Monitoring Splunk

Commands helps for search

DANITO115
Explorer

Good morning, I need to know what the exact search command is in order to see this parameter: Enter a search that returns all web application events that
contain a prohibited status (403)

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

View solution in original post

DANITO115
Explorer

ty This command help me a lot

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...