Splunk Search

Splunk Search
Community Activity
rashid47010
I want to use the eval function with cidrmatch function like 1- who to mention multip subnets in x field against cid...
by rashid47010 Communicator in Splunk Search 03-10-2019
0 1
0
1
mdmaala
in my table, I have a field named Username, and it has two values: Machine 1 and 2. I only want to show Machine1 only...
by mdmaala Communicator in Splunk Search 03-10-2019
0 0
0
0
tej8
I have two fields "body.response.successfulItemsCount" & "body.successfulItemsCount". I need sum of total of these tw...
by tej8 New Member in Splunk Search 03-10-2019
0 1
0
1
shaikbavaji
sourceType="source_log" | rex field=_raw .... ........ Expected output : Service_call Avf for 03/04 avg ...
by shaikbavaji New Member in Splunk Search 03-09-2019
0 5
0
5
koshyk
hi, We have a SPL which emits hostname as a single value, but this needs to be checked against a valid list of hostna...
by koshyk Super Champion in Splunk Search 03-09-2019
0 2
0
2
Mustang1964s
I have the following search. index=ironstream IFCID=1 LUWID_LUNAME=DBTP | rex "QWSAPROC_0001\":\"(?P<proc...
by Mustang1964s New Member in Splunk Search 03-09-2019
0 2
0
2
sabaKhadivi
As I setting up a splunk serach head clustering, and migrate data from single serach head to new cluster, I cant see ...
by sabaKhadivi Path Finder in Splunk Search 03-09-2019
0 3
0
3
pench2k19
Hi Guys , I would like to extract the values that are highlited below into different fields. Can you please help me ...
by pench2k19 Explorer in Splunk Search 03-09-2019
0 4
0
4
russell120
Hi, When I run index=wineventlog earliest=-5s@s latest=now the results are 35k events. When I run sourcetype=mySour...
by russell120 Communicator in Splunk Search 03-09-2019
0 2
0
2
mendesjo
Can anyone suggest how you query IronPort logs? When I query mail logs on the ironport itself, say for an email from ...
by mendesjo Path Finder in Splunk Search 03-09-2019
1 9
1
9
braicu
Hello, Please help me with this. I have result of two columns: Tag-Key Tag-Value A...
by braicu New Member in Splunk Search 03-09-2019
0 7
0
7
njohnson7
Hallo, I am trying to find the total number of different types of events per month(chronologically) and the sum of ...
by njohnson7 Path Finder in Splunk Search 03-09-2019
0 12
0
12
stike100
I'm having a tough time figuring this one out for some reason. The datasource I am using contains multiple records...
by stike100 New Member in Splunk Search 03-08-2019
0 2
0
2
mpasha
Hi, This might be trivial question, but I am having a hard time to figure it out. Any help is greatly appreciated. ...
by mpasha Path Finder in Splunk Search 03-08-2019
0 2
0
2
ahogbin
Hello, I am trying (rather unsuccessfully) to extract a number of varying length form a sting. The constants are 0s ...
by ahogbin Communicator in Splunk Search 03-08-2019
0 11
0
11
magilbert1
I would like to add a new field at index-time that will be visible in the list of events. In the same way as Host, so...
by magilbert1 Explorer in Splunk Search 03-08-2019
0 8
0
8
samhodgson
I have added Security Essentials on my indexer and the Splunk_TA_windows app on the forwarders however when i run the...
by samhodgson Path Finder in Splunk Search 03-08-2019
1 5
1
5
tulusoy
Hi, I have a search with regex ERROR * | rex ".*?(?(?:\w+\.)+\w*?Exception).*" | stats sparkline count by ex...
by tulusoy New Member in Splunk Search 03-08-2019
0 5
0
5
russell120
Hi, Can I run a search with two or more indexes and specify a different time range in each one? For example, would ...
by russell120 Communicator in Splunk Search 03-08-2019
1 11
1
11
magun
Scenario: In a way, the local admin user can be retrieved, the computer to remove the domain, and without the domain ...
by magun New Member in Splunk Search 03-08-2019
0 7
0
7
uppukumar
Hi all, I am new to splunk Following is the information: Column1 Column2 column3 f...
by uppukumar Explorer in Splunk Search 03-08-2019
0 2
0
2
emipintus
Hi, I have a search which returns a list of records, some of them have a duplicate Value. Here's an example of the ou...
by emipintus Explorer in Splunk Search 03-08-2019
0 7
0
7
chirsf
I've seen a lot about not using join subsearches, how it's slow, etc etc. Which proves to be true in practice. What ...
by chirsf Explorer in Splunk Search 03-08-2019
0 2
0
2
evinasco
Hi team i have been working a new project with banking sector where they are using the Core Banking T24. Does anyon...
by evinasco Communicator in Splunk Search 03-08-2019
1 3
1
3
mdmaala
hi! I want to create a stacked bar chart like in a timline series like this |[----RUN TIME----]|[----IDLE TIME----]|...
by mdmaala Communicator in Splunk Search 03-07-2019
0 2
0
2
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...