Splunk Search

Need a help in writing a query in splunk

jagan_vannala
Observer

I need a help for writing a query to fetch logs in the system

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jagan_vannala ,

as also @marnall  said, your question is too vague: which kind of logs are you speaking of?

did you already ingested or do you have to index them?

i you already indexed them, you must know index and sourcetype of them.

If you have to index them, see at https://docs.splunk.com/Documentation/SplunkCloud/8.1.10/Data/Getstartedwithgettingdatain the ways to ingest and to index logs.

Ciao.

Giuseppe

0 Karma

marnall
Motivator

What kind of logs are you trying to fetch? Does the system have a forwarder or Splunk Enterprise installed on it?

0 Karma

jagan_vannala
Observer

System having a splunk forwarder

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...