Splunk Search

Splunk Search
Community Activity
splunk219783
We've been using services.sh to get service status on systemd boxes without issue. But when we started looking at ol...
by splunk219783 Path Finder in Splunk Search 01-22-2019
0 0
0
0
ebkeys94
Hi, I am fairly new to regex and cannot figure out how to capture certain strings. Here is an example of the string...
by ebkeys94 Engager in Splunk Search 01-22-2019
0 4
0
4
magilbert1
I have a log file date which is split on different fields ( date_hour, date_second, date_hour etc...) Can i decide t...
by magilbert1 Explorer in Splunk Search 01-22-2019
0 3
0
3
dstuder
When I do a drill down in my dashboard the search box in the new windows get's rid of all the line breaks in my SPL s...
by dstuder Communicator in Splunk Search 01-22-2019
1 1
1
1
odeddror
Hi there, Can someone help me with search around these subjects (I'm using DBX output to SQL) I'm new to this langua...
by odeddror New Member in Splunk Search 01-22-2019
0 1
0
1
muzicman61
So I've read several previous questions on how to get the time difference between events, and they all seem to revolv...
by muzicman61 New Member in Splunk Search 01-22-2019
0 9
0
9
JoshuaJohn
So I tested this regex with regex101 and it seems to be working but Splunk doesn't seem to like it. Any ideas? | rex...
by JoshuaJohn Contributor in Splunk Search 01-22-2019
0 10
0
10
AaronMoorcroft
Hey Guys, I seem to be struggling to pull out some what I thought would be simple searches. An example result coul...
by AaronMoorcroft Communicator in Splunk Search 01-22-2019
0 9
0
9
MaryvonneMB
Hi all, I have several events like this: Field_A // Field_B // Field_C A // 1 // z A // 2 // z B // 3 // y B // ...
by MaryvonneMB Path Finder in Splunk Search 01-22-2019
0 2
0
2
jaj
What columns can I somehow override and specify which ones are totaled up? I only want the count to be totaled but ot...
by jaj Path Finder in Splunk Search 01-22-2019
0 2
0
2
jaj
How can I get trendline data to show up on a single visualization using the following query? The results come back fi...
by jaj Path Finder in Splunk Search 01-22-2019
0 2
0
2
tgdvopab
Hi all, I want to get the average from a value, group this by cluster and hostname and show the value in a timechart...
by tgdvopab Path Finder in Splunk Search 01-22-2019
0 3
0
3
splunkwiz
I want to display text in the middle of the panel that is based on the value of a status code or its percentage. I'v...
by splunkwiz New Member in Splunk Search 01-22-2019
0 0
0
0
scotmatson
I need to display trending IP events over the course of 90 days with each day being a sum of the events. My original...
by scotmatson Explorer in Splunk Search 01-22-2019
0 0
0
0
dojiepreji
I need to extract the first 4 words in a field with sample data like this, "The team performs checks for the follow...
by dojiepreji Path Finder in Splunk Search 01-22-2019
0 3
0
3
hkchew
Hi all, I have used back the old index & sourcetype but i have re-created new field names for my dashboard. when usi...
by hkchew New Member in Splunk Search 01-22-2019
0 4
0
4
baroudiem
Hello splunkers, I tried to submit a new case but unfortunately i got this error : "It appears you do not have an ...
by baroudiem New Member in Splunk Search 01-22-2019
0 6
0
6
adabud6267
Hello, I have a CSV file containing two columns URL and IP. I'm using it to retrieve only events were a match is fou...
by adabud6267 Explorer in Splunk Search 01-22-2019
0 0
0
0
sesharao92
I tried to change the time stamp of duplicate events. Can any one suggest me a solution.
by sesharao92 Explorer in Splunk Search 01-22-2019
0 1
0
1
deepak007
We have 2 types of accounts in our organization user adm-user I can find the disabled users in the organization, b...
by deepak007 Explorer in Splunk Search 01-22-2019
0 0
0
0
AKG1_old1
Hi, I am looking to extract fields from multi-line events. Some of the events are more than 20 lines. When I am tryi...
by AKG1_old1 Builder in Splunk Search 01-22-2019
0 4
0
4
karthi25
I have a Splunk log in JSON format as follows: {"SCMSplunkLog":{ "SCMSuccessLog":{ "payload":{ "sourceCount":0,"leve...
by karthi25 Path Finder in Splunk Search 01-21-2019
0 1
0
1
y2kbcm
Hi, I am currently figuring out what is wrong with my boolean expression. Currently, I'm making a whitelist of app...
by y2kbcm Explorer in Splunk Search 01-21-2019
0 2
0
2
rossparfect
Good evening one and all, I have CSV files that have monetary values in them, however when they are ingested into sp...
by rossparfect Path Finder in Splunk Search 01-21-2019
0 2
0
2
tseale
I have locations 1-6, and I am needing them to stay in the same spot, even if in the time event, there is not a quant...
by tseale New Member in Splunk Search 01-21-2019
0 7
0
7
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...