Splunk Search

Splunk Search
Community Activity
abhi04
How to capture all the below in one variable using Regex. Below is the sample. Each line is a separate value and in a...
by abhi04 Communicator in Splunk Search 07-11-2018
0 4
0
4
Grant007701
Hi, I'm trying to combine results of varying operating systems into one, for example: Microsoft Windows Server 2008...
by Grant007701 New Member in Splunk Search 07-11-2018
0 4
0
4
znaesh
Can you please advise, what do I do if my Splunk complains often (every couple minutes) in splunkd.log in production ...
by znaesh Path Finder in Splunk Search 07-11-2018
0 4
0
4
uddhav
Hi, I am planning to display the distinct count of users logged into Splunk today. I came across, following two sear...
by uddhav New Member in Splunk Search 07-11-2018
0 1
0
1
sh254087
I have a dashboard with a drop-down that will have a list of values populated to it. When the user selects a value fr...
by sh254087 Communicator in Splunk Search 07-11-2018
0 3
0
3
jip31
Hello I need help to display two curves in my chart and the 2 curves refer to host="$field1$ and host="$field2$ So I ...
by jip31 Motivator in Splunk Search 07-11-2018
0 3
0
3
nazanin2016
Hi, I wonder whether someone may be able to help me please. I have created in a separate search with a lookup table...
by nazanin2016 Path Finder in Splunk Search 07-11-2018
1 9
1
9
saranyaa21
Hi, City:{city1: 4, city2: 3, city3: 2, city4: 5} I used this regex to get the 3rd word from the above line: (?<"C...
by saranyaa21 Path Finder in Splunk Search 07-11-2018
0 16
0
16
Log_wrangler
I created this PART 2 as the previous thread is getting long. Recap: I am trying to monitor login behavior to an on...
by Log_wrangler Builder in Splunk Search 07-10-2018
0 0
0
0
Kendo213
Any ideas on how I can get around the 10k subsearch limit? This search is quick, and works fine, however I'm hitting...
by Kendo213 Communicator in Splunk Search 07-10-2018
0 5
0
5
kdimaria
I am trying to see the average users by day but when there are no events or users for a certain day the _time field d...
by kdimaria Communicator in Splunk Search 07-10-2018
0 2
0
2
navd
I have extracted the 500 error as "server_error" and I want to count the total number of server_error by host and sh...
by navd New Member in Splunk Search 07-10-2018
0 1
0
1
brdr
Is there a way I can continue my search when first search returns 0 events. Returning 0 events is a valid scenario in...
by brdr Contributor in Splunk Search 07-10-2018
0 2
0
2
laconix
Hello, I would like to perform a search that return only a particular field value for which i don't find in any othe...
by laconix New Member in Splunk Search 07-10-2018
0 9
0
9
satkumvnr
Hi dear Splunkers I have the following JSON given by a REST calling at Google Analytics: {"kind":"analytics#realtim...
by satkumvnr New Member in Splunk Search 07-10-2018
0 1
0
1
Chandras11
Hi everyone, when I try to use the following command, it always gives in CA_flag as "Other" although lower_Ticket_De...
by Chandras11 Communicator in Splunk Search 07-10-2018
0 6
0
6
yanlajeunesse
Hello, I have someone with logs looking a bit like this: QuoA, started QuoB, started QuoC, started QuoB, ended QuoC,...
by yanlajeunesse Explorer in Splunk Search 07-10-2018
0 0
0
0
Esky73
trying to extract the msg field from an azure blob which uses the _json sourcetype - the msg : field shows as one lon...
by Esky73 Builder in Splunk Search 07-10-2018
0 3
0
3
ankithreddy777
Can we set frequency to fetch results from database to real time. Does that effect anything. Does Splunk take more s...
by ankithreddy777 Contributor in Splunk Search 07-10-2018
0 3
0
3
jsburt
I have a table lookup to map product numbers to more-readable and usable names. I would like to be able to map numb...
by jsburt New Member in Splunk Search 07-09-2018
0 3
0
3
wills2g
Hi All, When using the line chart visualisation with a timechart command, there is additional white space to the rig...
by wills2g New Member in Splunk Search 07-09-2018
0 6
0
6
todd0
I would like to add an item to the results screen context menu to run a macro with the highlighted data as a paramete...
by todd0 New Member in Splunk Search 07-09-2018
0 2
0
2
Ghanayem1974
I am new to splunk and was wondering if anyone has a document they don't mind sharing detailing "example search queri...
by Ghanayem1974 Path Finder in Splunk Search 07-09-2018
0 4
0
4
HealyManTech
I am trying to see how many time a user fail a log on. index=WinEvent Event=4625 user=* | timechart span=15m count b...
by HealyManTech Explorer in Splunk Search 07-09-2018
0 13
0
13
griffinpair
I currently have dates from a log file coming in as 09/07/2018 (July 9, 2018) and they need to be formatted as 07/09/...
by griffinpair Path Finder in Splunk Search 07-09-2018
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...