Splunk Search

Splunk Search
Community Activity
brajaram
My data is in JSON format split into two different sourcetypes. Between the two sourcetypes exists a linking logID th...
by brajaram Communicator in Splunk Search 05-15-2018
0 1
0
1
splunker1981
Hello Splunkers, I'm trying to figure out how to apply an if statement to check the count of an index before adding ...
by splunker1981 Path Finder in Splunk Search 05-15-2018
0 2
0
2
davidcraven02
Search is trying to show all users within the companyOu that have Mobile Iron setup (Status=Allowed) and those that d...
by davidcraven02 Communicator in Splunk Search 05-15-2018
0 7
0
7
bcarr12
Hi all, What would be the best way for Splunk to handle repeating fields in a single event? For instance, one of my ...
by bcarr12 Path Finder in Splunk Search 05-15-2018
0 2
0
2
Kendo213
I have the query below that checks for the expiration date of a certificate, converts it to epoch time, and then basi...
by Kendo213 Communicator in Splunk Search 05-15-2018
0 3
0
3
vpatsalos
I have a search that captures when a user logs in and logs out of his PC: index=win* (EventCode=4800 OR EventCode=48...
by vpatsalos New Member in Splunk Search 05-15-2018
0 1
0
1
stanwin
Hi Is it fine to use Unicode characters as a quick way to to set checklist marks & various other formatting/make pr...
by stanwin Contributor in Splunk Search 05-15-2018
5 4
5
4
ccsfdave
I keep trying to figure things out myself but my head is getting bruised from hitting it against my desk... I am try...
by ccsfdave Builder in Splunk Search 05-15-2018
0 4
0
4
jackreeves
I have a report running in SPLUNK on a daily basis. The timestamp for this report is the "Report Date" field (i.e. to...
by jackreeves Explorer in Splunk Search 05-15-2018
0 9
0
9
OldManEd
Is there a way to format data in a table column to print one entry on a line? In my alert the table data shows up so...
by OldManEd Builder in Splunk Search 05-15-2018
0 5
0
5
simon21
I have a CSV file with fields mentioned below: Updated Date, SMSMessage,Sender,SMS Date,userID The SMSMessage field ...
by simon21 Path Finder in Splunk Search 05-15-2018
0 1
0
1
azulcactus
Today we have messages from our application like this: 2018-May-1 12:00:00.000 [Thread=4d2ce108-c322-49ff-bcc0-380d7...
by azulcactus New Member in Splunk Search 05-15-2018
0 0
0
0
ranjitbrhm1
Good Day all, I have a query, I am uploading a CSV regularly onto splunk. Since its uploaded in a random time, splunk...
by ranjitbrhm1 Communicator in Splunk Search 05-15-2018
0 2
0
2
akarivaratharaj
In one of the search queries, I am displaying the Latest and Oldest value of a field. Please refer the below sample q...
by akarivaratharaj Communicator in Splunk Search 05-15-2018
0 2
0
2
rahul_mckc_splu
Please see this query for brute force detection- index="wineventlog" sourcetype=wineventlog:security | search (Event...
by rahul_mckc_splu Loves-to-Learn in Splunk Search 05-15-2018
0 3
0
3
equick
I have a query like this, which prints the number of message matches and an abbreviation: sourcetype=source1 | rex "...
by equick Explorer in Splunk Search 05-15-2018
1 6
1
6
Allampally
Hi, I have a timechart result with two columns as shown in the 1st screenshot. Hour column contain a count for each...
by Allampally Path Finder in Splunk Search 05-15-2018
0 2
0
2
bhartmann
I've been looking at some similar questions .. (for instance, this showed how to have timechart display % each day in...
by bhartmann New Member in Splunk Search 05-14-2018
0 0
0
0
nls7010
The local.meta file on our splunk 5.0.4 version on the Search Head/Deployer server has had data removed (assuming acc...
by nls7010 Path Finder in Splunk Search 05-14-2018
0 3
0
3
developer_de
I would like to create stats from the data whose structure looks like mentioned below: { data: { ...
by developer_de New Member in Splunk Search 05-14-2018
0 4
0
4
ahmar74
i want to know who worked the most splunk events per day. We have corelation searches that fire on specific use cases...
by ahmar74 Explorer in Splunk Search 05-14-2018
0 0
0
0
Log_wrangler
I have some URL encoded logs. ...| eval decoded_raw = urldecode(_raw) how would I write a rex to find any decoded_...
by Log_wrangler Builder in Splunk Search 05-14-2018
1 4
1
4
jayaraj1717
i would like to calculate response time by extracting timestamp from two different search then subtracting Response=S...
by jayaraj1717 New Member in Splunk Search 05-14-2018
0 9
0
9
jackie_1001
Hi, I'm trying to show the concurrent number of 2 operations(eg, data 'export', and data 'import') on a server in a ...
by jackie_1001 New Member in Splunk Search 05-14-2018
0 4
0
4
DEAD_BEEF
I want to create a visualization that shows the number of sales in the last 1, 2, and 7 days all within the same visu...
by DEAD_BEEF Builder in Splunk Search 05-14-2018
0 5
0
5
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...