Splunk Search

Splunk Search
Community Activity
reed_kelly
I would like something like a stats command that groups events only if they form a contiguous run of a particular fie...
by reed_kelly Contributor in Splunk Search 10-10-2018
1 2
1
2
sgoodman26
We have been trying to create a search for AWS:Simple Email Services to locate any Bounce Back emails that come in; S...
by sgoodman26 Explorer in Splunk Search 10-10-2018
0 5
0
5
ColinJacksonPS
I'm trying to set up a search for when a user disables their 2FA vs when IT disables it for them. I have the User A...
by ColinJacksonPS Path Finder in Splunk Search 10-10-2018
0 8
0
8
atyshke1
Hello, I am using two searches for seeking two windows events 4732 and 4733. I want to print into a new table events...
by atyshke1 Path Finder in Splunk Search 10-10-2018
0 11
0
11
rolly_deguzman
Please could you help me on the working example with dataset using arules command? i'm planning to use this in my ma...
by rolly_deguzman New Member in Splunk Search 10-10-2018
0 0
0
0
chintan_shah
Hi, I have the data in the below format i.e i have calculated base on Type A,B,C per month and the data looks like J...
by chintan_shah Path Finder in Splunk Search 10-10-2018
0 4
0
4
kokanne
I want to find the ratio of failures and successful logins. Therefore I use one field in a data model, called Authent...
by kokanne Communicator in Splunk Search 10-10-2018
0 8
0
8
nick405060
Scoured a ton of related questions, but none exactly like this have been posted yet as far as I can tell. I have an ...
by nick405060 Motivator in Splunk Search 10-09-2018
0 2
0
2
pratapbhanu2047
I am trying to convert values from rows into columns. below is a example data ServerName Counter Value server1 %_P...
by pratapbhanu2047 Engager in Splunk Search 10-09-2018
0 8
0
8
splunk2018a
I am trying to show two things in one graph: 1) bar chart of the count of events for last 24 hours in hourly interval...
by splunk2018a New Member in Splunk Search 10-09-2018
0 2
0
2
kakarsu
Hi Guys, I am pretty new to regex and need help with getting repeated values from one event (record). Splunk is sho...
by kakarsu New Member in Splunk Search 10-09-2018
0 3
0
3
paimonsoror
Having some strange behavior with base searches right now. For example, we have events like this flowing into Splunk...
by paimonsoror Builder in Splunk Search 10-09-2018
0 3
0
3
rajyah
Good day sirs! I have two different indexes with different fields but same value-ish. index=a: MTH=SEPTEMBER index=...
by rajyah Communicator in Splunk Search 10-09-2018
0 3
0
3
zacksoft
My query ends with | stats count(_raw) by user I want the values to be displayed in descending order based on the...
by zacksoft Contributor in Splunk Search 10-09-2018
0 2
0
2
Wondergoat77
I am trying to remove all content returned in a field between two specific strings but only from the first occurrence...
by Wondergoat77 Engager in Splunk Search 10-09-2018
0 4
0
4
nick405060
Hi there, I read a bunch of related Splunk answers, but so far I haven't seen a solution posted to creating a drilld...
by nick405060 Motivator in Splunk Search 10-09-2018
0 9
0
9
mwdbhyat
Hi guys, Has anyone ever written a search that can compare events(in this case "indicator" across 2 indexes and show...
by mwdbhyat Builder in Splunk Search 10-09-2018
0 4
0
4
abdullahalhabba
Hi Splunker; How do I create a custom key indicator search on a normal dashboard? I don't want to create a custom ke...
by abdullahalhabba Explorer in Splunk Search 10-09-2018
1 0
1
0
replicamask
Hey there, I've been having a look around on here, and through Google, but so far coming I'm up blank. I'm looking ...
by replicamask Explorer in Splunk Search 10-09-2018
0 3
0
3
Mohsin123
Hi , I have a rsult set like this : status eSIMEntitlement selfcare oauth2 account customer catalog moat ...
by Mohsin123 Path Finder in Splunk Search 10-08-2018
0 2
0
2
pkumar9610
HI Friends, I have more than 50 Indexes in my Splunk cluster. For a few of the Indexes, the earliest event is show...
by pkumar9610 Explorer in Splunk Search 10-08-2018
0 7
0
7
sarahafrin
The default folder under SPLUNK_HOME/etc/apps/search has been overwritten and all my changes are now in a default.old...
by sarahafrin Explorer in Splunk Search 10-08-2018
0 2
0
2
cosmo360
Hi, Can someone suggest a good way (or a real good book) on how to learn splunk queries. any suggestions would be ap...
by cosmo360 New Member in Splunk Search 10-08-2018
0 4
0
4
jackpal
I have a relatively simple query with which I am evaluating a new field. I'd like to get the top values of this new ...
by jackpal Path Finder in Splunk Search 10-08-2018
0 2
0
2
Sidharda
Hello Splunkers, I have a requirement to match a field from an index to a field in a lookup and then extract the res...
by Sidharda Path Finder in Splunk Search 10-08-2018
0 1
0
1
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors