Splunk Search

Splunk Search
Community Activity
zacksoft
I have 5 different servers/hosts, and whenever the 'game app' initiates in it, an event with the string "Game Startin...
by zacksoft Contributor in Splunk Search 10-16-2018
0 1
0
1
joseft
CSV file Source_IP,Source_Name 18.130.101.34,AWS 18.130.215.107,AWS or Source_IP,Source_Name "18.130.101.34",AWS...
by joseft Explorer in Splunk Search 10-16-2018
0 0
0
0
shayhibah
I have dashboards with drill down option. The drill down query contains custom earliest and latest tokens since there...
by shayhibah Path Finder in Splunk Search 10-16-2018
0 4
0
4
joemiller
I'm having trouble extracting key/value pairs from a set of data. I think there are two separate problems that are ma...
by joemiller Path Finder in Splunk Search 10-16-2018
0 6
0
6
jiaqya
i have 2 columns , one which has install status and the other which has the exception status. install status has yes/...
by jiaqya Builder in Splunk Search 10-16-2018
0 4
0
4
swetar
Can anyone please suggest to me how I can break this event... PATH="/user/hive/datastore/xyz.db/file_name1" PATH="/u...
by swetar New Member in Splunk Search 10-15-2018
0 6
0
6
teddyidc1101
I have this data Owner Branch# Bname O1 B1 Bname1 O1 B2 Bname2 O2 B1 Bname3 O2 B3 Bname4 O2 B4 Bname5 O3 ...
by teddyidc1101 Communicator in Splunk Search 10-15-2018
0 3
0
3
jrnastase
Hello all, Currently I have acquired a timechart in the format: Field_A / Field_B / Field_C / Field_D / Total //// ...
by jrnastase Explorer in Splunk Search 10-15-2018
0 1
0
1
dbcase
Hi, I have the below data and looking to determine the API call name . For the first one the name would be alarmS...
by dbcase Motivator in Splunk Search 10-15-2018
0 4
0
4
nick405060
There are a few other similar questions on Splunk answers, but each answer has been tailored to each asker's use case...
by nick405060 Motivator in Splunk Search 10-15-2018
0 1
0
1
landen99
I am interested in indexing all user's OS search history, web search history, and web browsing history from any brows...
by landen99 Motivator in Splunk Search 10-15-2018
0 5
0
5
highsplunker
Hey guys, It seems that if a field in Splunk index contains Non English characters - the search is very slow. I would...
by highsplunker Contributor in Splunk Search 10-15-2018
0 6
0
6
Log_wrangler
I have events like this.... <22>2018-10-10T09:38:50.631063-05:00 m0074417 sendmail[16942]: w9AEM7sO030350: to=<thisg...
by Log_wrangler Builder in Splunk Search 10-15-2018
0 1
0
1
luke222010
I am running the following search: index=fi | stats last(BP) as start,first(BP) as last by Name | eval diff=last-sta...
by luke222010 Engager in Splunk Search 10-15-2018
0 0
0
0
junxianli
How do I pass an event's field value into a subsearch to retrieve another field? At the moment, I can't use join bec...
by junxianli Explorer in Splunk Search 10-15-2018
4 4
4
4
a212830
Hi, We are frequently required to validate that data is being received by Splunk from multiple servers. The lists o...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
a212830
Hi, I have a query that uses this search to look for hosts that we need to validate: |tstats count WHERE index=* AN...
by a212830 Champion in Splunk Search 10-15-2018
0 5
0
5
dsmeerkat
So here are the results from my "Scanned" field: 20Certificates.pdf 20from=20GLA-PTX164760.pdf 20from=20a=20Xerox.pd...
by dsmeerkat Explorer in Splunk Search 10-15-2018
0 1
0
1
widomj
Is it possible to run multiple searches without having to open multiple browser tabs? Does Splunk have a built in tab...
by widomj New Member in Splunk Search 10-15-2018
0 2
0
2
jamesmoriarty
Hello! I've recently upgraded a test server of mine from 6.x.x to 7.2.x to find a weird bug and I'm wondering if any...
by jamesmoriarty Explorer in Splunk Search 10-15-2018
1 3
1
3
jip31
hello I use the request below but i would like to have an example of doing this code more performant following splun...
by jip31 Motivator in Splunk Search 10-15-2018
0 2
0
2
Sp3ctre11
So we have a lookup and an index : We need to correlate the prefix from the lookup with the data from the index, if...
by Sp3ctre11 New Member in Splunk Search 10-14-2018
0 7
0
7
jafarmat
Hi, So i'm having this rule... index=logs sourcetype=console_test_1 "[Status] Discovered" | rex "<regex rule...
by jafarmat New Member in Splunk Search 10-14-2018
0 4
0
4
landen99
Let's say I have a search that immediately goes into a lookup with a filtered kvstore of 1 million events followed by...
by landen99 Motivator in Splunk Search 10-14-2018
0 1
0
1
Esperteyu
Hi, I'm trying to get a timeline of the percentage of a particular error code among the total of logs. And, based on...
by Esperteyu Explorer in Splunk Search 10-14-2018
0 8
0
8
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors