Splunk Search

Need help with Basic query over splunk

ashish_d
New Member

Please help share query to check 

> network logs and firewall blocks for specific Host machine
> LDAP password login failed query for specific user account

>

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Very sparse information here - please share some anonymised sample events, preferably in a code block (using the </> edit option. Please share what you have already tried. Where your events have been ingested to. What your current results are, etc. Contributors are pretty talented here but mind-reading is a rare capability!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...