Splunk Search

Splunk Search
Community Activity
sanjds
i have look table with known errors and planning to create job which runs on cron schedule and provide me list of er...
by sanjds New Member in Splunk Search 03-06-2019
0 1
0
1
jip31
Hi, With the code below, I count the event number by source for a sourcetype. But different sources use the same so...
by jip31 Motivator in Splunk Search 03-06-2019
0 10
0
10
mishaaaaaaaaaa
Hi splunk comunity! How can i get specific value from latest event and earliest event during the period i set? I ne...
by mishaaaaaaaaaa Explorer in Splunk Search 03-06-2019
0 0
0
0
mdmaala
hi! Under the field Username, I have two lists, Machine1 and Machine2 I want to split this into two separate column...
by mdmaala Communicator in Splunk Search 03-06-2019
0 3
0
3
johann2017
Hello. How would I write a search to show a computer that has been authenticating to multiple machines. For example, ...
by johann2017 Explorer in Splunk Search 03-06-2019
0 3
0
3
mkarimi17
I have a path (and a variable file_path) that looks like this: C:\\\\Program Files\\\\theapp\\\\the app\\\\Tools\\\\...
by mkarimi17 Path Finder in Splunk Search 03-06-2019
0 8
0
8
JakeInfoSec
So I have a search that runs hourly over a lookup table which I have created that includes IP, ticket number, date_ad...
by JakeInfoSec Explorer in Splunk Search 03-06-2019
0 4
0
4
ryangrobbel
Hi All, I currently am pulling in data from an application and we are looking extract a single line that the event o...
by ryangrobbel Explorer in Splunk Search 03-05-2019
0 3
0
3
gkumarashanmuga
How do you check the number of users who are currently using the system(Splunk web UI login) over the last month?
by gkumarashanmuga Explorer in Splunk Search 03-05-2019
0 4
0
4
rpradeep
We use Splunk for many of our project dashboards & want to see if I can use the same setup to host a Vacation Tracker...
by rpradeep Path Finder in Splunk Search 03-05-2019
1 18
1
18
ramesh12345
Hi, index="os" sourcetype="Service" CaseNumber=* status=* assignment_group=* |dedup _time,CaseNumber,assignment_gr...
by ramesh12345 Explorer in Splunk Search 03-05-2019
0 1
0
1
jwhughes58
I have this search that I'm trying to break down | tstats `summariesonly` values(Web.url) as url values(Web.src) as ...
by jwhughes58 Contributor in Splunk Search 03-05-2019
0 3
0
3
veerendra_modi
I have a stats result with the count field. I want to compare if this count is greater than another field. I.e., a th...
by veerendra_modi Loves-to-Learn in Splunk Search 03-05-2019
0 3
0
3
MABurberry
Hi Guys, I hope someone can help me? I'm looking to search through several port ranges and match against one or mul...
by MABurberry Engager in Splunk Search 03-05-2019
0 2
0
2
lucy2019
I have mydates.csv file uploaded to Splunk lookups. It looks like this: Date 1/2/2019 2/5/2019 2/16/2019 I need to ...
by lucy2019 Explorer in Splunk Search 03-05-2019
0 12
0
12
mdmaala
Hi! I am currently working on a project that required to show a timeline duration of a machine runtime, downtime, er...
by mdmaala Communicator in Splunk Search 03-05-2019
0 1
0
1
baklimek
I'm trying to connect the sum of measurements from a certain process and connect them to workorders by the times the ...
by baklimek New Member in Splunk Search 03-05-2019
0 8
0
8
robprice797
org_name="myOrg" index="myIndex" app_name="myAppName" space_name="Staging" | rex field=msg "stack:(?<.*java\.lang.*Ex...
by robprice797 New Member in Splunk Search 03-05-2019
0 2
0
2
rwarnerii
I have created a Month over Month dashboard that will eventually become a report that is sent on the 1st day of the m...
by rwarnerii New Member in Splunk Search 03-05-2019
0 2
0
2
christoffertoft
Hi, This is basically a question of when automatic lookups are applied to data. I have a field url i need to sed a...
by christoffertoft Communicator in Splunk Search 03-05-2019
0 2
0
2
ashleyherbert
I'm looking for a variable that can be used to replace the index name for the following configs in the indexes.conf f...
by ashleyherbert Communicator in Splunk Search 03-05-2019
1 5
1
5
kahless1985
The title says it all. I'm looking for a way to remove fields from searches and subsearches. I know I can hide fields...
by kahless1985 Explorer in Splunk Search 03-05-2019
0 3
0
3
simpkins1958
Have a field in our HEC input that is larger the 10,000 characters. When searching the data input from HEC the field ...
by simpkins1958 Contributor in Splunk Search 03-05-2019
0 6
0
6
changj
Data: message: ================> Request Details: [requestId:123122313-3453-1122-1112222] [requestMethod = GE...
by changj New Member in Splunk Search 03-05-2019
0 3
0
3
jmorri6
Given a string: (path=/myPath/123/endpoint,method=GET,accept=text/plain;version=0.0.4;q=1,*/*;q=0.1,content-type=nul...
by jmorri6 Engager in Splunk Search 03-05-2019
0 2
0
2
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...