Splunk Search

Splunk Search
Community Activity
grantsmiley
Suppose I have a data set with a metric, let's say for example, it contains the average # of stamps licked per day by...
by grantsmiley Path Finder in Splunk Search 09-06-2018
1 2
1
2
JakeInfoSec
So, I put together a search not too long ago, with help from the community on here, that would run hourly to update a...
by JakeInfoSec Explorer in Splunk Search 09-06-2018
1 7
1
7
samsam48
I have the following Splunk base search: sourcetype=serverA FATAL OR ERROR OR WARN | rex field=_raw max_match=1 "(?...
by samsam48 Explorer in Splunk Search 09-06-2018
0 5
0
5
samsam48
I have a Splunk Search that returns events that have an alert-type field value of "Severe", "Moderate", and "light"....
by samsam48 Explorer in Splunk Search 09-06-2018
0 2
0
2
jaxob01
Hello Splunkers i requiered eval the last field with current row. example: field 1 ...... field2.........field3.....
by jaxob01 New Member in Splunk Search 09-06-2018
0 1
0
1
ninisimonishvil
Hello fellows, I have an issue that I'm not really sure how to solve. Well in event I have time in following form...
by ninisimonishvil Path Finder in Splunk Search 09-06-2018
0 10
0
10
sabeqa
i am trying to search for urls that are not in my allowed list lookup csv , my csv file is named as url and has 1 col...
by sabeqa Engager in Splunk Search 09-06-2018
0 3
0
3
vintik
Hello, I have multiple queries with small differences, is it possible to combine them? Here is example: index=some...
by vintik Engager in Splunk Search 09-06-2018
0 2
0
2
ajhstn
Hello, i have a single Splunk Enterprise instance with a 9997 listener. I have a single Windows Server with a UF for...
by ajhstn Explorer in Splunk Search 09-06-2018
0 4
0
4
sunith35
index="_internal" | timechart span=15m count(name) as name | eval Status=if(name>1500, "RED", if(name>100,"AMBER","G...
by sunith35 Engager in Splunk Search 09-06-2018
1 0
1
0
sabeqa
i am trying to search for the allowed urls (passthrough) and not in my list uploaded csv called url. the csv is made ...
by sabeqa Engager in Splunk Search 09-06-2018
0 0
0
0
jip31
hi I use the code below in order to count some events from 3 fields: (LogName SourceName Type ) index="windows" (s...
by jip31 Motivator in Splunk Search 09-05-2018
0 6
0
6
w344423
I got a number in my first lookup and i want to compare this number with a start and end number in a lookup, how do i...
by w344423 Explorer in Splunk Search 09-05-2018
0 6
0
6
WXY
Now ,I want to get common values from data. I use this command: `index="new_1" |stats list(oper_field) as gn by de...
by WXY Path Finder in Splunk Search 09-05-2018
0 5
0
5
USER78
I have search A which gives out results like field A, field B , field C, where field C is a combination of two halves...
by USER78 New Member in Splunk Search 09-05-2018
0 2
0
2
brajaram
I have a query that looks like this: index=A ( ErrorCode=2 OR ErrorCode=3) [ search index=B Criteria=1 ...
by brajaram Communicator in Splunk Search 09-05-2018
0 1
0
1
nedwards94
trying to use "lookup dnslookup clientip as dvc OUTPUT clienthost AS dvc" within a search on a dashboard. Some of the...
by nedwards94 Engager in Splunk Search 09-05-2018
0 0
0
0
ixixix_spl
I'm having some serious difficulty in figuring out how to escape a double backslash within the REX/regex spl command....
by ixixix_spl Explorer in Splunk Search 09-05-2018
0 2
0
2
griffinpair
I have an index that is populated by and extensive, long running query that creates a line like "Client1 Export1 Miss...
by griffinpair Path Finder in Splunk Search 09-05-2018
0 3
0
3
dkrichards16
Hi, I'm doing some research for our new architecture and am currently doing some house keeping on our props and trans...
by dkrichards16 Path Finder in Splunk Search 09-05-2018
0 4
0
4
Navitas28
Hi sourcetype="SourceA" ERROR NOT "GET-INFO" NOT "GET-ArchivedInfo" NOT "Error1" NOT "ERROR2" The above search g...
by Navitas28 New Member in Splunk Search 09-05-2018
0 1
0
1
koshyk
We have got data for particular data which contains field in many places Events 2018-09-05 01:00:00 logged in by USE...
by koshyk Super Champion in Splunk Search 09-05-2018
1 3
1
3
enoshima
例えば、Index=XXX sourcetype=+++ と言ったログファイルをサーチする際に 2018/09/10には2018/9/7のデータを検索したい、2018/09/11には2018/09/08~2018/09/10までのデ...
by enoshima New Member in Splunk Search 09-05-2018
0 1
0
1
Shashank_87
Hi, I am looking for some help regarding Splunk Regular Expression. I have a data something like this in a field "fie...
by Shashank_87 Explorer in Splunk Search 09-05-2018
0 7
0
7
aherrington
Hi there, I'm wondering if it's possible to format a Splunk query like so: IF results contains "this string" THEN u...
by aherrington Path Finder in Splunk Search 09-05-2018
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...