Splunk Search

Splunk Search
Community Activity
knutsod
Is there a way to set a Field Alias as search time, I am building a report looking at Windows Event IDs, In this case...
by knutsod Path Finder in Splunk Search 01-24-2019
2 3
2
3
florianduhme
My data looks like this: 1. System CheckpointName ProcessTimestamp ConnectionId 2. SAP Checkpo...
by florianduhme Path Finder in Splunk Search 01-24-2019
0 7
0
7
SplunkPersonal
Hello, I have a search I'm trying to speed up. I have a list of field values stored in a KV store. I use an inputloo...
by SplunkPersonal Path Finder in Splunk Search 01-24-2019
0 1
0
1
jsryu0247
Hello Multiple time logs in one timestamp example 19/01/24 10:28:51 [2019-01-24 10:28:51] DEBUG [SyslogReceiver.jav...
by jsryu0247 Engager in Splunk Search 01-24-2019
0 1
0
1
baxiani
Hi all, I monitor files on a heavy forwarder and use different sourcetypes and hosts for each file, but one common i...
by baxiani Explorer in Splunk Search 01-23-2019
0 4
0
4
darioapis
I had to have yearly report on my main dashboard. Creating it every day would be really hard, so I am wondering can I...
by darioapis Explorer in Splunk Search 01-23-2019
0 1
0
1
jl23
I'm looking to set a field value in an event based on field values in another event. Given the data: ev=1 req = 123...
by jl23 New Member in Splunk Search 01-23-2019
0 2
0
2
jdc8723
I have a JSONArray with embedded array and an optional field. I'd like to print the data into a table, with each fie...
by jdc8723 Engager in Splunk Search 01-23-2019
0 1
0
1
baegoon
I have timestamps in my data sources that are EPOCH with fractional microseconds for example: 1547528398.991103 1547...
by baegoon Explorer in Splunk Search 01-23-2019
0 1
0
1
tonymorin
Via Python REST API SDK jobs.create(search) search starts and runs, but takes like 20 minutes compared to search app ...
by tonymorin Explorer in Splunk Search 01-23-2019
0 0
0
0
jwalzerpitt
I have the following search based on F5 logs that count the HTTP POSTs by src in a five-minute bucket: index=f5 acti...
by jwalzerpitt Influencer in Splunk Search 01-23-2019
0 10
0
10
DouglasSmithers
I'm trying to calculate an average column in a chart by renaming the Total column (created with the addtotals command...
by DouglasSmithers Engager in Splunk Search 01-23-2019
0 2
0
2
mpasha
Good day, I am trying to create a search that can first search DNS for a certain domain name and after if finds a ma...
by mpasha Path Finder in Splunk Search 01-23-2019
0 0
0
0
dpanych
Hi everyone, I'm having trouble applying the following fields transformation — it's not "parsing" during search time....
by dpanych Communicator in Splunk Search 01-23-2019
0 3
0
3
rpatelnes
Hello, I've been banging my head against the wall over the last like two hours over this and figured I should just po...
by rpatelnes New Member in Splunk Search 01-23-2019
0 6
0
6
reddyavi256
I am trying to calculate difference in my two custom date time/fields and get output results in milliseconds. I trie...
by reddyavi256 Explorer in Splunk Search 01-23-2019
0 4
0
4
rakeshksingh
Hi All, Could you please help me with a query to map a lookup table with splunk events but not aware on matching f...
by rakeshksingh New Member in Splunk Search 01-23-2019
0 0
0
0
wowczarek
Hello Splunkers, I am developing dashboards in a Splunk instance which I don't manage, so I have little room for add...
by wowczarek Engager in Splunk Search 01-23-2019
1 5
1
5
robertlynch2020
Hi Is there a way to get my eval token to wait for the full result. I am setting a token time_selection_BUFFER.earli...
by robertlynch2020 Influencer in Splunk Search 01-23-2019
1 2
1
2
weidertc
I'm trying to join 2 lookup tables. To make the logic easy to read, I want the first table to be the one whose data ...
by weidertc Contributor in Splunk Search 01-23-2019
0 10
0
10
caitcait
I am need of help to build the regex to mask a password string looking similar to this Password: 22222222abc22222222...
by caitcait Explorer in Splunk Search 01-23-2019
0 10
0
10
JoshuaJohn
I have this query that works in all regex assist sites but is too greedy for my Splunk Environment. I am unable to ad...
by JoshuaJohn Contributor in Splunk Search 01-23-2019
0 3
0
3
weidertc
Is there any way to use a wildcard as a value to a variable? | inputlookup Functionalities.csv | search AppNo=$app$ ...
by weidertc Contributor in Splunk Search 01-23-2019
0 15
0
15
EmEdwards
I have a table that has various columns of Totals. However, the CurrentYear can represent different information. I o...
by EmEdwards Path Finder in Splunk Search 01-23-2019
0 1
0
1
ticbos
I have the Sophos XG forwarding logs to Splunk. How do i search for users who logged into Sophos XG in Splunk.
by ticbos New Member in Splunk Search 01-23-2019
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors