<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic Query help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543921#M154076</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232503"&gt;@mnmn777&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you have in your logs the SHA of many files, you can use Splunk to search that signature, which data have you to search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 15 Mar 2021 20:36:49 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-03-15T20:36:49Z</dc:date>
    <item>
      <title>Basic Query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543908#M154068</link>
      <description>&lt;P&gt;I just want to look for a hash signature in Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&amp;nbsp;&lt;SPAN&gt;d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What is the basic query please?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 17:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543908#M154068</guid>
      <dc:creator>mnmn777</dc:creator>
      <dc:date>2021-03-15T17:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543909#M154069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232503"&gt;@mnmn777&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry but I don't understand your need:&lt;/P&gt;&lt;P&gt;the hash you shared is what you want to search in your logs or what else?&lt;/P&gt;&lt;P&gt;if this is waht you want to search, you can use this string in a simple search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your:index d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e&lt;/LI-CODE&gt;&lt;P&gt;if you could add more informations to you question we'd be able to help you.&lt;/P&gt;&lt;P&gt;CIao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 18:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543909#M154069</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-15T18:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543910#M154070</link>
      <description>&lt;P&gt;I want to see if a file, which has that SHA256 signature is in my Enterprise or logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 18:07:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543910#M154070</guid>
      <dc:creator>mnmn777</dc:creator>
      <dc:date>2021-03-15T18:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Query help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543921#M154076</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232503"&gt;@mnmn777&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you have in your logs the SHA of many files, you can use Splunk to search that signature, which data have you to search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 20:36:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Basic-Query-help/m-p/543921#M154076</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-15T20:36:49Z</dc:date>
    </item>
  </channel>
</rss>

