Monitoring Splunk

Commands helps for search

DANITO115
Explorer

Good morning, I need to know what the exact search command is in order to see this parameter: Enter a search that returns all web application events that
contain a prohibited status (403)

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

View solution in original post

DANITO115
Explorer

ty This command help me a lot

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DANITO115,

did you followed the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial)?

Anyway, this depends on the data type you want to search and if you already extracted the status field.

If you already extracted, you could simply use:

index=your_index status=403

if not, you have to extract it using a regex, but to help you in this a sample of your logs is required.

Otherwise, you can simply search the string 403

index=your_index 403

but you could have some false positive:

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...