Splunk Search

Splunk Search
Community Activity
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm very new to using Splunk and most certainly to the...
by IRHM73 Motivator in Splunk Search 10-19-2018
0 21
0
21
lbentin
Hi, I have a cumulative counter in a .csv log, the issue is, the software generating the .csv resets this counter fro...
by lbentin New Member in Splunk Search 10-19-2018
0 0
0
0
NicoloPunzalan2
Hi All, I am having an issue on extracting a string in a field. For example, I have this data below: "18/10/2018 03...
by NicoloPunzalan2 Engager in Splunk Search 10-18-2018
0 4
0
4
puneetkharband1
I have 6 events. Each one has a timestamp, and I have extracted the time of each into a new field using eval. But now...
by puneetkharband1 Path Finder in Splunk Search 10-18-2018
0 1
0
1
trozza
Currently in our log files, the _time value is rounded down to the nearest second and is sorted accordingly. But in ...
by trozza Engager in Splunk Search 10-18-2018
0 2
0
2
dsbruce
We have a sevone network monitoring a JSON data time field formatted as EPOCH in Scientific Notation format. All the...
by dsbruce Explorer in Splunk Search 10-18-2018
0 0
0
0
pshangguan
I have the following query I use to get the latest status and time(_time). index=jenkins |spath job_name | search jo...
by pshangguan New Member in Splunk Search 10-18-2018
0 17
0
17
bobbieluturner
I have this query that uses the timewrap command that I want to insert a subsearch instead of a 'fixed' value ( 193 )...
by bobbieluturner New Member in Splunk Search 10-18-2018
0 3
0
3
leninkp3005
Folks !! I'm struggling with removing empty rows from the result fields in my results. In my results, i've got many ...
by leninkp3005 Explorer in Splunk Search 10-18-2018
1 5
1
5
jakewhittet
I have some ironport logs that I am trying to tie together within Splunk without much success. Currently I have a se...
by jakewhittet Explorer in Splunk Search 10-18-2018
0 0
0
0
jakewhittet
I have some ironport logs that I am trying to tie together within Splunk without much success. Currently I have a se...
by jakewhittet Explorer in Splunk Search 10-18-2018
0 0
0
0
ibrahima
is there a search to find out which users (Pulling username from AD on windows) were logged on to a machine at a cert...
by ibrahima New Member in Splunk Search 10-18-2018
0 0
0
0
moorvogi
i'm using a NIFI flow to send in 3 values (host, message, moreData). I want to use host passed in from nifi as a JSON...
by moorvogi Path Finder in Splunk Search 10-18-2018
0 0
0
0
bharathkumarnec
Hi All, Context X Y Z ABC 98 97 67 DEF 50 45 23 GHI 3 2 1 So, if Context is ABC, i have to apply color coding for ...
by bharathkumarnec Contributor in Splunk Search 10-18-2018
0 2
0
2
thezen
I am looking to retrieve the following a field from a lookup table depending on the lookup result of two fields as fo...
by thezen Explorer in Splunk Search 10-18-2018
0 5
0
5
abhishekgandhe
Hi, I have to find the value of true or false from the following string in logfile. Below are 2 strings with either ...
by abhishekgandhe Explorer in Splunk Search 10-18-2018
0 6
0
6
mfritsch
Hi I have a lookup table containg the host name and a software version hostlookup.csv hostname,version hostA,2 hos...
by mfritsch New Member in Splunk Search 10-18-2018
0 3
0
3
evkuzin
I try to get from iis logs top source IP by requests with the number of requests in every 5 seconds. If I just try to...
by evkuzin New Member in Splunk Search 10-18-2018
0 2
0
2
arrangineni
I need am trying to find the maximum value of a field(Peak value and time at which it happened everyday) based on a ...
by arrangineni Path Finder in Splunk Search 10-17-2018
0 1
0
1
matthewg
I have multiple events such as below: Key points here: New values of event_type may be added randomly and the sched...
by matthewg Explorer in Splunk Search 10-17-2018
0 2
0
2
heskez
Hi there, when I run this search: index=* source=stream:Splunk_IP | rex field=src_ip "(?<src1>.*)\.(?<src2>.*)\.(?<...
by heskez Engager in Splunk Search 10-17-2018
0 7
0
7
stevennoble
I'm trying to figure out how I can format my logs such that splunk does not get confused by an escaped quote. I'm cur...
by stevennoble Explorer in Splunk Search 10-17-2018
3 5
3
5
gnanaraj_mcc
How do i compare my raw data volume to the indexed data volume for a specific source type? Can someone help with thi...
by gnanaraj_mcc Loves-to-Learn Lots in Splunk Search 10-17-2018
0 1
0
1
josephinemho
I am trying to look up a server (using an input field - $field1$) in my dashboard and pull the most recent alerts for...
by josephinemho Path Finder in Splunk Search 10-17-2018
1 0
1
0
garryclarke
I have a dashboard where I want to use a textbox input to add data to a lookup file. I have managed to get this to ...
by garryclarke Path Finder in Splunk Search 10-17-2018
1 6
1
6
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...