Splunk Search

Basic Query help

mnmn777
Observer

I just want to look for a hash signature in Splunk. 

Example: d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e

What is the basic query please? 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mnmn777,

sorry but I don't understand your need:

the hash you shared is what you want to search in your logs or what else?

if this is waht you want to search, you can use this string in a simple search:

index=your:index d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e

if you could add more informations to you question we'd be able to help you.

CIao.

Giuseppe

0 Karma

mnmn777
Observer

I want to see if a file, which has that SHA256 signature is in my Enterprise or logs. 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mnmn777,

If you have in your logs the SHA of many files, you can use Splunk to search that signature, which data have you to search?

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...