Splunk Search

Splunk Search
Community Activity
MattibergB
Hi all, We are trying to do the following: At index time we want to use 4 regex TRANSFORMS to store values in two f...
by MattibergB Path Finder in Splunk Search 02-27-2019
0 4
0
4
fisuser1
I'm looking to send junk data to nullque on our heavy forwarder and I only want to key in on specific events in the r...
by fisuser1 Contributor in Splunk Search 02-27-2019
0 5
0
5
dorgra
A schedule task on a Windows server runs a CHKDSK /SCAN on every logical drive. The resultant Message field looks lik...
by dorgra Path Finder in Splunk Search 02-27-2019
0 4
0
4
clintla
What would be the easiest one line solution to remove special characters from a token? I'm taking a text input (mac ...
by clintla Contributor in Splunk Search 02-27-2019
0 6
0
6
henriq_c
Hello, I am doing: case(strptime($latest$,"%Y/%m/%d %H:%M:%S")-strptime($earliest$,"%Y/%m/%d %H:%M:%S")<518400,...
by henriq_c Explorer in Splunk Search 02-27-2019
0 1
0
1
pgbr7
Hello guys, I have 2 sourcetype, the sourcetype A have the fields [ IP , hostname , source_mac ] , the sourcetype B ...
by pgbr7 Explorer in Splunk Search 02-27-2019
0 8
0
8
cquinney
Greetings I'm using the following query over 24hrs. | initial search | timechart useother=f span=1h avg(field1) by ...
by cquinney Communicator in Splunk Search 02-27-2019
0 9
0
9
compguy
I have a log: "TOTAL NUMBER OF RECORDS IS:0" I need to Query it in a way that it finds a log message if the number o...
by compguy New Member in Splunk Search 02-27-2019
0 4
0
4
skribble5
Hi team, I have a query about sub-queries. I've searched this forum for a while and tried a few different things but...
by skribble5 Explorer in Splunk Search 02-27-2019
0 9
0
9
Sp3ctre1
Is there such thing to display a minspan for transaction... Trying to looking for users from building A to Buildin...
by Sp3ctre1 New Member in Splunk Search 02-27-2019
0 1
0
1
ajith_sukumaran
Hi, I have two lookup tables lookup1: RealName, username Smith, J ( LDN), smithj Andy, H (LDN),andyh Tan, Y ...
by ajith_sukumaran Explorer in Splunk Search 02-27-2019
0 5
0
5
joesrepsolc
I figured out how to use the dedup command by the user (see example below) but I still want to get the latest record ...
by joesrepsolc Communicator in Splunk Search 02-27-2019
1 18
1
18
jip31
Hi I have something strange when I execute the search below, I have 47 events on a one week slot time eventtype="App...
by jip31 Motivator in Splunk Search 02-27-2019
0 4
0
4
ramesh12345
Hi, i have a CSV file that contains a few persons names and teamname(column names is "name" and "Team"). The team na...
by ramesh12345 Explorer in Splunk Search 02-27-2019
0 1
0
1
gowtham495
i have a lookup hostlist.csv which have list of host names and other metrics related to it. i need to filter out eac...
by gowtham495 Path Finder in Splunk Search 02-26-2019
1 5
1
5
asplunk789
I have a requirement to use lookups instead of queries in Splunk Dashboards. How can I get them and how to convert t...
by asplunk789 Loves-to-Learn Everything in Splunk Search 02-26-2019
0 7
0
7
mhale1982
Is it possible, and if so, how would I, filter specific terms but only for a certain time range within a broader sear...
by mhale1982 Path Finder in Splunk Search 02-26-2019
0 1
0
1
beetlegeuse
I am trying to put together a search that will incorporate two fields used in a CSV file ("RoleInstance" and "Environ...
by beetlegeuse Path Finder in Splunk Search 02-26-2019
0 5
0
5
eoszej123
I am attempting to merge two datasources to find every transaction (not to be confused with a Splunk transaction!) th...
by eoszej123 Engager in Splunk Search 02-26-2019
0 0
0
0
mbasharat
Hi, I have a report about hosts and vulnerabilities. It has about 30k hosts with list of vulnerabilities they are af...
by mbasharat Builder in Splunk Search 02-26-2019
0 9
0
9
tdarrow
I am relatively new to Splunk so please forgive my naivety. I have been tasked with calculating the session length o...
by tdarrow New Member in Splunk Search 02-26-2019
0 1
0
1
jlundtristate
Here is the example in the Splunk documentation: specific.server | stats dc(userID) as totalUsers | appendcols [ sea...
by jlundtristate Engager in Splunk Search 02-26-2019
0 3
0
3
dpoupon
Hello, I ingest in Splunk enterprise the following log file about end user sessions (only one record is sent at the...
by dpoupon New Member in Splunk Search 02-26-2019
0 0
0
0
deepusoundar
I have a lookup(search_query.csv) with data as below. Name Subcategory Query Get Vehicle index=abc I ...
by deepusoundar Engager in Splunk Search 02-26-2019
0 9
0
9
mataharry
I want to do a " | stat count by host " or a " | timechart span=1d count by host". I need the detail for each host. ...
by mataharry Communicator in Splunk Search 02-26-2019
3 6
3
6
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors