Splunk Search

Splunk Search
Community Activity
smichalski
Dear Splunkers, I face logs, where special characters have been encoded into Unicode codepoints (e. g. \u0301 instea...
by smichalski Explorer in Splunk Search 10-04-2018
3 3
3
3
mitchellthom
I'm getting strange behavior with a sort, and wondered if anyone knows why. If I run: index=os source=/var/log/sla...
by mitchellthom Engager in Splunk Search 10-04-2018
0 2
0
2
alex_kh
Hello Folks, i have folowing question I have folowing search index=indexA OR index=indexB OR indexC user=alex OR ip...
by alex_kh Explorer in Splunk Search 10-04-2018
0 2
0
2
Shark2112
Hello! I want to find local IPs that communicate with outside IPs every 5 minutes, for example: ...
by Shark2112 Communicator in Splunk Search 10-04-2018
0 1
0
1
ADRIANODL
Hi splunkers, Suppose I have the following table: Date ItemsPurchased UnitPrice 1/1/1111 20 0.5 2/1/1111 10 1 3/1...
by ADRIANODL Explorer in Splunk Search 10-03-2018
0 7
0
7
JoshuaJohn
Trying to capture multiple groups, basically after the colon MacAddress : 7A:AA:82:31:24:B1 Manufactu...
by JoshuaJohn Contributor in Splunk Search 10-03-2018
0 4
0
4
patricianaguit
I need to find another way instead of eventstats for my search. Is there a way where I can tag the events and add an...
by patricianaguit Explorer in Splunk Search 10-03-2018
0 2
0
2
patricianaguit
is there a way where I can tag events and add another field based on hierarchy? For example: Id 1 has different ini...
by patricianaguit Explorer in Splunk Search 10-03-2018
0 4
0
4
jip31
Hello In a report, i used the code below in order to search for an error code in my events. But, when a code is fou...
by jip31 Motivator in Splunk Search 10-03-2018
0 2
0
2
alex129
I am doing a search and evaluating count, avg RT based on some URL patterns. Below are the URLs for my category pages...
by alex129 New Member in Splunk Search 10-03-2018
0 8
0
8
jcleary47
I have a search to identify when a particular server activates "hardware mode" and doesn't exit within a certain time...
by jcleary47 Path Finder in Splunk Search 10-03-2018
0 2
0
2
russell120
Hi, I have two lookup files below: masterinventory.csv type make model year storeID keycode...
by russell120 Communicator in Splunk Search 10-03-2018
0 3
0
3
gnoellbn
Hello, I'm trying to figure out a way to extract values where the field has multiple spaces in it. When I do a sim...
by gnoellbn Explorer in Splunk Search 10-03-2018
0 8
0
8
m4sucess
index="index1 sourcetype="sourcetype1" | join deviceId [ search index="index2" sourcetype="sourcetype2" productFamil...
by m4sucess New Member in Splunk Search 10-03-2018
0 7
0
7
lukasz92
Hi, How can I get 'raw' earliest and latest value before doing search? I need the epoch seconds format, so -1d@d co...
by lukasz92 Communicator in Splunk Search 10-03-2018
1 10
1
10
edwardrose
Hello All I am not sure how to show the row count in my dashboard. I have one panel that searches a list of hosts...
by edwardrose Contributor in Splunk Search 10-03-2018
0 2
0
2
nkchaitanya
Want to capture the latest occurrence of "working_condition_check - status -" which is "Stopped". Please help me in...
by nkchaitanya Explorer in Splunk Search 10-03-2018
0 2
0
2
gcescatto
I have the following JSON, but I'm not really familiar with Splunk's rex function. I tried this command without succe...
by gcescatto New Member in Splunk Search 10-03-2018
0 1
0
1
Shuhei052492
Hi, I would like to know how to calculate the "number of files" field in the table colunm of "Files & directories",w...
by Shuhei052492 Path Finder in Splunk Search 10-03-2018
0 0
0
0
hartcl1
I have data that looks like this; When I perform my search the data returned by Splunk looks like this on the dashbo...
by hartcl1 Explorer in Splunk Search 10-02-2018
0 2
0
2
pretzel2
I can search for events and run stats count by host. And I can run a search of distinct number of hosts. I want t...
by pretzel2 Path Finder in Splunk Search 10-02-2018
0 8
0
8
Skins
Hi, Is there a way to search for what searches have been run over a period of time and by who - preferably listing t...
by Skins Path Finder in Splunk Search 10-02-2018
0 2
0
2
hoerberm
Hi, I need your help, I have a search like this index=test sourcetype=XY | stats count(Field1) AS f1 by action=...
by hoerberm New Member in Splunk Search 10-02-2018
0 4
0
4
m4sucess
index="index1" sourcetype=show_command | join id [ search index="index2" sourcetype=software_data ] | sort _time | ...
by m4sucess New Member in Splunk Search 10-02-2018
0 3
0
3
josedgaravito
Hi, I have a CSV file with the following structure: NAME DiskSerial ProcSerial ...
by josedgaravito New Member in Splunk Search 10-02-2018
0 1
0
1
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors