Splunk Search

Splunk Search
Community Activity
kiamco
Hello, I have a question about the use of the foreach command. I have a good idea what the foreach command can do for...
by kiamco Path Finder in Splunk Search 02-11-2019
0 2
0
2
Carolina
Hi, I need to create or design the following table. Is posible in Splunk Enterprise?
by Carolina Engager in Splunk Search 02-11-2019
0 4
0
4
richardphung
so, I'm working on implementing this: https://answers.splunk.com/answers/588964/how-can-we-make-multiple-mac-address...
by richardphung Communicator in Splunk Search 02-11-2019
0 5
0
5
dbashyam
Hi, I have the following text to parse. I want to break when I encounter the **** date ***. I tried the following, ...
by dbashyam Explorer in Splunk Search 02-10-2019
0 3
0
3
ddrillic
I have the following query - index=_internal host = <host1> OR host = <host2> OR host = <host3> | ta...
by ddrillic Ultra Champion in Splunk Search 02-10-2019
1 5
1
5
jainkul123
How can I trim the date timestamp from _raw. My _raw is as follows: [1/13/19 10:18:20:577 GMT] 00000097 LogOut O IN...
by jainkul123 Explorer in Splunk Search 02-10-2019
0 5
0
5
vb1612
I have a date field in my feed as "2/15/2019" , want to compare this with upcoming friday date value in search. pleas...
by vb1612 New Member in Splunk Search 02-10-2019
0 1
0
1
babukumarreddy
actually iam new to splunk in my logs starttime and endtime is there need to calculate duration starttime endtime |0...
by babukumarreddy Loves-to-Learn Lots in Splunk Search 02-10-2019
0 3
0
3
babukumarreddy
how to calculate starttime and Endtime duration |08-feb-2019 01:30:18|08-feb-2019 01:30:28
by babukumarreddy Loves-to-Learn Lots in Splunk Search 02-10-2019
0 3
0
3
damucka
Hello, Is it possible to view the configuration files / parameters, e.g. limits.conf using the search? I do not have...
by damucka Builder in Splunk Search 02-09-2019
1 2
1
2
ramprakash
Hi Everyone...I want to put restrictions on users search as presently users can search for as long as they like. This...
by ramprakash Explorer in Splunk Search 02-09-2019
0 8
0
8
mbyreddy03
Hi All Below are my sample events am trying to use regex and extract Time to run brinson for all days in Parallel a...
by mbyreddy03 New Member in Splunk Search 02-09-2019
0 9
0
9
approachct
Having trouble with the below regex generated from the field extractor application \w+:\\w+\\w+\(?P\w+\\w+) When add...
by approachct Path Finder in Splunk Search 02-09-2019
1 8
1
8
dmanojbaba
There are already several Splunk Answers around mvexpand multiple multi-value fields. https://answers.splunk.com/ans...
by dmanojbaba Explorer in Splunk Search 02-09-2019
0 1
0
1
mwirth
With a simple systemd unit file you can tell systemd how to start and stop a Splunk instance, but if the Splunk insta...
by mwirth Explorer in Splunk Search 02-08-2019
5 5
5
5
vrmandadi
Below is the sample event 01/15/2019 03:49:15 PM LogName=Security SourceName=Microsoft Windows security auditing. Ev...
by vrmandadi Builder in Splunk Search 02-08-2019
0 8
0
8
nqjpm
Have a working query, but the boss has now asked me to timechart for SuccessRateByPlatformPCT per week and I am havin...
by nqjpm Path Finder in Splunk Search 02-08-2019
0 5
0
5
bveltre
Hello, I am trying to send some records to Splunk that are incorrectly getting written. This is what the message lo...
by bveltre New Member in Splunk Search 02-08-2019
0 0
0
0
limalbert
If I'm trying to regex InteractionID and msg below, how do I get the results for all InteractionID and msg within the...
by limalbert Path Finder in Splunk Search 02-08-2019
0 2
0
2
maryamchar
Hello, I have a lookup table for all the source types. I'm trying to use stats or tstats to show all the source typ...
by maryamchar Explorer in Splunk Search 02-08-2019
0 1
0
1
jduganPaychex
If searches are queuing, can searches from particular roles/users be prioritized over others to run next, regardless ...
by jduganPaychex Engager in Splunk Search 02-08-2019
2 0
2
0
urasplunkronbur
I'm trying to determine which Windows workstations a user is currently logged in to by: Examining logs from our Doma...
by urasplunkronbur New Member in Splunk Search 02-08-2019
0 3
0
3
blindfire_bandi
Hello there from someone in healthcare it industry. I'm working with multiple conditions, and I want to make sure m...
by blindfire_bandi Explorer in Splunk Search 02-08-2019
0 2
0
2
astatrial
Hello I have a query that create a field with a value i can't fully understand : eval earliestQual=match("-24h@h","...
by astatrial Contributor in Splunk Search 02-08-2019
0 10
0
10
bntdumas
Hello, I have several hosts sending logs to Splunk. These logs depends on the version of the software creating these...
by bntdumas Engager in Splunk Search 02-08-2019
0 5
0
5
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...