Splunk Search

Splunk Search
Community Activity
jiaqya
i have 2 columns , one which has install status and the other which has the exception status. install status has yes/...
by jiaqya Builder in Splunk Search 10-16-2018
0 4
0
4
swetar
Can anyone please suggest to me how I can break this event... PATH="/user/hive/datastore/xyz.db/file_name1" PATH="/u...
by swetar New Member in Splunk Search 10-15-2018
0 6
0
6
teddyidc1101
I have this data Owner Branch# Bname O1 B1 Bname1 O1 B2 Bname2 O2 B1 Bname3 O2 B3 Bname4 O2 B4 Bname5 O3 ...
by teddyidc1101 Communicator in Splunk Search 10-15-2018
0 3
0
3
jrnastase
Hello all, Currently I have acquired a timechart in the format: Field_A / Field_B / Field_C / Field_D / Total //// ...
by jrnastase Explorer in Splunk Search 10-15-2018
0 1
0
1
dbcase
Hi, I have the below data and looking to determine the API call name . For the first one the name would be alarmS...
by dbcase Motivator in Splunk Search 10-15-2018
0 4
0
4
nick405060
There are a few other similar questions on Splunk answers, but each answer has been tailored to each asker's use case...
by nick405060 Motivator in Splunk Search 10-15-2018
0 1
0
1
landen99
I am interested in indexing all user's OS search history, web search history, and web browsing history from any brows...
by landen99 Motivator in Splunk Search 10-15-2018
0 5
0
5
highsplunker
Hey guys, It seems that if a field in Splunk index contains Non English characters - the search is very slow. I would...
by highsplunker Contributor in Splunk Search 10-15-2018
0 6
0
6
Log_wrangler
I have events like this.... <22>2018-10-10T09:38:50.631063-05:00 m0074417 sendmail[16942]: w9AEM7sO030350: to=<thisg...
by Log_wrangler Builder in Splunk Search 10-15-2018
0 1
0
1
luke222010
I am running the following search: index=fi | stats last(BP) as start,first(BP) as last by Name | eval diff=last-sta...
by luke222010 Engager in Splunk Search 10-15-2018
0 0
0
0
junxianli
How do I pass an event's field value into a subsearch to retrieve another field? At the moment, I can't use join bec...
by junxianli Explorer in Splunk Search 10-15-2018
4 4
4
4
a212830
Hi, We are frequently required to validate that data is being received by Splunk from multiple servers. The lists o...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
a212830
Hi, I have a query that uses this search to look for hosts that we need to validate: |tstats count WHERE index=* AN...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
dsmeerkat
So here are the results from my "Scanned" field: 20Certificates.pdf 20from=20GLA-PTX164760.pdf 20from=20a=20Xerox.pd...
by dsmeerkat Explorer in Splunk Search 10-15-2018
0 1
0
1
widomj
Is it possible to run multiple searches without having to open multiple browser tabs? Does Splunk have a built in tab...
by widomj New Member in Splunk Search 10-15-2018
0 2
0
2
jamesmoriarty
Hello! I've recently upgraded a test server of mine from 6.x.x to 7.2.x to find a weird bug and I'm wondering if any...
by jamesmoriarty Explorer in Splunk Search 10-15-2018
1 3
1
3
jip31
hello I use the request below but i would like to have an example of doing this code more performant following splun...
by jip31 Motivator in Splunk Search 10-15-2018
0 2
0
2
Sp3ctre11
So we have a lookup and an index : We need to correlate the prefix from the lookup with the data from the index, if...
by Sp3ctre11 New Member in Splunk Search 10-14-2018
0 7
0
7
jafarmat
Hi, So i'm having this rule... index=logs sourcetype=console_test_1 "[Status] Discovered" | rex "<regex rule...
by jafarmat New Member in Splunk Search 10-14-2018
0 4
0
4
landen99
Let's say I have a search that immediately goes into a lookup with a filtered kvstore of 1 million events followed by...
by landen99 Motivator in Splunk Search 10-14-2018
0 1
0
1
Esperteyu
Hi, I'm trying to get a timeline of the percentage of a particular error code among the total of logs. And, based on...
by Esperteyu Explorer in Splunk Search 10-14-2018
0 8
0
8
asdusert
Here is my query : index="basicdataapi" source="/data/api-process/logs/equitydata-rawdata-producer/application.log" ...
by asdusert Engager in Splunk Search 10-14-2018
0 3
0
3
flzhang132
I want to group by virtual machine and then find the latest time project name in each group. How would I implement t...
by flzhang132 Explorer in Splunk Search 10-13-2018
0 3
0
3
rajhemant26
Hello everyone. Want to display the output only for the time which crosses 18 months (earliest time)
by rajhemant26 New Member in Splunk Search 10-13-2018
0 1
0
1
meinfan
I am trying to create a Regular Expression string which could extract several key pieces of data from a syslog event ...
by meinfan New Member in Splunk Search 10-13-2018
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors