<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431015#M52877</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I am practicing the event and having problem doing search on the dataset. When I just search the answer, I can see the event, but when I use Splunk search query, the answer is not appearing for some reason.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;:&lt;BR /&gt;
What is the name of the file that defaced the &lt;CODE&gt;imreallynotbatman.com&lt;/CODE&gt; website? Please submit only the name of the file with extension (For example "notepad.exe" or "favicon.ico")&lt;BR /&gt;
Answer is &lt;CODE&gt;poisonivy-is-coming-for-you-batman.jpeg&lt;/CODE&gt;&lt;BR /&gt;
so if I just search &lt;CODE&gt;poisonivy-is-coming-for-you-batman.jpeg&lt;/CODE&gt; it gives me two events&lt;BR /&gt;
 &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5660iFB4D226EDB2BB5F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However when I do &lt;CODE&gt;search sourcetype=suricata src_ip=192.168.250.70 | table url | search url=*batman*&lt;/CODE&gt; it does not give me that event and this happens to a lot of questions. Any suggestions of what is happening?&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5661i1FBC623978154AC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;updated to mark code for you - dmj&lt;/P&gt;</description>
    <pubDate>Sun, 26 Aug 2018 22:41:42 GMT</pubDate>
    <dc:creator>samlinsongguo</dc:creator>
    <dc:date>2018-08-26T22:41:42Z</dc:date>
    <item>
      <title>Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431015#M52877</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I am practicing the event and having problem doing search on the dataset. When I just search the answer, I can see the event, but when I use Splunk search query, the answer is not appearing for some reason.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;:&lt;BR /&gt;
What is the name of the file that defaced the &lt;CODE&gt;imreallynotbatman.com&lt;/CODE&gt; website? Please submit only the name of the file with extension (For example "notepad.exe" or "favicon.ico")&lt;BR /&gt;
Answer is &lt;CODE&gt;poisonivy-is-coming-for-you-batman.jpeg&lt;/CODE&gt;&lt;BR /&gt;
so if I just search &lt;CODE&gt;poisonivy-is-coming-for-you-batman.jpeg&lt;/CODE&gt; it gives me two events&lt;BR /&gt;
 &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5660iFB4D226EDB2BB5F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However when I do &lt;CODE&gt;search sourcetype=suricata src_ip=192.168.250.70 | table url | search url=*batman*&lt;/CODE&gt; it does not give me that event and this happens to a lot of questions. Any suggestions of what is happening?&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5661i1FBC623978154AC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;updated to mark code for you - dmj&lt;/P&gt;</description>
      <pubDate>Sun, 26 Aug 2018 22:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431015#M52877</guid>
      <dc:creator>samlinsongguo</dc:creator>
      <dc:date>2018-08-26T22:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431016#M52878</link>
      <description>&lt;P&gt;Take a careful look at exactly what you are specifying in your search, especially the exact spelling of each field.  &lt;/P&gt;

&lt;P&gt;Review each of the results from your first search, look in those results for the fields that are spelled exactly like you spelled them, and see whether they exist and what values they contain. &lt;/P&gt;

&lt;P&gt;If you do this carefully, you will see what mistake you made.&lt;/P&gt;

&lt;P&gt;(We could tell you, but you will learn more by finding them yourself.)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 00:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431016#M52878</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-27T00:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431017#M52879</link>
      <description>&lt;P&gt;I don't have a great answer for you at the moment...  I have attached my searches of sourcetype suricata in two different ways and both ways return 133 events.&lt;/P&gt;

&lt;P&gt;It is worth mentioning that when I run a search for poisonivy-is-coming-for-you-batman.jpeg, i get 10 events returned, but you are only getting two.  I wonder if your dataset is not complete for some reason.  The other thing that is odd is you are showing me the first and last event in your first search.&lt;/P&gt;

&lt;P&gt;I wish I had a better answer for you but hopefully these couple of nuggets help steer you toward the expected output.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5658i66677727BC7B04D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5659iD6EDE93CDDC81DDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 00:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431017#M52879</guid>
      <dc:creator>jstoner_splunk</dc:creator>
      <dc:date>2018-08-27T00:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431018#M52880</link>
      <description>&lt;P&gt;Hi DalJeanis&lt;BR /&gt;
I am not quick get it it I triple checked the first search is &lt;CODE&gt;"poisonivy-is-coming-for-you-batman.jpeg"&lt;/CODE&gt; and the second query is search &lt;CODE&gt;sourcetype=suricata src_ip=192.168.250.70 | table url | search url=*batman*&lt;/CODE&gt; if you refer to the actual field is http.url I did the same search as well search &lt;CODE&gt;sourcetype=suricata src_ip=192.168.250.70 | table http.url | search http.url=*batman*&lt;/CODE&gt; it have the same problem. plus I can see both field have the value.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 06:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431018#M52880</guid>
      <dc:creator>samlinsongguo</dc:creator>
      <dc:date>2018-08-27T06:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Boss of SOC V1 dataset: Why am I having a problem finding an event that I know is there?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431019#M52881</link>
      <description>&lt;P&gt;Hi @samlinsongguo. Did either of the answers below solve your question? If yes, please click “Accept” directly below the answer to resolve the post. If not, please comment with more information if you are still having issues.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 23:50:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Boss-of-SOC-V1-dataset-Why-am-I-having-a-problem-finding-an/m-p/431019#M52881</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-08-28T23:50:23Z</dc:date>
    </item>
  </channel>
</rss>

