Splunk Search

Splunk Search
Community Activity
ggangwar
Hi, I have a splunk dashboard with different panels i.e. pie chart, table etc. I need to increase the font size of te...
by ggangwar Path Finder in Splunk Search 02-22-2024
2 10
2
10
deepthi5
Hi i have stats table with following   
by deepthi5 Path Finder in Splunk Search 02-22-2024
0 1
0
1
kodyrubida
Hi, I am looking to grab all windows events of successful NTLM logins without using Kerberos. Here is my query so far...
by kodyrubida Engager in Splunk Search 02-22-2024
0 1
0
1
harishsplunk7
how to show the how long alert took triggered from the time the event occurred. To calculate the "diff" in times, to ...
by harishsplunk7 Explorer in Splunk Search 02-22-2024
0 6
0
6
anil1219
Hi,My requirement is to find 30 mins result using timechart span=30m from the start time that I have mentioned.Start ...
by anil1219 Engager in Splunk Search 02-22-2024
0 2
0
2
vinod743374
Hi everyone,i need an alternative for the transaction command, bcoz its taking to much time to load the dashboard,thi...
by vinod743374 Communicator in Splunk Search 02-22-2024
0 1
0
1
LearningGuy
Hello,I don't know how to simulate this using makeresults, but I have data over 10,000 (let say 50,000)If I sort desc...
by LearningGuy Motivator in Splunk Search 02-21-2024
0 1
0
1
indeed_2000
HiI have a query that need to compare count of PF field for two log file:on splunk I have two query that create this ...
by indeed_2000 Motivator in Splunk Search 02-21-2024
0 4
0
4
avikc100
I am using Splunk Enterprise Version: 9.1.0.1.my search query is :index="webmethods_prd" source="/apps/webmethods/int...
by avikc100 Path Finder in Splunk Search 02-21-2024
0 5
0
5
Tron-spectron47
Can an event be searched using the transaction without any index or source values?Yes or Nobreif answer on selection
by Tron-spectron47 Loves-to-Learn in Splunk Search 02-21-2024
0 3
0
3
ea-2023
I'm not sure why rex is properly matching the beginning of the value I am looking for (NameofTeam), but it also match...
by ea-2023 Path Finder in Splunk Search 02-21-2024
0 4
0
4
GEB
Our splunk implementation has SERVERNAME as a preset field, and there are servers in different locations, but there i...
by GEB Explorer in Splunk Search 02-21-2024
0 4
0
4
guywood13
 index=my_index source="/var/log/nginx/access.log" | stats avg(request_time) as Average_Request_Time | where Average...
by guywood13 Path Finder in Splunk Search 02-21-2024
0 7
0
7
simo
hiI have this situationindex="idx" [| inputlookup name.csv | table id name ]idx=idname1a2aaa1A2aaa12abbb lookupidname...
by simo Path Finder in Splunk Search 02-21-2024
0 1
0
1
Harikiranjammul
Can some one please help with the regex that can be used to view the below event in tabular format.EventINFO > 2024-0...
by Harikiranjammul Explorer in Splunk Search 02-21-2024
0 1
0
1
bigll
Hi.I have a single filed for date and time of event - 2024-02-19T11:16:58.930104ZI would like to have to fields Date ...
by bigll Path Finder in Splunk Search 02-21-2024
0 3
0
3
ea-2023
HelloI have a working dashboard where I have various fields that can be defined (field1 and field2 in the example), a...
by ea-2023 Path Finder in Splunk Search 02-20-2024
0 11
0
11
att35
We have application data coming from Apache Tomcat's and have a regex in place to extract exception name. But there a...
by att35 Builder in Splunk Search 02-20-2024
0 3
0
3
atul9771
I need help to write a search query where the result from the one query is passed onto the second query1 we import th...
by atul9771 Engager in Splunk Search 02-20-2024
0 2
0
2
ramnaresh2051
I have requirement to calculate total time a user has been connected to system, for that I have logs as below which s...
by ramnaresh2051 Engager in Splunk Search 02-20-2024
0 3
0
3
DaClyde
In Microsoft IIS logs, when a field is empty, a dash ( - ) is used instead of leaving the value blank.  Presumably th...
by DaClyde Contributor in Splunk Search 02-20-2024
0 4
0
4
att35
We have a search where one of the fields from base search is passed onto a REST API using map command.  <Base Search>...
by att35 Builder in Splunk Search 02-20-2024
0 2
0
2
Olivier2024
Hi all,I'm trying to extract a part of a field. The field named Computer and is like MySrv.MyDomain.MySubDom1.comMySu...
by Olivier2024 Explorer in Splunk Search 02-20-2024
0 4
0
4
ITSplunk117
I'm using a modified search from splunksearches.com to get the events from the past two days and returning the differ...
by ITSplunk117 Path Finder in Splunk Search 02-20-2024
0 2
0
2
omcollia
"I have an issue with creating a field named 'Path' which should be populated with 'YES' or 'NO' based on the followi...
by omcollia Engager in Splunk Search 02-20-2024
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...