Splunk Search

Splunk Search
Community Activity
mmwilson
Hi Splunk Community! I have a search i'm trying to build out, that will ultimately power some Dashboards to find ho...
by mmwilson Explorer in Splunk Search 05-06-2018
0 0
0
0
payamhaddad
hello all i have a client that i already installed splunk forwarder on it and configured to log everything and send ...
by payamhaddad New Member in Splunk Search 05-06-2018
0 2
0
2
daniel333
All, I have three eventtypes [insecure_telnet] app=telnet OR dest_port=23 [insecure_snmp] app=snmp OR dest_port...
by daniel333 Builder in Splunk Search 05-06-2018
0 1
0
1
tamduong16
Think of this as a youtube scenario where I have 2 different indexes: viewerreport and videoreport. The viewerreport...
by tamduong16 Contributor in Splunk Search 05-05-2018
0 3
0
3
sumitkathpal292
Hi All, We have endpoint logs by default logs are in JSON format field which are auto extracted however we have two...
by sumitkathpal292 New Member in Splunk Search 05-05-2018
0 1
0
1
skelly99
Hi - I'm trying to display a count of all sources over a 4 week period for a specific source type as part of a data q...
by skelly99 Explorer in Splunk Search 05-04-2018
0 3
0
3
splunkrocks2014
For instance, how to show "_msg" from the search result? Thanks. | makeresults | eval _msg="Hello World"
by splunkrocks2014 Communicator in Splunk Search 05-04-2018
0 2
0
2
chrisw3
Looking for confirmation that I've found the right setting. When i run: query | stats count I see 400,000 events. ...
by chrisw3 Explorer in Splunk Search 05-04-2018
1 4
1
4
a212830
Hi, Is there a way to get the "Resolve host" "NetName" "Organization" fields from whois, using the iplocation comma...
by a212830 Champion in Splunk Search 05-04-2018
0 2
0
2
jmartens
I have the following data in a key (called test_key through a field extraction) I want to split: domain\firstname.la...
by jmartens Path Finder in Splunk Search 05-04-2018
0 5
0
5
karthi25
I have a splunk log as follows: ...||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.batch.writer.LeadItemWriter - ...
by karthi25 Path Finder in Splunk Search 05-04-2018
0 7
0
7
Harinder_Singh
How we usually do business is; on our deployment server, we will create an app specific to its environment. Which can...
by Harinder_Singh New Member in Splunk Search 05-04-2018
0 11
0
11
darksky21
Hi, is there any way i could merge events base on common field? For example there are 6 events : Jun 1 2012 A:1 Ju...
by darksky21 Path Finder in Splunk Search 05-04-2018
2 3
2
3
HattrickNZ
How can I iterate through all the column names and replace space with underscore and replace :(colon space) with an u...
by HattrickNZ Motivator in Splunk Search 05-04-2018
0 1
0
1
shoermann
If I filter by Owner in View 'Searches, Reports, and Alerts' (Settings->Searches, Reports, and Alerts), there are no ...
by shoermann Explorer in Splunk Search 05-03-2018
0 1
0
1
skiller1234
Hello everybody! Trying to search for a series of strings - then count and display by host. I got this far: index=...
by skiller1234 Explorer in Splunk Search 05-03-2018
0 2
0
2
HattrickNZ
With multiple appendpipes how do I specify the number of rows above I want to apply it to? | makeresults | eval ...
by HattrickNZ Motivator in Splunk Search 05-03-2018
3 5
3
5
ksolanki88
...dedup Order_Number|search NOT[|inputlookup Order_Details_Lookup.csv|fields Order_Number]|table Order_Number Need ...
by ksolanki88 Explorer in Splunk Search 05-03-2018
3 12
3
12
johannesschilli
Hi, I'm writing a search command and need to log events from it to Splunk Web. I'm using the Python SDK in the curr...
by johannesschilli Engager in Splunk Search 05-03-2018
0 2
0
2
asuratos
I have two sourcetypes. first is a table of different pet types and respective animal. second is showing which pet is...
by asuratos New Member in Splunk Search 05-03-2018
0 6
0
6
wilcoxj
I was thinking that I could do a rex to grab everything up to the newline but I am trying to categorize the below out...
by wilcoxj New Member in Splunk Search 05-03-2018
0 6
0
6
panovattack
I am trying to find a good tutorial (yes, I have looked at the splunk documents) on writing a custom generating comma...
by panovattack Communicator in Splunk Search 05-03-2018
1 0
1
0
gmbenz0726
My file contains data like this: 85119.805: [GC pause (G1 Evacuation Pause) (young) 218M->81M(256M), 0.0159821 secs]...
by gmbenz0726 New Member in Splunk Search 05-03-2018
0 1
0
1
gu255363
When I run a query using stats count , I can see Events count as "636 events (4/26/18 8:00:00.000 AM to 5/3/18 8:3...
by gu255363 New Member in Splunk Search 05-03-2018
0 3
0
3
Hppjet
I would like to manipulate it to look like this:
by Hppjet Path Finder in Splunk Search 05-03-2018
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...