Search
Community Activity
Ash1
|mstats sum(Transactions) as Transaction_count where index=metrics-logs application=login services IN(get, put, delet...
by Ash1 Communicator in Splunk Search 04-02-2024
0 5
0
5
sle
<search> <query>index="ourIndex" sourcetype=$stype$ABC AND Is_Service_Account="True" OR Is_Service_Account="False" ...
by sle Engager in Splunk Search 04-02-2024
0 2
0
2
kreddykotla
https://www.nike.com/in/t/air-max-90-lv8-shoes-5KhTdP/FD4328-102https://www.nike.com/in/t/air-max-dn-shoes-FtLNfm/DV3...
by kreddykotla New Member in Splunk Search 04-02-2024
0 1
0
1
psomeshwar
So, I have two indexes and sourcetypes with the following fields: index1 and sourcetype1: aip = 34.465.45.234 AppVend...
by psomeshwar Path Finder in Splunk Search 04-01-2024
0 8
0
8
jkat54
How to detect CVE-2024-3094 with Splunk?
by SplunkTrust SplunkTrust in Splunk Search 04-01-2024
0 3
0
3
NAGA4
Good day All, We have enabled the searches as durable searches. In our environment due to any one or other activity t...
by NAGA4 Engager in Splunk Search 04-01-2024
0 0
0
0
Muthu_Vinith
Hi Experts, I have a list of dates in the field called my_date like below:451234512745130How can I convert this? Than...
by Muthu_Vinith Path Finder in Splunk Search 04-01-2024
0 14
0
14
khsewell
Hi!,This is a contrived example, but could you help me understand why this completes (and functions as expected): | m...
by khsewell Engager in Splunk Search 04-01-2024
0 2
0
2
alexspunkshell
I have 10 indexes starts with "ep_winevt_ms" . So i am using * here "index=ep_winevt_ms*".But while taking the | stat...
by alexspunkshell Contributor in Splunk Search 04-01-2024
0 3
0
3
Thulasiraman
Please help with splunk query to get pass and fail count in table format from below jsonarray| Group   | Pass | Fail ...
by Thulasiraman Explorer in Splunk Search 03-30-2024
0 1
0
1
splunkbeginner1
I'm attempting to compute the total number of API calls from our backend engine. Initially, I process API identificat...
by splunkbeginner1 Engager in Splunk Search 03-30-2024
0 8
0
8
gauravu_14
All,I am looking for a solution to identify the hosts that have stopped reporting to Splunk using lookup table. Howev...
by gauravu_14 Explorer in Splunk Search 03-30-2024
0 3
0
3
taijusoup64
I'm trying to calculate the data throughput for a cloud computing solution that will be charging based on outgoing da...
by taijusoup64 Loves-to-Learn Lots in Splunk Search 03-30-2024
0 3
0
3
RS
Hi,I have following log data that are in splunk. Below is example data taken from splunk:2024-02-04T00:15:15.209Z [jf...
by RS Engager in Splunk Search 03-30-2024
0 7
0
7
MVK1
Hello,I have a splunk query returning my search results  index="demo1" source="demo2" | rex field=_raw "id_num \{ dat...
by MVK1 Path Finder in Splunk Search 03-29-2024
0 14
0
14
Suara
Hello all ! Can anyone help me in editing the below SPL so it can only list the _key - value paris for the entities ?...
by Suara Explorer in Splunk Search 03-29-2024
0 2
0
2
ClubMed
From the Subject Title, what I mean is it will increase the row count and decrease the column count - that is my inte...
by ClubMed Path Finder in Splunk Search 03-29-2024
0 2
0
2
rajesh143rs
 I need help with a splunk query to return events where an array of object contains certain value for a key in all th...
by rajesh143rs Engager in Splunk Search 03-28-2024
0 5
0
5
Renunaren
Hi Team,The below is the event which we have received into the splunk,Dataframe row : {"_c0":{"0":"{","1":" \"0\": {"...
by Renunaren Loves-to-Learn Everything in Splunk Search 03-28-2024
0 7
0
7
mahesh27
we are trying to set up a cron schedule on alert to run only on weekends(sat and sun) at 6am, 12pm, 8pm , 10pmi tired...
by mahesh27 Communicator in Splunk Search 03-28-2024
0 3
0
3
asingla
I need to use fillnull command but I don't have the exact field names before hand. All my fields starts (which I want...
by asingla Communicator in Splunk Search 03-28-2024
1 3
1
3
Renunaren
  Dataframe row : {"_c0":{"0":"{","1":" \"0\": {","2":" \"jobname\": \"A001_GVE_ADHOC_AUDIT\"","3":" \"status\": \"EN...
by Renunaren Loves-to-Learn Everything in Splunk Search 03-28-2024
0 2
0
2
riley_lewis
When I do this search: index="mydata" | eval mymean=avg(floatnumbers) | table floatnumbers,mymean mymean just mimics ...
by riley_lewis Loves-to-Learn Lots in Splunk Search 03-28-2024
0 1
0
1
barosan007
Hello, This question has probably been asked and answered, but I just can't seem to find a best solution. So, in the ...
by barosan007 Explorer in Splunk Search 03-28-2024
0 4
0
4
srinivas_gowda
Hello team, I am facing an issue with multiple events getting merged as a single event in tier 3. I do not have this ...
by srinivas_gowda Path Finder in Splunk Search 03-28-2024
0 1
0
1
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...