Splunk Search

Splunk Search
Community Activity
ramprakash
Hi Everyone...I want to put restrictions on users search as presently users can search for as long as they like. This...
by ramprakash Explorer in Splunk Search 02-09-2019
0 8
0
8
mbyreddy03
Hi All Below are my sample events am trying to use regex and extract Time to run brinson for all days in Parallel a...
by mbyreddy03 New Member in Splunk Search 02-09-2019
0 9
0
9
approachct
Having trouble with the below regex generated from the field extractor application \w+:\\w+\\w+\(?P\w+\\w+) When add...
by approachct Path Finder in Splunk Search 02-09-2019
1 8
1
8
dmanojbaba
There are already several Splunk Answers around mvexpand multiple multi-value fields. https://answers.splunk.com/ans...
by dmanojbaba Explorer in Splunk Search 02-09-2019
0 1
0
1
mwirth
With a simple systemd unit file you can tell systemd how to start and stop a Splunk instance, but if the Splunk insta...
by mwirth Explorer in Splunk Search 02-08-2019
5 5
5
5
vrmandadi
Below is the sample event 01/15/2019 03:49:15 PM LogName=Security SourceName=Microsoft Windows security auditing. Ev...
by vrmandadi Builder in Splunk Search 02-08-2019
0 8
0
8
nqjpm
Have a working query, but the boss has now asked me to timechart for SuccessRateByPlatformPCT per week and I am havin...
by nqjpm Path Finder in Splunk Search 02-08-2019
0 5
0
5
bveltre
Hello, I am trying to send some records to Splunk that are incorrectly getting written. This is what the message lo...
by bveltre New Member in Splunk Search 02-08-2019
0 0
0
0
limalbert
If I'm trying to regex InteractionID and msg below, how do I get the results for all InteractionID and msg within the...
by limalbert Path Finder in Splunk Search 02-08-2019
0 2
0
2
maryamchar
Hello, I have a lookup table for all the source types. I'm trying to use stats or tstats to show all the source typ...
by maryamchar Explorer in Splunk Search 02-08-2019
0 1
0
1
jduganPaychex
If searches are queuing, can searches from particular roles/users be prioritized over others to run next, regardless ...
by jduganPaychex Engager in Splunk Search 02-08-2019
2 0
2
0
urasplunkronbur
I'm trying to determine which Windows workstations a user is currently logged in to by: Examining logs from our Doma...
by urasplunkronbur New Member in Splunk Search 02-08-2019
0 3
0
3
blindfire_bandi
Hello there from someone in healthcare it industry. I'm working with multiple conditions, and I want to make sure m...
by blindfire_bandi Explorer in Splunk Search 02-08-2019
0 2
0
2
astatrial
Hello I have a query that create a field with a value i can't fully understand : eval earliestQual=match("-24h@h","...
by astatrial Contributor in Splunk Search 02-08-2019
0 10
0
10
bntdumas
Hello, I have several hosts sending logs to Splunk. These logs depends on the version of the software creating these...
by bntdumas Engager in Splunk Search 02-08-2019
0 5
0
5
jephillips
I'm trying to run the below searches and get the subtracted value from them. However, the eval command is not giving ...
by jephillips Explorer in Splunk Search 02-08-2019
0 5
0
5
AlexeySh
Hello, We use an ES ‘Excessive Failed Logins’ correlation search: | tstats summariesonly=true allow_old_summaries=t...
by AlexeySh Communicator in Splunk Search 02-08-2019
0 6
0
6
splunker1981
Hello folks, Trying to figure out how to go about joining 2 fields with a dash but only if they don't have the same...
by splunker1981 Path Finder in Splunk Search 02-08-2019
0 1
0
1
UMDTERPS
We are using a lookuptable with CSV's for reports. However, the _time field has the following format for time: 2015-...
by UMDTERPS Communicator in Splunk Search 02-08-2019
0 4
0
4
ips_mandar
Hi everyone, Can someone tell me what I'm suppose to edit in my datetime.xml file for my custom date and time to be r...
by ips_mandar Builder in Splunk Search 02-08-2019
0 17
0
17
jfriedman_ofigl
My vulnerability data looks like this: Machine MachineType VulnCode Impact ------- ----------- -------- ------...
by jfriedman_ofigl Explorer in Splunk Search 02-08-2019
0 4
0
4
Shashank_87
Hi, I am working on a query where I have to match the responseCode from the search to the responseCode in a lookup ...
by Shashank_87 Explorer in Splunk Search 02-08-2019
0 3
0
3
damucka
Hello, I have an alert which selects from the database and whenever entries come back, the alert is triggered. Now, ...
by damucka Builder in Splunk Search 02-08-2019
0 3
0
3
Deepz2612
Hi, Why is that a particular user in my team is unable to see his name on the top in Splunk UI like anyother in my te...
by Deepz2612 Explorer in Splunk Search 02-08-2019
0 4
0
4
vaibhavvijay9
Hi All, I want to display only results which are present in a given list (please see below) : ....... | xmlkv | sta...
by vaibhavvijay9 New Member in Splunk Search 02-07-2019
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...