Monitoring Splunk

Commands helps for search

DANITO115
Explorer

Good morning, I need to know what the exact search command is in order to see this parameter: Enter a search that returns all web application events that
contain a prohibited status (403)

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

View solution in original post

DANITO115
Explorer

ty This command help me a lot

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...