Splunk Search

Splunk Search
Community Activity
ntttmttoro
How do you add comments and descriptions into objects' fields in an existing data model WITHOUT manually edit the da...
by ntttmttoro New Member in Splunk Search 08-07-2018
0 0
0
0
knr26
We have a requirement where we need to extract the multiple key value pairs from the log files Ex: places= multipl...
by knr26 New Member in Splunk Search 08-07-2018
0 10
0
10
chadman
I would like to use an LDAP search to find computers located in multiple groups. I tried something like this, but I c...
by chadman Path Finder in Splunk Search 08-07-2018
0 7
0
7
mgao
I have two fields, "sender" and "recipient". I want to create a table that lists distinct sender-recipient pairs and ...
by mgao Engager in Splunk Search 08-07-2018
0 2
0
2
cromm
I built a dashboard and am trying to include a time filter on Purchase Date and not the default _time field. At first...
by cromm Explorer in Splunk Search 08-07-2018
0 4
0
4
denys_k
Hello guys I have an index, stored in active directory. Is there a possibility to make my splunk instance extract da...
by denys_k Explorer in Splunk Search 08-07-2018
0 2
0
2
super_virus
I have the below log line: Slow GraphQL query [8447ms] How can I grab only the value "8447"?
by super_virus New Member in Splunk Search 08-06-2018
0 2
0
2
aksharp
We are in a process of setting up new splunk env on CentOS 7. As part of it we have configured 1 search head and 1 in...
by aksharp Explorer in Splunk Search 08-06-2018
0 3
0
3
chrisschum
How would I go about performing a field extraction when the data is structured as follows: ->Message.[some random nu...
by chrisschum Path Finder in Splunk Search 08-06-2018
0 5
0
5
rajindurbal
When I generate a pdf of a dashboard, the columns on the chart are too narrow. The values that are shown on each bar ...
by rajindurbal Path Finder in Splunk Search 08-06-2018
1 3
1
3
eboniebutler
Hey everyone! I have a pretty simple question. Below is a sample search string: index=os sourcetype=df mount="/etc" ...
by eboniebutler New Member in Splunk Search 08-06-2018
0 3
0
3
Nidheesh
I have 3 sources source1, source2, source3 and 5 sourcetypes sourcetype1, sourcetype2, sourcetype3, sourcetype4, sour...
by Nidheesh Explorer in Splunk Search 08-06-2018
0 6
0
6
qinghaogoh
Hi Splunkies, I have configured a transforms.conf below: [ABCD] REGEX = (?m)^(.*)("ABCD":")(\w+(\w{4}["].*)) FORMAT...
by qinghaogoh New Member in Splunk Search 08-06-2018
0 1
0
1
navd
I have a field extracted called "IP" , I want to display the values of IP in a dropdown . But I want to do it based ...
by navd New Member in Splunk Search 08-06-2018
0 7
0
7
Rajkumarkbm
I am having n number of events but want to read 3 and 4th record. Eg: 2018-02-09 ABCD 1234 5678 2018-02-09 EFGH 133...
by Rajkumarkbm Engager in Splunk Search 08-06-2018
0 6
0
6
adlireza
I have been busting my brain on this for a few weeks with no clear solution, turning to the brainiacs in the Splunk c...
by adlireza Path Finder in Splunk Search 08-06-2018
0 4
0
4
jmteo
Hi guys, I am trying to create an evaluated field, action, that will contain different values from different fields ...
by jmteo Explorer in Splunk Search 08-06-2018
1 10
1
10
david_casey
Can you do a data model search based on a macro? Trying but Splunk is not liking it. It yells about the wildcards *...
by david_casey Path Finder in Splunk Search 08-06-2018
0 2
0
2
Splunk_Shinobi
Timechartで10種類以上のデータを同時に表示・プロットしたいのですが、Othersに丸められてしまいます。 15種類など、より多く設定するにはどうすればよいでしょうか。
by Splunk_Shinobi Splunk Employee Splunk Employee in Splunk Search 08-06-2018
0 2
0
2
SMWickman
I'm trying to write a search for an asset lookup that I'm able to query to take a list of IPs and bring back the corr...
by SMWickman Explorer in Splunk Search 08-06-2018
0 1
0
1
danielpellarini
In some of my sourcetypes, I am using automatic CSV lookups to add some data to Splunk (as explained in the docs here...
by danielpellarini Path Finder in Splunk Search 08-06-2018
0 3
0
3
CarlAnners
Hello, Using the ML Toolkit, I am looking to train and and apply the OneclassSVM algorithm on a list of models. Basi...
by CarlAnners New Member in Splunk Search 08-06-2018
0 0
0
0
jackreeves
I am displaying some data by Month for 2018/2019 (i.e. 01-2018, 02-2018) on a barchart. Search Query: ( sourcetype=s...
by jackreeves Explorer in Splunk Search 08-06-2018
0 4
0
4
andrehl
Hi community! I would like to make the number inside the red circle to be a percentage based on the total customer i...
by andrehl Explorer in Splunk Search 08-06-2018
0 3
0
3
asamajdwar
index="test_index" |table Calendar, Job, Status |eval dayNow=strftime(now(),"%A") |search Calendar= ??? My 'Calenda...
by asamajdwar New Member in Splunk Search 08-05-2018
0 1
0
1
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors