Splunk Search

Splunk Search
Community Activity
omcollia
"I have an issue with creating a field named 'Path' which should be populated with 'YES' or 'NO' based on the followi...
by omcollia Engager in Splunk Search 02-20-2024
0 3
0
3
DEADBEEF
I have a timechart that shows the last 30d and with the timechart I also have a trendline showing the sma7.  The prob...
by DEADBEEF Path Finder in Splunk Search 02-19-2024
0 3
0
3
Harish2
|mstats avg(os.mem.utilized) as Memory_Used where index=metricsidx host=host1 OR host=host2 span=1d |table Memory_Us...
by Harish2 Path Finder in Splunk Search 02-19-2024
0 3
0
3
runiyal
I have a logfile like this - 2024-02-15 09:07:47,770 INFO [com.mysite.core.app1.upload.FileUploadWebScript] [http-ni...
by runiyal Path Finder in Splunk Search 02-19-2024
0 7
0
7
jip31
hi When I call the lookup like below it works fine     | inputlookup test.csv     but when I use the lookup in a sear...
by jip31 Motivator in Splunk Search 02-19-2024
0 20
0
20
MattiaP
Hi, I have an index that doesn't show events anymore. Could you help me please?On November I had a problem with Mongo...
by MattiaP Loves-to-Learn Lots in Splunk Search 02-19-2024
0 9
0
9
codetester
 So we have a query: (index="it_ops") source="bank_sys" message.content.country IN ("CANADA","USA","UK","FRANCE","SP...
by codetester Loves-to-Learn Lots in Splunk Search 02-19-2024
0 1
0
1
rzv424
We want an alert to run every day (Monday-Sunday) on a 30 minutes interval with one exception. The exception is it sh...
by rzv424 Engager in Splunk Search 02-19-2024
0 2
0
2
mahesh27
Created 2 drop downs in a dashboard. 1. Country2. Applications (getting data from .csv file)In applications drop down...
by mahesh27 Communicator in Splunk Search 02-18-2024
0 4
0
4
pitt93
I am trying to get a understanding why I get a different count total for the number of events for the following searc...
by pitt93 New Member in Splunk Search 02-18-2024
0 1
0
1
SplunkDash
Hello,I have a lookup table called account_audit.csv and have a timestamp field UPDATE_DATE=01/05/24 04:49:26. How ca...
by SplunkDash Motivator in Splunk Search 02-18-2024
0 6
0
6
Muthu_Vinith
Hey Experts, I'm new to splunk and I'm trying to extract APP WEB and MNOPQ from a field called result. Can someone pl...
by Muthu_Vinith Path Finder in Splunk Search 02-18-2024
0 8
0
8
Muthu_Vinith
Hey Experts, I'm new to splunk and I'm trying to create a new lookup from data in a index=abc. Can someone please gui...
by Muthu_Vinith Path Finder in Splunk Search 02-17-2024
0 8
0
8
Santosh2
Query:index=abc mal_code=xyz TERM(application) OR (TERM(status) TERM(success)) NOT (TERM(unauthorized) TERM(time) TER...
by Santosh2 Path Finder in Splunk Search 02-17-2024
0 10
0
10
vihshah
Hi,So my task is to extract a field from a query and search for that field. That query will give an object value as a...
by vihshah Engager in Splunk Search 02-17-2024
0 84
0
84
iamsplunker0415
Hello Splunk Community, I have a requirement to exclude the events from field values between  2AM-3AM everyday.For Ex...
by iamsplunker0415 Engager in Splunk Search 02-16-2024
0 3
0
3
keorus
Good morning, I come to you because after looking for an answer to my problem, my last solution is to come and seek h...
by keorus New Member in Splunk Search 02-16-2024
0 4
0
4
jyates76
I have events like the below that are saying when a particular pool member was out of rotation for a particular perio...
by jyates76 Explorer in Splunk Search 02-16-2024
0 1
0
1
Kat456
I have a list of comma separated names (lastname, firstname) that I need to reverse. So "Smith, Suzy" becomes "Suzy S...
by Kat456 Engager in Splunk Search 02-16-2024
0 3
0
3
jeradb
I can run the below command in a search successfully -  | eval message=replace(Message, "^Installation Successful: Wi...
by jeradb Explorer in Splunk Search 02-15-2024
0 2
0
2
davidcraven02
My logic for my field "Action" is below, but because there is different else conditions I cannot write an eval do ach...
by davidcraven02 Communicator in Splunk Search 02-15-2024
0 14
0
14
dmitrynt
Hello guys, I have below query which uses join. I see lots of examples how to replace that with stats, but I am not a...
by dmitrynt Engager in Splunk Search 02-15-2024
0 12
0
12
mwcentracomm
I am using the search below | metadata type=hosts | where recentTime < now() - 10800| eval lastSeen = strftime(recent...
by mwcentracomm Explorer in Splunk Search 02-15-2024
0 3
0
3
Taruchit
Hello All,I have the below SPL to compare hourly event data and indexed data to find if they follow similar pattern a...
by Taruchit Contributor in Splunk Search 02-15-2024
0 8
0
8
Branden
Quick question: how can I view a user's search history?
by Branden Builder in Splunk Search 02-15-2024
14 24
14
24
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors