Splunk Search

Splunk Search
Community Activity
SapthagiriAavik
I have a events log something like this, 2018-06-29 03:34:23.090 -5 Thread-55 CM 6107 1 Content Manager is ...
by SapthagiriAavik Explorer in Splunk Search 06-29-2018
0 1
0
1
joydeep741
I have a SEARCH-1 Which Gives results like -time column1 column2 I want to run a secondary search for each value...
by joydeep741 Path Finder in Splunk Search 06-29-2018
0 1
0
1
splunker1981
Hello experts, I have a search that I am trying to add a where statement to which compares fieldvalueA to fieldvalue...
by splunker1981 Path Finder in Splunk Search 06-29-2018
0 4
0
4
jeanmatthieu
Hi, I have an inputs.conf as below in my UniversalForwarder [monitor::///private/var/log/system.log] _meta = serial...
by jeanmatthieu Explorer in Splunk Search 06-29-2018
1 4
1
4
gbehl
My requirement is to find duplicate events for a pattern that occurred in the same 'second' of timestamp after stripp...
by gbehl New Member in Splunk Search 06-29-2018
0 4
0
4
ankithnageshshe
Hello Splunkers, I'am trying to understand the concept of Search head concurrency. I have a SHC with three search h...
by ankithnageshshe Path Finder in Splunk Search 06-29-2018
0 1
0
1
blangrill
Use case: I want to pull a specific set of security events from OMS into Splunk. Within OMS log search, querying for:...
by blangrill Explorer in Splunk Search 06-29-2018
1 8
1
8
_smp_
I have sequence of events from a VPN session. The last message in the sequence contains a field for duration of the s...
by _smp_ Builder in Splunk Search 06-29-2018
0 5
0
5
dhruv101
Hi my x axis labels for a chart are really long. E.g. 2017-19-18 22:33:22:10247392048 ABSSHEUVCBKSOWNMSKWOKSNKJWK Be...
by dhruv101 Path Finder in Splunk Search 06-29-2018
0 4
0
4
Log_wrangler
Hi I am trying to write a query where I can monitor transactions/hr/user. I would like an output where I have the...
by Log_wrangler Builder in Splunk Search 06-29-2018
0 4
0
4
Log_wrangler
I have a list of userIDs on a text file, called WatchList.txt Splunk can natively parse out a field value pair (user...
by Log_wrangler Builder in Splunk Search 06-29-2018
0 7
0
7
msaranya
I have start time and end time for 5 rows with duration, i need a graph which populates from start_time till the dura...
by msaranya Observer in Splunk Search 06-29-2018
0 2
0
2
krish3
Hi, I need to know is it role based data masking is possible in 6.0.1? If yes then please let me know what are the p...
by krish3 Contributor in Splunk Search 06-29-2018
1 9
1
9
sistemistiposta
Hello, I would like to plot an hour distribution with aggregate stats over time. For instance, I want to see distrib...
by sistemistiposta Path Finder in Splunk Search 06-29-2018
0 3
0
3
cdhippen
I have log items that have event messages but no IDs indicating that the log in and log out belong to the same sessio...
by cdhippen Path Finder in Splunk Search 06-28-2018
0 5
0
5
khavildar
I have a requirement wherein I have to find timedifference of 2 events. Below is an example on the event type: Host ...
by khavildar Explorer in Splunk Search 06-28-2018
0 2
0
2
pjdwyer
The event s I am dealing with have multiple "instance times" to work with, I am trying to find the time difference be...
by pjdwyer Explorer in Splunk Search 06-28-2018
0 3
0
3
Ragate
I have joined two searches together. My search only returns one event that everything matches up but there are more t...
by Ragate Explorer in Splunk Search 06-28-2018
0 6
0
6
hulgundi
I need to find the missing list of process from a list of hosts and setup an alert There will be number of process ...
by hulgundi New Member in Splunk Search 06-28-2018
0 2
0
2
pladamsplunk
In my logs I have something that looks like the following "string1":"string2" I would like to extract string2 as a fi...
by pladamsplunk Explorer in Splunk Search 06-28-2018
0 13
0
13
immortalraghava
I have a sample search with an eval statement which works, index = _internal | head 1 | eval temp = strftime(now(),...
by immortalraghava Path Finder in Splunk Search 06-28-2018
0 3
0
3
cpalicensing
Using the base search listed below it presents me with all print jobs, one print job per user. I would like to chart...
by cpalicensing New Member in Splunk Search 06-28-2018
0 1
0
1
dagnygaard
I am trying to set up a report with a search string that works OK. Unfortunately, only internal Ids are used in the ...
by dagnygaard Explorer in Splunk Search 06-28-2018
0 4
0
4
abhi04
How to compare more than 50 column values for a specific row and so on for the next row in splunk? I have below colu...
by abhi04 Communicator in Splunk Search 06-28-2018
0 5
0
5
Chandras11
Hi All, index="index1" sourcetype="SC1" OR sourcetype="SC2" | eval Ticket_Main5 = (Ticket,1,5)| eval Ticket_master ...
by Chandras11 Communicator in Splunk Search 06-28-2018
0 10
0
10
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...