Splunk Search

Splunk Search
Community Activity
DevinG
I am running into a problem I cannot seem to figure out. One log file I have splunk reading from suddenly starts read...
by DevinG New Member in Splunk Search 05-07-2018
0 3
0
3
skallaje
The following command should return the minimum value and it does. source="SampleFilePERF.log" | stats min(ELAPSED_T...
by skallaje Engager in Splunk Search 05-07-2018
0 2
0
2
ahartge
I receive logs from a device with the full form IPv6 address, as well as using capital letters. Example: 2001:0DB8:8...
by ahartge Path Finder in Splunk Search 05-07-2018
0 12
0
12
kokanne
Why does the following query not display the number of logins and logouts (index="ggg-sec") EventCode=4624 OR EventC...
by kokanne Communicator in Splunk Search 05-07-2018
0 10
0
10
Log_wrangler
Hi, I have UFs on a few ec2 aws instances, reading logs from /temp. I want to regex and only send logs containing ...
by Log_wrangler Builder in Splunk Search 05-06-2018
0 5
0
5
kokanne
Hey, I'm trying to create a dashboard where there can be multiple entries for a field. There is a report behind my mu...
by kokanne Communicator in Splunk Search 05-06-2018
0 6
0
6
Allampally
Hi, I have the below stats result **Service Method Action** Service1 Metho...
by Allampally Path Finder in Splunk Search 05-06-2018
1 1
1
1
Allampally
Hi, I have a raw_data as below [APP=XYZ] [m=ServiceName.MethodName] [SLA=100] Splunk already generated a filed with ...
by Allampally Path Finder in Splunk Search 05-06-2018
0 2
0
2
raja21
I have various Inputs and i want to execute different query based of different token input value. Eg. I have 2 diffe...
by raja21 Explorer in Splunk Search 05-06-2018
0 1
0
1
mmwilson
Hi Splunk Community! I have a search i'm trying to build out, that will ultimately power some Dashboards to find ho...
by mmwilson Explorer in Splunk Search 05-06-2018
0 0
0
0
payamhaddad
hello all i have a client that i already installed splunk forwarder on it and configured to log everything and send ...
by payamhaddad New Member in Splunk Search 05-06-2018
0 2
0
2
daniel333
All, I have three eventtypes [insecure_telnet] app=telnet OR dest_port=23 [insecure_snmp] app=snmp OR dest_port...
by daniel333 Builder in Splunk Search 05-06-2018
0 1
0
1
tamduong16
Think of this as a youtube scenario where I have 2 different indexes: viewerreport and videoreport. The viewerreport...
by tamduong16 Contributor in Splunk Search 05-05-2018
0 3
0
3
sumitkathpal292
Hi All, We have endpoint logs by default logs are in JSON format field which are auto extracted however we have two...
by sumitkathpal292 New Member in Splunk Search 05-05-2018
0 1
0
1
skelly99
Hi - I'm trying to display a count of all sources over a 4 week period for a specific source type as part of a data q...
by skelly99 Explorer in Splunk Search 05-04-2018
0 3
0
3
splunkrocks2014
For instance, how to show "_msg" from the search result? Thanks. | makeresults | eval _msg="Hello World"
by splunkrocks2014 Communicator in Splunk Search 05-04-2018
0 2
0
2
chrisw3
Looking for confirmation that I've found the right setting. When i run: query | stats count I see 400,000 events. ...
by chrisw3 Explorer in Splunk Search 05-04-2018
1 4
1
4
a212830
Hi, Is there a way to get the "Resolve host" "NetName" "Organization" fields from whois, using the iplocation comma...
by a212830 Champion in Splunk Search 05-04-2018
0 2
0
2
jmartens
I have the following data in a key (called test_key through a field extraction) I want to split: domain\firstname.la...
by jmartens Path Finder in Splunk Search 05-04-2018
0 5
0
5
karthi25
I have a splunk log as follows: ...||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.batch.writer.LeadItemWriter - ...
by karthi25 Path Finder in Splunk Search 05-04-2018
0 7
0
7
Harinder_Singh
How we usually do business is; on our deployment server, we will create an app specific to its environment. Which can...
by Harinder_Singh New Member in Splunk Search 05-04-2018
0 11
0
11
darksky21
Hi, is there any way i could merge events base on common field? For example there are 6 events : Jun 1 2012 A:1 Ju...
by darksky21 Path Finder in Splunk Search 05-04-2018
2 3
2
3
HattrickNZ
How can I iterate through all the column names and replace space with underscore and replace :(colon space) with an u...
by HattrickNZ Motivator in Splunk Search 05-04-2018
0 1
0
1
shoermann
If I filter by Owner in View 'Searches, Reports, and Alerts' (Settings->Searches, Reports, and Alerts), there are no ...
by shoermann Explorer in Splunk Search 05-03-2018
0 1
0
1
skiller1234
Hello everybody! Trying to search for a series of strings - then count and display by host. I got this far: index=...
by skiller1234 Explorer in Splunk Search 05-03-2018
0 2
0
2
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...