Splunk Search

Splunk Search
Community Activity
amith7
Hi I am trying to extract various fields from below entry in splunk. I executed the below splunk query : index=test...
by amith7 New Member in Splunk Search 02-28-2019
0 0
0
0
Deepz2612
I wanted to extract a field to capture the data before the question mark as below. api_call "Get \search\ip\6789\?=n...
by Deepz2612 Explorer in Splunk Search 02-28-2019
0 6
0
6
alc2019
Hi Experts, How can I get events on a numeric field where a 7 digit number begins with 11? I tried with ...my searc...
by alc2019 New Member in Splunk Search 02-28-2019
0 6
0
6
solarboyz1
I am trying to create a search against our LDAP strategy to show the capabilities, indexes, and users assigned to eac...
by solarboyz1 Builder in Splunk Search 02-28-2019
0 0
0
0
ssatti
Greetings all, I want to monitor an "httpd" process for a Linux Machine, and if the process is down or not running, ...
by ssatti New Member in Splunk Search 02-28-2019
0 4
0
4
theouhuios
So IP to a subnet CIDR match has always worked in Splunk. No issues there. BUT a request came where we need to do a s...
by theouhuios Motivator in Splunk Search 02-28-2019
1 0
1
0
mahenders
How do you calculate application availability in minutes based on a status code? I want to determine the outage if 50...
by mahenders New Member in Splunk Search 02-28-2019
0 0
0
0
stanwin
Hi all, I am trying to run a search that returns one row of results over a long historical time window on a per hour...
by stanwin Contributor in Splunk Search 02-28-2019
0 7
0
7
wvalente
Guys, I need to see which forwarders do not send events in a period of 3 hours. For example: if a forwarder does no...
by wvalente Explorer in Splunk Search 02-28-2019
0 5
0
5
hylam
Choropleth map applies different colors depending on the range of the "count" field. How can I use another field? If ...
by hylam Contributor in Splunk Search 02-28-2019
1 5
1
5
AbubakarShahid
Hi all, I was wondering how can i write a Splunk rex to parse out the IP between two words. for example <IpAd...
by AbubakarShahid New Member in Splunk Search 02-28-2019
0 2
0
2
ramesh12345
Hi, Test-20190212-0912 from this string. I want to retrieve date like this 2019-02-12 How do I write this in regex?
by ramesh12345 Explorer in Splunk Search 02-28-2019
0 21
0
21
karthi25
I have a created a splunk alert when there is a failure occurs. I have query as follows: index=* source=*** |spath p...
by karthi25 Path Finder in Splunk Search 02-28-2019
0 7
0
7
surekhasplunk
I just want to color the column headers and not the cells of my dashboard tables
by surekhasplunk Communicator in Splunk Search 02-28-2019
1 14
1
14
evetsleep
I have a Splunk query that parses out some Windows event log data. One of the things that I examine is the user name...
by evetsleep New Member in Splunk Search 02-28-2019
0 4
0
4
tljohnson
Hi all, I've been banging my head against the wall trying to get this to work. What I'm trying to do is to use a lo...
by tljohnson Engager in Splunk Search 02-28-2019
2 2
2
2
mishaaaaaaaaaa
Hi splunk comuniti! I have a job in splunk. In "Edit Search" i have two fields - Earliest time and Latest time. How ...
by mishaaaaaaaaaa Explorer in Splunk Search 02-28-2019
0 4
0
4
jip31
Hi, I use the search below in order to count event number. I want to do the same calculation, but in percent event...
by jip31 Motivator in Splunk Search 02-28-2019
0 7
0
7
MattibergB
Hi all, We are trying to do the following: At index time we want to use 4 regex TRANSFORMS to store values in two f...
by MattibergB Path Finder in Splunk Search 02-27-2019
0 4
0
4
fisuser1
I'm looking to send junk data to nullque on our heavy forwarder and I only want to key in on specific events in the r...
by fisuser1 Contributor in Splunk Search 02-27-2019
0 5
0
5
dorgra
A schedule task on a Windows server runs a CHKDSK /SCAN on every logical drive. The resultant Message field looks lik...
by dorgra Path Finder in Splunk Search 02-27-2019
0 4
0
4
clintla
What would be the easiest one line solution to remove special characters from a token? I'm taking a text input (mac ...
by clintla Contributor in Splunk Search 02-27-2019
0 6
0
6
henriq_c
Hello, I am doing: case(strptime($latest$,"%Y/%m/%d %H:%M:%S")-strptime($earliest$,"%Y/%m/%d %H:%M:%S")<518400,...
by henriq_c Explorer in Splunk Search 02-27-2019
0 1
0
1
pgbr7
Hello guys, I have 2 sourcetype, the sourcetype A have the fields [ IP , hostname , source_mac ] , the sourcetype B ...
by pgbr7 Explorer in Splunk Search 02-27-2019
0 8
0
8
cquinney
Greetings I'm using the following query over 24hrs. | initial search | timechart useother=f span=1h avg(field1) by ...
by cquinney Communicator in Splunk Search 02-27-2019
0 9
0
9
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...