Splunk Search

Splunk Search
Community Activity
Log_wrangler
I have a list of userIDs on a text file, called WatchList.txt Splunk can natively parse out a field value pair (user...
by Log_wrangler Builder in Splunk Search 06-29-2018
0 7
0
7
msaranya
I have start time and end time for 5 rows with duration, i need a graph which populates from start_time till the dura...
by msaranya Observer in Splunk Search 06-29-2018
0 2
0
2
krish3
Hi, I need to know is it role based data masking is possible in 6.0.1? If yes then please let me know what are the p...
by krish3 Contributor in Splunk Search 06-29-2018
1 9
1
9
sistemistiposta
Hello, I would like to plot an hour distribution with aggregate stats over time. For instance, I want to see distrib...
by sistemistiposta Path Finder in Splunk Search 06-29-2018
0 3
0
3
cdhippen
I have log items that have event messages but no IDs indicating that the log in and log out belong to the same sessio...
by cdhippen Path Finder in Splunk Search 06-28-2018
0 5
0
5
khavildar
I have a requirement wherein I have to find timedifference of 2 events. Below is an example on the event type: Host ...
by khavildar Explorer in Splunk Search 06-28-2018
0 2
0
2
pjdwyer
The event s I am dealing with have multiple "instance times" to work with, I am trying to find the time difference be...
by pjdwyer Explorer in Splunk Search 06-28-2018
0 3
0
3
Ragate
I have joined two searches together. My search only returns one event that everything matches up but there are more t...
by Ragate Explorer in Splunk Search 06-28-2018
0 6
0
6
hulgundi
I need to find the missing list of process from a list of hosts and setup an alert There will be number of process ...
by hulgundi New Member in Splunk Search 06-28-2018
0 2
0
2
pladamsplunk
In my logs I have something that looks like the following "string1":"string2" I would like to extract string2 as a fi...
by pladamsplunk Explorer in Splunk Search 06-28-2018
0 13
0
13
immortalraghava
I have a sample search with an eval statement which works, index = _internal | head 1 | eval temp = strftime(now(),...
by immortalraghava Path Finder in Splunk Search 06-28-2018
0 3
0
3
cpalicensing
Using the base search listed below it presents me with all print jobs, one print job per user. I would like to chart...
by cpalicensing New Member in Splunk Search 06-28-2018
0 1
0
1
dagnygaard
I am trying to set up a report with a search string that works OK. Unfortunately, only internal Ids are used in the ...
by dagnygaard Explorer in Splunk Search 06-28-2018
0 4
0
4
abhi04
How to compare more than 50 column values for a specific row and so on for the next row in splunk? I have below colu...
by abhi04 Communicator in Splunk Search 06-28-2018
0 5
0
5
Chandras11
Hi All, index="index1" sourcetype="SC1" OR sourcetype="SC2" | eval Ticket_Main5 = (Ticket,1,5)| eval Ticket_master ...
by Chandras11 Communicator in Splunk Search 06-28-2018
0 10
0
10
abhi04
How to assign value to a field which is not present in some of the events and compare that value with other values fr...
by abhi04 Communicator in Splunk Search 06-28-2018
0 2
0
2
ranjitbrhm1
Good Day splunkers. I have a query where i want to calculate the number of times a name came on the field, the averag...
by ranjitbrhm1 Communicator in Splunk Search 06-28-2018
0 3
0
3
beqanaveriani
I have syslog file like this: Mar 21 06:48:23 10.171.134.200 Mar 21 08:10:00 10.171.134.200 AlteonOS : 1.1.1.34 26...
by beqanaveriani New Member in Splunk Search 06-28-2018
0 7
0
7
joydeep741
I want to build a logic for SEARCH-2 My SEARCH -1 Gives me start and End time stamp of a Planned Outage. My SEARCH...
by joydeep741 Path Finder in Splunk Search 06-27-2018
0 4
0
4
vinodvv
I have configured splunk with http event collector on docker, so I am storing the logs of all the container into splu...
by vinodvv Engager in Splunk Search 06-27-2018
0 1
0
1
jpawloski
I've found some variations on this issue but nothing exactly the same. Go easy on me... I'm dealing with events that...
by jpawloski Path Finder in Splunk Search 06-27-2018
1 1
1
1
jpawloski
I have a search that compares an expanded multi value field against a lookup table and returns those events where at ...
by jpawloski Path Finder in Splunk Search 06-27-2018
0 3
0
3
Ragate
I have two sources of data. One that has an Account Name, License Key, and Account Revenue. The other has License Key...
by Ragate Explorer in Splunk Search 06-27-2018
0 1
0
1
joydeep741
I have 2 absolutely independent searches. Search-1 gives me the availability of server throughout the day. Sample da...
by joydeep741 Path Finder in Splunk Search 06-27-2018
0 2
0
2
vikas_baranwal
Hi, I am having correct value in current field and want to use that value as column name which is currently showing ...
by vikas_baranwal Path Finder in Splunk Search 06-27-2018
0 6
0
6
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...