Splunk Search

Splunk Search
Community Activity
Shashank_87
Hi, I have a multi value field who has data something like below which has been extracted from some web service. I a...
by Shashank_87 Explorer in Splunk Search 08-28-2018
0 5
0
5
hrithiktej
Our security events count is in millions and we observed that we have more then 600 service accounts in our environme...
by hrithiktej Communicator in Splunk Search 08-28-2018
0 0
0
0
flzhang132
How do I display all accounts in the same chart at the same time? There are three accounts! account1 have 1000000$ ...
by flzhang132 Explorer in Splunk Search 08-28-2018
0 1
0
1
Bhagyashri
I want to search a string "call_before_download &#61; function(){<!-- --> showInstallInstructions(); }
by Bhagyashri Explorer in Splunk Search 08-28-2018
0 2
0
2
psymonkey
My basic question is as follows: Is there a text alternative for specifying greater or less than, rather than using ...
by psymonkey New Member in Splunk Search 08-28-2018
0 4
0
4
jgauthier
I have a couple simple saved searches, and they are on a dashboard. After upgrading to 4.3, "other" started showing u...
by jgauthier Contributor in Splunk Search 08-28-2018
1 6
1
6
DataOrg
I have a list of server in lookup file and I want to create an alert. The list of server names in the lookup file(aro...
by DataOrg Builder in Splunk Search 08-28-2018
0 7
0
7
desi_stoitsova
How can I change the values in the legend for a timechart? I use: index&#61;indexone sourcetype&#61;sourceone | timechart co...
by desi_stoitsova Engager in Splunk Search 08-28-2018
2 0
2
0
yaminims
Below is my xml from which i need the Name and code under every option &lt;options&gt; &lt;name&gt;MESSAGING &#43; DA...
by yaminims New Member in Splunk Search 08-28-2018
0 2
0
2
peiyee422
Hi, Need help urgently. I am running Splunk command in batch file but I keep on getting FATAL: Error in 'eval' com...
by peiyee422 New Member in Splunk Search 08-28-2018
0 5
0
5
khanlarloo
Hi I have one question, is it possible to count the number of event in regex format for writing in transforms.conf?
by khanlarloo Explorer in Splunk Search 08-28-2018
0 8
0
8
thefuzz4
So here is my search index&#61;someindex sourcetype&#61;somesourcetype source&#61;"someloglocation*" eventtype&#61;"nix_kernel_attac...
by thefuzz4 Path Finder in Splunk Search 08-27-2018
0 4
0
4
strangelaw
I have following search: index&#61;pfsense OR index&#61;otherindex verdict&#61;pass | stats values(destip) AS fieldA, values(ot...
by strangelaw Explorer in Splunk Search 08-27-2018
0 3
0
3
jnames10
Hi Splunkers, newish user here... I'm looking at firewall logs, I want to create a table with number of blocked IP fo...
by jnames10 Explorer in Splunk Search 08-27-2018
1 2
1
2
ahofmann
Hi, I want to generate a timechart count of actual values and overlay a trendline of expected goal growth. Basically ...
by ahofmann Explorer in Splunk Search 08-27-2018
0 1
0
1
mag3690
Is it possible to include the graphical chart(not a pdf) along with tabular chart in the email alerts which are confi...
by mag3690 Engager in Splunk Search 08-27-2018
1 4
1
4
iomega311
I have created a query that will extract specific information from my Active Directory logs, and output it into a nic...
by iomega311 Explorer in Splunk Search 08-27-2018
0 1
0
1
adamsmith47
So, I've simplified my real problem down to this example with as few variables as possible. I wish I could simply alt...
by adamsmith47 Communicator in Splunk Search 08-27-2018
0 3
0
3
ppanchal
Below is my log, [ERL_ROUTE_ACK_INTERFACE] 2018-08-27 11:06:02 DEBUG [callUpdateERLRouteStatus] ERLRouteAckServiceI...
by ppanchal Path Finder in Splunk Search 08-27-2018
0 2
0
2
belts
Dear all, There are two columns with data: time (time scale in steps of 10 minutes) and val (amount of transactions)...
by belts New Member in Splunk Search 08-27-2018
0 2
0
2
knalla
Hi All, How to extract the fields for the syslog data with kv values at indexing time? Aug 27 10:05:58 ciscoasa SFI...
by knalla Path Finder in Splunk Search 08-27-2018
0 1
0
1
tkwaller_2
Hello I have a search that I use to calculate days between 2 dates. The search is like this: |index&#61;dev_tsv "B...
by tkwaller_2 Communicator in Splunk Search 08-27-2018
0 11
0
11
DEAD_BEEF
I'm trying to create a timechart to show when logs were ingested. Trying to use _indextime but it doesn't seem to be...
by DEAD_BEEF Builder in Splunk Search 08-27-2018
0 3
0
3
raj_mpl
Hi All , 1)How do you capture INFO/ERROR/WARN events using regular expression ? 2)How do you capture the rest of the ...
by raj_mpl Path Finder in Splunk Search 08-27-2018
0 3
0
3
rwmilligan
I'm trying to do some least common occurance hunting in our environment, and would like to see if I can make a search...
by rwmilligan Explorer in Splunk Search 08-27-2018
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...