Splunk Search

Splunk Search
Community Activity
sajithpm101
One of my dashboard design having lots of charts. In that, I am using a few icons. So how to add custom icons in Splu...
by sajithpm101 New Member in Splunk Search 08-10-2018
0 1
0
1
flzhang132
How to put two pictures in one line
by flzhang132 Explorer in Splunk Search 08-10-2018
0 3
0
3
sangs8788
index=sample | eval Latency=case(walltime<500, "0-0.5s", walltime>=500 AND walltime<1000, "0.5s-1s", ...
by sangs8788 Communicator in Splunk Search 08-10-2018
0 4
0
4
moey
Raw Cisco WSA squid event: 1533849492.277 0 192.168.1.11 TCP_DENIED/307 0 GET http://detectportal.firefox.com/succe...
by moey New Member in Splunk Search 08-09-2018
0 3
0
3
ankithreddy777
For props.conf which has highest precedence. In documentation, they said [source::] settings override both [host::]...
by ankithreddy777 Contributor in Splunk Search 08-09-2018
0 2
0
2
rgcox1
I'm trying to use a lookup table to find servers that are not reporting or have NEVER reported to Splunk. Since I don...
by rgcox1 Communicator in Splunk Search 08-09-2018
0 7
0
7
dminev1
Hi everyone, I am using splunk for about two week at my work and I have task to build dashboard. I have splunk query...
by dminev1 Explorer in Splunk Search 08-09-2018
0 5
0
5
ocgovsplunk
Hi, I have two searches index= windows EventCode=1234 Logon_Type=8 | table host | dedup host and index=iis host=*|ta...
by ocgovsplunk Engager in Splunk Search 08-09-2018
0 2
0
2
a109120
I am trying to build a summary index to pull a week over week comparison of specific applications. The below query wo...
by a109120 New Member in Splunk Search 08-09-2018
0 5
0
5
josephinemho
I have two line charts I'd like to display in one view, but I'm having trouble combining them because they're using d...
by josephinemho Path Finder in Splunk Search 08-09-2018
0 3
0
3
jcrochon
I’m looking for a way to define a constant to use as a variable when searching. Such defined as: define LocalIPs =...
by jcrochon Explorer in Splunk Search 08-09-2018
0 7
0
7
jimbolya
I have a search: index=proxy sourcetype=proxy_logs (url="somewebsite.com:443" OR url=" somewebsite.com:443 " OR url=...
by jimbolya New Member in Splunk Search 08-09-2018
0 6
0
6
siva_cg
Is it possible to use Splunk REST API to lookup external data from Search Head and show some statistics? I have gone ...
by siva_cg Path Finder in Splunk Search 08-09-2018
0 0
0
0
dhaertel
So I've been tasked to run a mock search as if one of our users breached a database just to see if we are collecting ...
by dhaertel Path Finder in Splunk Search 08-09-2018
0 7
0
7
chrisschum
How can you only extract data from a _raw log where the data I want is separated with double quotes? So it's "this is...
by chrisschum Path Finder in Splunk Search 08-09-2018
0 4
0
4
joydeep741
I have a search query index=abc sourcetype=xyz | stats count by created_date I get results like CREATED_DATE ...
by joydeep741 Path Finder in Splunk Search 08-09-2018
0 7
0
7
dannili
Hi all, this is one sample I'm trying to extract in order to visualize them in table. But when I select a sample fiel...
by dannili Communicator in Splunk Search 08-09-2018
0 7
0
7
ljxdennis
Hi guys, i am pretty new to Splunk and i have the following Task. I have four Systems with logs. I want to merge s...
by ljxdennis New Member in Splunk Search 08-09-2018
0 2
0
2
kumar88
Hi Team, I am new to splunk. and need help in validating data in a lookup I have lookup and the data is like below ...
by kumar88 New Member in Splunk Search 08-09-2018
0 0
0
0
LBG_Ankit
Hi, How can I mask the bank balance in splunk? it is showing something like this: mybal=2426.88,availableBal=2426.88...
by LBG_Ankit New Member in Splunk Search 08-09-2018
0 5
0
5
joydeep741
I have a query which gives results like COLUMN_1 COLUMN_2 1 a 2 ...
by joydeep741 Path Finder in Splunk Search 08-08-2018
0 2
0
2
swetar
Hi everyone, I wanted to highlight the row values based on condition. I am new to CSS and JS . Can you please guide ...
by swetar New Member in Splunk Search 08-08-2018
0 2
0
2
afulamba
Hello Splunkers, This is my 1st post on this forum, I need some help here. I have to set up a alert which has 2 searc...
by afulamba Explorer in Splunk Search 08-08-2018
0 4
0
4
mmdacutanan
I have got a splunk query that searches for the string 'PS1234_IVR_DM' and once found, perform a rex on the field cal...
by mmdacutanan Explorer in Splunk Search 08-08-2018
0 8
0
8
flzhang132
There are 5 rows of data in the table. I want to display these 5 rows of data a line chart. There are 4 fields, field...
by flzhang132 Explorer in Splunk Search 08-08-2018
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...