Splunk Search

Splunk Search
Community Activity
BenSI
Hi, Is there a way to regroup similar values without defining tons of regex. Let say I do a search that return urls. ...
by BenSI New Member in Splunk Search 02-28-2024
0 1
0
1
allen_hunter
I am trying to write a search that will pull the 10 (or so) most recent events for each host. The tail and head comma...
by allen_hunter Explorer in Splunk Search 02-28-2024
0 3
0
3
dm2
I have this rule, I need it to trigger when results / count of events is greater than 4 but the "Trigger Condition" d...
by dm2 Explorer in Splunk Search 02-28-2024
0 5
0
5
m4jk3l
Hello Splunk members!I have a CSV Lookup file with 2 columnsClientNameHWDetSystemBD-K-027EY     VMwareI have an index...
by m4jk3l Explorer in Splunk Search 02-28-2024
0 11
0
11
michael_sleep
I spent a fair amount of time perusing Google and Splunk Answers but couldn't seem to find a solution that made sense...
by michael_sleep Communicator in Splunk Search 02-28-2024
0 4
0
4
Mrig342
Hi All, I have logs like below in splunk:Log1: Tue Feb 25 04:00:20 2024 EST 10G 59M 1% /apps Log2: Tue Feb 25 04:00:2...
by Mrig342 Contributor in Splunk Search 02-27-2024
0 4
0
4
SplunkDash
Hello,I have some issues with parsing events and a few sample events are given below:{"eventVer":"2.56", "userId":"A0...
by SplunkDash Motivator in Splunk Search 02-27-2024
0 1
0
1
jeffmartin
I have a saved "MySearch" that takes a parameter "INPUT_SessionId", something like this:index=foo| ... some stuff| se...
by jeffmartin Engager in Splunk Search 02-27-2024
0 1
0
1
LearningGuy
Hello,How to add space on a text on a single value?     Thank you for your helpAdding spaces did not have any affect....
by LearningGuy Motivator in Splunk Search 02-27-2024
0 9
0
9
karthi2809
Thanks in Advance.In my scenario i want to club the the result using correlationID .so i used transaction command .Be...
by karthi2809 Builder in Splunk Search 02-27-2024
0 2
0
2
Anud
Hi Team,how to Sum of the field based on the other field values.Row1 field values will be 0-9 and a-z.Sample one give...
by Anud Path Finder in Splunk Search 02-27-2024
0 2
0
2
jroedel
Hello everyone,I am looking for a SPL-solution to determine how long the longest common substring of two strings is.I...
by jroedel Path Finder in Splunk Search 02-27-2024
0 3
0
3
deepdive100
Lookup file `tenants.csv` tenant, tenant1, tenant2, tenant3, tenant4, Desired query index=index1 (tenant1xxx OR tenan...
by deepdive100 Loves-to-Learn Everything in Splunk Search 02-26-2024
0 12
0
12
Poojitha
Hi All,I am trying to send email using sendemail command with csv as an attachment . Email is getting sent successful...
by Poojitha Communicator in Splunk Search 02-26-2024
0 5
0
5
bgill0123
I have a search that gives me the total number of hits to my website and the average number of hits over a 5 day peri...
by bgill0123 Loves-to-Learn in Splunk Search 02-26-2024
0 6
0
6
kalilinux0011
I don't know what happened,pls look the picture and help me! thanks very much
by kalilinux0011 New Member in Splunk Search 02-26-2024
0 6
0
6
alexa
Hi,I have two separate searches that are working independently (expected count, actual count).  I want to combine the...
by alexa Engager in Splunk Search 02-26-2024
0 3
0
3
Skeer-Jamf
As the titles suggests, I'm looking into whether it's possible or not to load balance Universal Forwarder hosts that ...
by Skeer-Jamf Path Finder in Splunk Search 02-26-2024
0 14
0
14
rupasri
Can I retrieve list of alerts shared in App level, Is it possible? |rest /services/saved/searches | search eai:acl.a...
by rupasri Observer in Splunk Search 02-26-2024
0 1
0
1
emilep
In a drilldown, I have 2 possible queries and they look like:qry1=index=fed:xxx_yyyy sourcetype="aaaaa:bbbbb:cccc" so...
by emilep Explorer in Splunk Search 02-26-2024
0 3
0
3
ericaooi
Hi,I would like to have a xml panels code to be passed from Javascript to Splunk XML code dynamically.For instance, b...
by ericaooi Explorer in Splunk Search 02-26-2024
0 0
0
0
ea-2023
In my search I have a field (ResourceId) that contains various cloud resource values. One of these values is Instance...
by ea-2023 Path Finder in Splunk Search 02-25-2024
0 5
0
5
Ash1
query:|tstats count where index=new_index host=new-host source=https://itcsr.welcome.com/logs* by PREFIX(status:) _ti...
by Ash1 Communicator in Splunk Search 02-25-2024
0 4
0
4
super_edition
Hello teamBelow are my splunk logs:{<!-- -->body_bytes_sent: 0bytes_sent: 0host: nice_hosthttp_content_type: -http_referer: -...
by super_edition Path Finder in Splunk Search 02-25-2024
0 1
0
1
twadeus
We are working to link server information to the services in the ServiceNow CMDB. We are looking for example to relat...
by twadeus Loves-to-Learn in Splunk Search 02-25-2024
0 1
0
1
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...
Top Solution Authors