Splunk Search

Splunk Search
Community Activity
umdterps02
I have an indexed source from tanium and an inputlookup from nessus. I want to run a search that if the MAC Address m...
by umdterps02 Path Finder in Splunk Search 09-25-2018
0 5
0
5
hoyomi
What I want to achieve is to extract surrounding log lines by thread ID, which is found on the line where the keyword...
by hoyomi Explorer in Splunk Search 09-25-2018
0 3
0
3
cboonyan
Some of my logs are generated via automatic jobs and I want to filter them away. What is the best way to filter away ...
by cboonyan New Member in Splunk Search 09-25-2018
0 3
0
3
hyperscaleau
I need to return the average of the earliest 10 results (OG) in an index and the average of the latest 10 results (FG...
by hyperscaleau Engager in Splunk Search 09-25-2018
1 2
1
2
ratan2257
It might be a very simple answer, however I am not able to find it so far . My splunk query has a field name "Size(...
by ratan2257 New Member in Splunk Search 09-25-2018
0 6
0
6
becksyboy
Hi, I would like to compare 1 week of tabled data to the previous weeks and calculate the percentage difference for ...
by becksyboy Contributor in Splunk Search 09-25-2018
0 1
0
1
bjaylsu
Can we track CPU usage of users via splunk? We have users that are running lots of transactions. We are looking to de...
by bjaylsu New Member in Splunk Search 09-25-2018
0 3
0
3
kmmanikandan
i have two search results like search1 produce table with 15 columns and search2 produce table with the exactly same ...
by kmmanikandan Explorer in Splunk Search 09-24-2018
0 6
0
6
KaneKennedyNHSD
Hi, Could anyone help me get further with this please? I have a list of UK post codes in my event data. They will a...
by KaneKennedyNHSD New Member in Splunk Search 09-24-2018
0 3
0
3
karthi2809
i have two source A and B Log A: REQUEST_TS="2018-02-16 01:20:05.303" REPLY_TS="2018-02-16 01:20:05.53" SENDER_ID=R...
by karthi2809 Builder in Splunk Search 09-24-2018
0 3
0
3
JoshuaJohn
I want to see devices that do not have a specific value. I am organizing my devices by Mac Address, and I am trying t...
by JoshuaJohn Contributor in Splunk Search 09-24-2018
0 5
0
5
jip31
hello In the file attached, i need to do a line break not after a format date like "06/09/2018 - 14:21:24" as its ac...
by jip31 Motivator in Splunk Search 09-24-2018
0 7
0
7
nacartwright
Newbie here...I have an index of data that represents calls. Each event has a start_time and duration. I've been aske...
by nacartwright New Member in Splunk Search 09-24-2018
0 5
0
5
ibob0304
I have CSV data like below, --------------------------------------------------- Date1 | WaitDays -...
by ibob0304 Communicator in Splunk Search 09-24-2018
0 3
0
3
JoshuaJohn
I am trying to see the number of devices in a fleet by location without a specific setting applied. The data I have c...
by JoshuaJohn Contributor in Splunk Search 09-24-2018
0 2
0
2
bablucho
I'm pulling in stats data via CSV file. I am using a specific column header "LoginTime" as the Date field I've timec...
by bablucho Path Finder in Splunk Search 09-24-2018
0 7
0
7
terryloar
In DB Connect I used "Data Inputs in Splunk Manager" to create test_dump which it did without error and produced: db...
by terryloar Path Finder in Splunk Search 09-24-2018
0 3
0
3
umdterps02
This following search works just fine: | inputlookup assets.csv | inputlookup append=true all_ vulnerabilities.csv |...
by umdterps02 Path Finder in Splunk Search 09-24-2018
0 17
0
17
Nadhiyaa
How do I rename the value "other(n)" to "OTHERS" in a pie chart after the stats command?
by Nadhiyaa Path Finder in Splunk Search 09-24-2018
0 1
0
1
Task1906
Hello, I hope someone can help. I am attempting to do a subsearch that I am having difficulty with and hope someone ...
by Task1906 Explorer in Splunk Search 09-23-2018
0 3
0
3
Mohsin123
Hi , i am trying to calculate a percentage of status codes over time, but the calculation doesn't sum up to 100% . ...
by Mohsin123 Path Finder in Splunk Search 09-23-2018
0 2
0
2
rakesh_498115
hi.. I have four fields say A,B,C,D..All these are multivalued fields .. i.e for a single event they can be multiple...
by rakesh_498115 Motivator in Splunk Search 09-23-2018
0 11
0
11
vn86893
Hello, I am trying to calculate average CPU% utilized by top 10 processes on a Windows machine. When I do the searc...
by vn86893 Explorer in Splunk Search 09-23-2018
1 1
1
1
spoolunk
Below is the data in my index named index ETS=20180921 CNT=161756 BRAND=A INDICATOR=Y ETS=20180921 CNT=156203 BRAND...
by spoolunk Engager in Splunk Search 09-22-2018
0 1
0
1
enmanu
I encountered the following error while trying to save: "The time difference / clock skew between this system and t...
by enmanu New Member in Splunk Search 09-22-2018
0 3
0
3
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...